# telekom-security/tpotce

**Attribution required: if you use, quote, or summarise this content, you must credit and link back to [awesome-repositories.com](https://awesome-repositories.com/repository/telekom-security-tpotce).**

9,298 stars · 1,376 forks · Shell · GPL-3.0

## Links

- GitHub: https://github.com/telekom-security/tpotce
- awesome-repositories: https://awesome-repositories.com/repository/telekom-security-tpotce.md

## Topics

`deception` `docker` `elk` `honeypot` `network-security` `security` `t-pot`

## Description

T-Pot is a multi-honeypot platform and threat intelligence framework that deploys a collection of containerized decoy services to capture attacker behavior and network telemetry. It functions as a Docker-based deception system, simulating vulnerable network environments to gather intelligence on threat actors.

The system features a distributed sensor network using a hub-and-spoke architecture, allowing remote sensors to transmit logs back to a central management hub. It integrates large language models to create a dynamic deception engine capable of adaptive interactions with attackers.

The platform covers a broad range of security capabilities, including the emulation of vulnerable services, passive network traffic analysis, and the use of HTTP tarpitting to exhaust attacker resources. Captured event logs are aggregated into real-time dashboards and geographic maps for threat data visualization.

Administrative access to the tool suite and dashboards is managed through a reverse proxy and authenticated web access control.

## Tags

### Part of an Awesome List

- [Honeypots and Deception](https://awesome-repositories.com/f/awesome-lists/security/honeypots-and-deception.md) — Deploys simulated vulnerable services and HTTP tarpits to mislead attackers and capture their behavior.
- [Honeypot Management](https://awesome-repositories.com/f/awesome-lists/security/honeypot-management.md) — Runs a collection of simulated vulnerable services in containers to capture attacker behavior and telemetry.
- [Multi-Service Honeypots](https://awesome-repositories.com/f/awesome-lists/security/multi-service-honeypots.md) — Runs a diverse collection of containerized services to simulate vulnerable systems and capture wide-ranging attacker activity. ([source](https://github.com/telekom-security/tpotce#readme))
- [Threat Intelligence](https://awesome-repositories.com/f/awesome-lists/security/threat-intelligence.md) — Collects and analyzes network attack data to identify threat actors and contribute to global security research.
- [Threat Intelligence Platforms](https://awesome-repositories.com/f/awesome-lists/devops/threat-intelligence-platforms.md) — Provides capabilities to share captured attack data with community backends and third-party threat intelligence brokers. ([source](https://github.com/telekom-security/tpotce/blob/master/README.md))

### DevOps & Infrastructure

- [Deceptive Environments](https://awesome-repositories.com/f/devops-infrastructure/container-orchestration/container-runtimes/runtime-configuration-interfaces/docker-socket-orchestrators/docker-target-configurators/docker-container-deployments/deceptive-environments.md) — Deploys a collection of simulated vulnerable services in Docker containers to mimic real network environments.
- [Container Orchestrators](https://awesome-repositories.com/f/devops-infrastructure/container-orchestrators.md) — Orchestrates a diverse collection of simulated vulnerable services in isolated containers to capture attacker activity.
- [Hub-and-Spoke Agent Deployment](https://awesome-repositories.com/f/devops-infrastructure/distributed-deployment/hub-and-spoke-agent-deployment.md) — Implements a hub-and-spoke architecture where remote sensors host services and transmit telemetry to a central hub.
- [Deployment Configuration](https://awesome-repositories.com/f/devops-infrastructure/deployment-configuration.md) — Allows configuring an instance to act as either a central management hub or a remote sensor that pushes data. ([source](https://github.com/telekom-security/tpotce/blob/master/env.example))

### Security & Cryptography

- [AI-Driven Deception](https://awesome-repositories.com/f/security-cryptography/network-deception-technologies/ai-driven-deception.md) — Uses large language models to create dynamic and adaptive simulated environments that interact realistically with attackers.
- [LLM-Powered Deception](https://awesome-repositories.com/f/security-cryptography/network-deception-technologies/llm-powered-deception.md) — Integrates large language models to simulate realistic network services and adaptive interactions with attackers.
- [Threat Intelligence Platforms](https://awesome-repositories.com/f/security-cryptography/threat-intelligence-platforms.md) — Aggregates captured honeypot data into dashboards and maps for global cyber threat analysis.
- [Remote Service Credential Captures](https://awesome-repositories.com/f/security-cryptography/identity-access-management/credential-lifecycle-management/credential-security/credential-extraction-utilities/network-credential-capturers/remote-service-credential-captures.md) — Mimics common network services like RDP and API servers to capture credential telemetry and attacker behavior. ([source](https://github.com/telekom-security/tpotce/blob/master/CHANGELOG.md))
- [Network Deception Technologies](https://awesome-repositories.com/f/security-cryptography/network-deception-technologies.md) — Uses simulated services and AI-driven interactions as network deception technologies to lure and analyze attackers. ([source](https://github.com/telekom-security/tpotce/blob/master/README.md))
- [HTTP Tarpits](https://awesome-repositories.com/f/security-cryptography/tarpit-data-emission/http-tarpits.md) — Slows down bot requests by feeding them an infinite stream of fake secrets to exhaust attacker resources. ([source](https://github.com/telekom-security/tpotce/blob/master/CHANGELOG.md))

### Software Engineering & Architecture

- [Distributed Sensor Networks](https://awesome-repositories.com/f/software-engineering-architecture/namespace-management/distributed-sensor-networks.md) — Deploys remote sensors that capture traffic and transmit log data to a central hub for consolidated analysis.

### Artificial Intelligence & ML

- [Interactive Honeypots](https://awesome-repositories.com/f/artificial-intelligence-ml/generative-ai-resources/generative-ai/llm-model-integrations/interactive-honeypots.md) — Integrates large language models to create dynamic and realistic simulations for adversary engagement within honeypots.

### Data & Databases

- [Search Engine Dashboards](https://awesome-repositories.com/f/data-databases/data-visualization-dashboards/search-engine-dashboards.md) — Aggregates captured event logs into a search engine to provide real-time dashboards and geographic attack maps.

### System Administration & Monitoring

- [Passive Traffic Analyzers](https://awesome-repositories.com/f/system-administration-monitoring/network-traffic-analysis/passive-traffic-analyzers.md) — Extracts network metadata and fingerprints traffic passively to monitor security events without interfering with attackers.
- [Network Traffic Dashboards](https://awesome-repositories.com/f/system-administration-monitoring/real-time-metric-visualization/network-traffic-dashboards.md) — Converts captured security events into real-time dashboards and geographic maps to monitor active attack patterns.

### Web Development

- [Attack Data Dashboards](https://awesome-repositories.com/f/web-development/real-time-data-streaming/websocket-dashboards/attack-data-dashboards.md) — Aggregates security events into real-time dashboards and animated geographic maps to analyze attacker behavior. ([source](https://github.com/telekom-security/tpotce/blob/master/CHANGELOG.md))
