awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
dtag-dev-sec avatar

dtag-dev-sec/tpotce

0
View on GitHub↗
9,281 stars·1,375 forks·Shell·GPL-3.0·17 views

Tpotce

T-Pot is a multi-honeypot orchestration platform and threat intelligence collector. It utilizes a Docker-based security sandbox to deploy and manage a collection of diverse decoy services that simulate vulnerable targets to lure attackers and record their activity.

The system features a distributed sensor network where remote nodes capture attack logs and transmit them via encrypted communication to a central hub. This central hub employs an analytics stack to transform raw logs into geographic maps and interactive dashboards for adversary behavior visualization. To increase the realism of simulated targets, the platform integrates large language models.

Broad capabilities include automated environment installation across Linux distributions, passive network fingerprinting, and the ability to filter out mass scanner traffic to reduce noise. The platform also supports exporting captured security event data to community backends and third-party global threat feeds.

Features

  • Honeypot Environments - Integrates large language models and diverse services to create realistic targets that trick attackers.
  • Threat Intelligence Platforms - Manages a distributed network of sensors to collect and transmit attacker logs to a central hub.
  • Threat Intelligence - Enables the contribution of captured attack data to community backends and global threat intelligence feeds.
  • Analytics Dashboards - Transforms raw attack logs into interactive dashboards and geographic maps for behavioral visualization.
  • Container Environment Orchestrators - Deploys diverse vulnerable services in isolated containers to simulate targets and capture attacker activity.
  • Decoy Service Deployments - Deploys a collection of diverse services in a single environment to analyze network attack data across various ports.
  • Distributed Deployment - Coordinates a network of remote sensors that relay captured intruder activity back to a central server.
  • Remote Monitoring Transmission - Transmits captured attack data from distributed remote installations to a central hub for aggregated analysis.
  • Attack Data Collection - Captures and persists network traffic and attacker logs to facilitate detailed security analysis.
  • Cyber Threat Intelligence Maps - Visualizes captured network traffic and intruder behavior using centralized dashboards and geographic maps.
  • Secure Sandboxing - Uses Docker containers to create isolated security sandboxes that simulate vulnerable services without risking the host system.
  • Decoy Services - Deploys a collection of diverse decoy services to simulate vulnerable targets and capture network attack data.
  • Centralized Logging Systems - Aggregates attack logs from multiple remote sensors into a centralized system for unified monitoring.
  • Distributed Log Aggregation - Collects and synchronizes security event data from multiple remote sensors into a centralized hub for analysis.
  • Sensor Network Coordination - Deploys and coordinates multiple remote sensors to collect threat intelligence across different network locations.
  • Interactive Honeypots - Integrates large language models to power interactive simulations that act as realistic targets for attackers.
  • Behavior Visualizations - Visualizes captured attack traffic through integrated dashboards and geographic maps to analyze adversary behavior.
  • Data Persistence and Storage - Stores collected attack logs and artifacts with configurable retention and purging policies.
  • Automated System Installers - Automates dependency installation, firewall configuration, and system setup across various Linux distributions.
  • Communication Encryption - Protects data transit between remote collection nodes and the central server using SSL certificates.
  • Device Fingerprinting - Extracts metadata and device identifiers from live traffic using passive network fingerprinting.
  • Infrastructure Fingerprinters - Extracts network metadata and fingerprints from live traffic using passive fingerprinting engines to identify infrastructure.
  • Open Source Intelligence Tools - Collects open source intelligence and utilizes encoding and decryption tools to investigate attacker behavior.
  • Security Analysis Dashboards - Provides a centralized security analysis dashboard using the ELK stack to visualize attack patterns and geographic maps.
  • Traffic Filtering Systems - Null-routes traffic from known mass scanners at the network level to reduce noise in threat intelligence.
  • Honeypot Management - All-in-one honeypot appliance for rapid deployment.

Star history

Star history chart for dtag-dev-sec/tpotceStar history chart for dtag-dev-sec/tpotce

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does dtag-dev-sec/tpotce do?

T-Pot is a multi-honeypot orchestration platform and threat intelligence collector. It utilizes a Docker-based security sandbox to deploy and manage a collection of diverse decoy services that simulate vulnerable targets to lure attackers and record their activity.

What are the main features of dtag-dev-sec/tpotce?

The main features of dtag-dev-sec/tpotce are: Honeypot Environments, Threat Intelligence Platforms, Threat Intelligence, Analytics Dashboards, Container Environment Orchestrators, Decoy Service Deployments, Distributed Deployment, Remote Monitoring Transmission.

What are some open-source alternatives to dtag-dev-sec/tpotce?

Open-source alternatives to dtag-dev-sec/tpotce include: stamparm/maltrail — Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network… telekom-security/tpotce — T-Pot is a multi-honeypot platform and threat intelligence framework that deploys a collection of containerized decoy… crowdsecurity/crowdsec — CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection.… cube-js/cube — Cube is a semantic data layer that provides a unified framework for defining business metrics, dimensions, and… linkedin/school-of-sre — This project is a comprehensive educational resource and curriculum focused on site reliability engineering,… misp/misp — MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing…

Open-source alternatives to Tpotce

Similar open-source projects, ranked by how many features they share with Tpotce.
  • stamparm/maltrailstamparm avatar

    stamparm/maltrail

    8,498View on GitHub↗

    Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o

    Pythonattack-detectionintrusion-detectionmalware
    View on GitHub↗8,498
  • telekom-security/tpotcetelekom-security avatar

    telekom-security/tpotce

    9,298View on GitHub↗

    T-Pot is a multi-honeypot platform and threat intelligence framework that deploys a collection of containerized decoy services to capture attacker behavior and network telemetry. It functions as a Docker-based deception system, simulating vulnerable network environments to gather intelligence on threat actors. The system features a distributed sensor network using a hub-and-spoke architecture, allowing remote sensors to transmit logs back to a central management hub. It integrates large language models to create a dynamic deception engine capable of adaptive interactions with attackers. The

    Shelldeceptiondockerelk
    View on GitHub↗9,298
  • crowdsecurity/crowdseccrowdsecurity avatar

    crowdsecurity/crowdsec

    12,574View on GitHub↗

    CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection. It functions as an intrusion detection system that parses logs and network traffic to identify malicious patterns, utilizing a bucket-based threshold detection model to aggregate events and trigger alerts. The platform is built on a modular architecture that includes a centralized local API server for managing security signals and a relational database for persistent storage of remediation decisions. What distinguishes the project is its decoupled enforcement model, which offl

    Goattacks-preventiondetectionids
    View on GitHub↗12,574
  • cube-js/cubecube-js avatar

    cube-js/cube

    20,251View on GitHub↗

    Cube is a semantic data layer that provides a unified framework for defining business metrics, dimensions, and relationships across diverse data sources. By acting as a headless business intelligence engine, it transforms raw data into a governed model that can be queried via SQL, REST, and GraphQL interfaces. This architecture ensures consistent data definitions and logic across all downstream analytical applications and reporting tools. The platform distinguishes itself through its integrated conversational AI capabilities, which allow users to explore data using natural language. It orches

    Rustagentic-analyticsagentsai
    View on GitHub↗20,251
  • See all 30 alternatives to Tpotce→