awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
telekom-security avatar

telekom-security/tpotce

0
View on GitHub↗
9,298 stars·1,376 forks·Shell·GPL-3.0·21 views

Tpotce

T-Pot is a multi-honeypot platform and threat intelligence framework that deploys a collection of containerized decoy services to capture attacker behavior and network telemetry. It functions as a Docker-based deception system, simulating vulnerable network environments to gather intelligence on threat actors.

The system features a distributed sensor network using a hub-and-spoke architecture, allowing remote sensors to transmit logs back to a central management hub. It integrates large language models to create a dynamic deception engine capable of adaptive interactions with attackers.

The platform covers a broad range of security capabilities, including the emulation of vulnerable services, passive network traffic analysis, and the use of HTTP tarpitting to exhaust attacker resources. Captured event logs are aggregated into real-time dashboards and geographic maps for threat data visualization.

Administrative access to the tool suite and dashboards is managed through a reverse proxy and authenticated web access control.

Features

  • Honeypots and Deception - Deploys simulated vulnerable services and HTTP tarpits to mislead attackers and capture their behavior.
  • Deceptive Environments - Deploys a collection of simulated vulnerable services in Docker containers to mimic real network environments.
  • Honeypot Management - Runs a collection of simulated vulnerable services in containers to capture attacker behavior and telemetry.
  • Multi-Service Honeypots - Runs a diverse collection of containerized services to simulate vulnerable systems and capture wide-ranging attacker activity.
  • Threat Intelligence - Collects and analyzes network attack data to identify threat actors and contribute to global security research.
  • Container Orchestrators - Orchestrates a diverse collection of simulated vulnerable services in isolated containers to capture attacker activity.
  • Hub-and-Spoke Agent Deployment - Implements a hub-and-spoke architecture where remote sensors host services and transmit telemetry to a central hub.
  • AI-Driven Deception - Uses large language models to create dynamic and adaptive simulated environments that interact realistically with attackers.
  • LLM-Powered Deception - Integrates large language models to simulate realistic network services and adaptive interactions with attackers.
  • Threat Intelligence Platforms - Aggregates captured honeypot data into dashboards and maps for global cyber threat analysis.
  • Distributed Sensor Networks - Deploys remote sensors that capture traffic and transmit log data to a central hub for consolidated analysis.
  • Interactive Honeypots - Integrates large language models to create dynamic and realistic simulations for adversary engagement within honeypots.
  • Threat Intelligence Platforms - Provides capabilities to share captured attack data with community backends and third-party threat intelligence brokers.
  • Search Engine Dashboards - Aggregates captured event logs into a search engine to provide real-time dashboards and geographic attack maps.
  • Deployment Configuration - Allows configuring an instance to act as either a central management hub or a remote sensor that pushes data.
  • Remote Service Credential Captures - Mimics common network services like RDP and API servers to capture credential telemetry and attacker behavior.
  • Network Deception Technologies - Uses simulated services and AI-driven interactions as network deception technologies to lure and analyze attackers.
  • HTTP Tarpits - Slows down bot requests by feeding them an infinite stream of fake secrets to exhaust attacker resources.
  • Passive Traffic Analyzers - Extracts network metadata and fingerprints traffic passively to monitor security events without interfering with attackers.
  • Network Traffic Dashboards - Converts captured security events into real-time dashboards and geographic maps to monitor active attack patterns.
  • Attack Data Dashboards - Aggregates security events into real-time dashboards and animated geographic maps to analyze attacker behavior.

Star history

Star history chart for telekom-security/tpotceStar history chart for telekom-security/tpotce

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does telekom-security/tpotce do?

T-Pot is a multi-honeypot platform and threat intelligence framework that deploys a collection of containerized decoy services to capture attacker behavior and network telemetry. It functions as a Docker-based deception system, simulating vulnerable network environments to gather intelligence on threat actors.

What are the main features of telekom-security/tpotce?

The main features of telekom-security/tpotce are: Honeypots and Deception, Deceptive Environments, Honeypot Management, Multi-Service Honeypots, Threat Intelligence, Container Orchestrators, Hub-and-Spoke Agent Deployment, AI-Driven Deception.

What are some open-source alternatives to telekom-security/tpotce?

Open-source alternatives to telekom-security/tpotce include: dtag-dev-sec/tpotce — T-Pot is a multi-honeypot orchestration platform and threat intelligence collector. It utilizes a Docker-based… hacklcx/hfish — HFish is a distributed honeypot system and network intrusion detection tool designed to deploy decoy services and… opencti-platform/opencti — OpenCTI is a cyber threat intelligence platform and knowledge base used to store, manage, and analyze technical… jekil/awesome-hacking — This project is a curated, version-controlled directory of software and resources designed for cybersecurity… thehive-project/thehive — TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security… misp/misp — MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing…

Open-source alternatives to Tpotce

Similar open-source projects, ranked by how many features they share with Tpotce.
  • dtag-dev-sec/tpotcedtag-dev-sec avatar

    dtag-dev-sec/tpotce

    9,281View on GitHub↗

    T-Pot is a multi-honeypot orchestration platform and threat intelligence collector. It utilizes a Docker-based security sandbox to deploy and manage a collection of diverse decoy services that simulate vulnerable targets to lure attackers and record their activity. The system features a distributed sensor network where remote nodes capture attack logs and transmit them via encrypted communication to a central hub. This central hub employs an analytics stack to transform raw logs into geographic maps and interactive dashboards for adversary behavior visualization. To increase the realism of si

    Shell
    View on GitHub↗9,281
  • hacklcx/hfishhacklcx avatar

    hacklcx/HFish

    4,517View on GitHub↗

    HFish is a distributed honeypot system and network intrusion detection tool designed to deploy decoy services and nodes to detect and analyze attacker behavior. It functions as a deceptive asset orchestrator that simulates enterprise services and configures custom baits to lure network intruders. The system utilizes a server-client architecture to manage distributed nodes across different platforms, allowing for centralized control of telemetry collection and decoy deployment. It incorporates cloud-based traffic routing to redirect suspicious network activity into managed decoy environments f

    honeypothunting
    View on GitHub↗4,517
  • opencti-platform/openctiOpenCTI-Platform avatar

    OpenCTI-Platform/opencti

    8,812View on GitHub↗

    OpenCTI is a cyber threat intelligence platform and knowledge base used to store, manage, and analyze technical security data. It functions as a threat intelligence visualization tool and an enterprise security data orchestrator that maps relationships between threat actors, malware, and vulnerabilities. The platform utilizes the STIX and TAXII standards for data representation and exchange, allowing for the sharing and receiving of standardized intelligence bundles. It distinguishes itself by converting complex security information into visual relationship diagrams and geographic maps to ide

    TypeScriptcticybercybersecurity
    View on GitHub↗8,812
  • jekil/awesome-hackingjekil avatar

    jekil/awesome-hacking

    3,746View on GitHub↗

    This project is a curated, version-controlled directory of software and resources designed for cybersecurity professionals and researchers. It functions as a centralized knowledge base that aggregates and organizes external security utilities into a structured taxonomy to facilitate discovery and access for specialized research and testing tasks. The repository distinguishes itself through a community-driven model where external resource locations are verified and maintained by contributors. By leveraging a distributed version control system, the project ensures the historical integrity and c

    Pythoncurated-listforensicshacking
    View on GitHub↗3,746
See all 30 alternatives to Tpotce→