awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
thinkst avatar

thinkst/opencanary

0
View on GitHub↗
2,776 stars·395 forks·Python·bsd-3-clause·17 viewsopencanary.org↗

Opencanary

OpenCanary is a network service simulator and honeypot designed for network intrusion detection. It functions as a security decoy that creates fake server personalities and open ports to identify unauthorized users scanning a private network.

The system uses deception technology to mimic various server protocols, luring attackers into revealing their presence and activity. When a simulated service is accessed, it acts as an intrusion alerting gateway, transmitting notifications via email or webhooks.

The project covers internal network monitoring and intrusion source tracking to identify the location of security breaches. It utilizes a plugin-based architecture for service personalities and supports containerized deployment for consistent execution across different operating systems.

Features

  • Service Emulators - Mimics common network protocols through fake socket listeners to lure and identify unauthorized traffic.
  • Service Honeypots - Functions as a service honeypot that emulates network protocols to detect unauthorized scanning.
  • Service Network Mocks - Provides simulated network listeners and target groups to identify intruders scanning the network.
  • Deceptive Service Mocks - Mimics various server personalities to attract unauthorized users and identify their activity.
  • Security Access Alerts - Sends immediate security-critical access alerts via email or webhooks upon detection of an intruder.
  • Packet Source Identifiers - Captures the remote network addresses of incoming packets to identify the source of a breach.
  • Network Deception Technologies - Employs deception technology by creating simulated server personalities to trick attackers into revealing themselves.
  • Network Intrusion Detection - Detects unauthorized network access by alerting administrators when fake services are interacted with.
  • Decoy Services - Acts as a specialized decoy service designed to lure attackers and record their activity in a sandbox.
  • Plugin-Based Architectures - Uses a modular plugin architecture to define different server personalities and their responses to intruders.
  • Event-Driven Notification Triggers - Triggers immediate security notifications via webhooks or email when simulated services are accessed.
  • Intrusion Source Monitoring - Tracks interactions with simulated services to identify the specific source and location of security breaches.
  • Containerized Deployments - Provides a containerized environment to ensure consistent deployment of security decoys across different operating systems.
  • Deceptive Protocol Configurations - Allows the definition of specific network protocols and ports to simulate for the purpose of identifying intruders.
  • Alerting Integrations - Integrates with external notification services like webhooks and email to deliver breach alerts.
  • Network Alerting Systems - Serves as a backend triggering system that notifies external platforms when security risks are detected.
  • Security Lab Environments - Deception tool for detecting unauthorized network activity.

Star history

Star history chart for thinkst/opencanaryStar history chart for thinkst/opencanary

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does thinkst/opencanary do?

OpenCanary is a network service simulator and honeypot designed for network intrusion detection. It functions as a security decoy that creates fake server personalities and open ports to identify unauthorized users scanning a private network.

What are the main features of thinkst/opencanary?

The main features of thinkst/opencanary are: Service Emulators, Service Honeypots, Service Network Mocks, Deceptive Service Mocks, Security Access Alerts, Packet Source Identifiers, Network Deception Technologies, Network Intrusion Detection.

What are some open-source alternatives to thinkst/opencanary?

Open-source alternatives to thinkst/opencanary include: hacklcx/hfish — HFish is a distributed honeypot system and network intrusion detection tool designed to deploy decoy services and… stamparm/maltrail — Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network… blacklanternsecurity/bbot — This project is an open-source intelligence reconnaissance framework and recursive attack surface mapper. It functions… security-onion-solutions/securityonion — Security Onion is a security information and event management platform and network security monitoring suite. It… magicmirrororg/magicmirror — MagicMirror is an open source framework for creating personalized information dashboards, specifically designed for… k4yt3x/video2x — Video2x is a modular processing framework designed for AI-enhanced video upscaling and frame rate conversion. It…

Open-source alternatives to Opencanary

Similar open-source projects, ranked by how many features they share with Opencanary.
  • hacklcx/hfishhacklcx avatar

    hacklcx/HFish

    4,517View on GitHub↗

    HFish is a distributed honeypot system and network intrusion detection tool designed to deploy decoy services and nodes to detect and analyze attacker behavior. It functions as a deceptive asset orchestrator that simulates enterprise services and configures custom baits to lure network intruders. The system utilizes a server-client architecture to manage distributed nodes across different platforms, allowing for centralized control of telemetry collection and decoy deployment. It incorporates cloud-based traffic routing to redirect suspicious network activity into managed decoy environments f

    honeypothunting
    View on GitHub↗4,517
  • stamparm/maltrailstamparm avatar

    stamparm/maltrail

    8,498View on GitHub↗

    Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o

    Pythonattack-detectionintrusion-detectionmalware
    View on GitHub↗8,498
  • blacklanternsecurity/bbotblacklanternsecurity avatar

    blacklanternsecurity/bbot

    9,929View on GitHub↗

    This project is an open-source intelligence reconnaissance framework and recursive attack surface mapper. It functions as a containerized security scanner designed to map public-facing infrastructure, perform subdomain enumeration, and automate the gathering of open-source intelligence. The system employs a recursive discovery engine to iteratively explore target infrastructure, utilizing a plugin-based module architecture to extend scanning capabilities. It integrates third-party APIs for data enrichment and applies YARA rules across discovered assets to identify specific vulnerability patte

    Python
    View on GitHub↗9,929
  • security-onion-solutions/securityonionSecurity-Onion-Solutions avatar

    Security-Onion-Solutions/securityonion

    4,661View on GitHub↗

    Security Onion is a security information and event management platform and network security monitoring suite. It functions as an intrusion detection system and a network traffic analysis tool designed to identify malicious activity and network intrusions through signature-based detection and host-based monitoring. The platform integrates a security case management system to organize investigations by tracking detections and grouping related security events. It provides capabilities for full packet capture, network metadata extraction, and the collection and indexing of security logs from dive

    Shell
    View on GitHub↗4,661
See all 30 alternatives to Opencanary→