For o platformă de deception și decoy, the strongest matches are telekom-security/tpotce (T-Pot is a multi-honeypot platform that deploys containerized decoy), thinkst/opencanary (OpenCanary is a self-hosted honeypot that simulates multiple network) and dtag-dev-sec/tpotce (T-Pot is a multi-honeypot orchestration platform that deploys decoy). honeytrap/honeytrap and cowrie/cowrie round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Instrumente de securitate open-source care implementează servicii false și honeytoken-uri pentru a detecta și analiza activitatea neautorizată în rețea.
T-Pot is a multi-honeypot platform and threat intelligence framework that deploys a collection of containerized decoy services to capture attacker behavior and network telemetry. It functions as a Docker-based deception system, simulating vulnerable network environments to gather intelligence on threat actors. The system features a distributed sensor network using a hub-and-spoke architecture, allowing remote sensors to transmit logs back to a central management hub. It integrates large language models to create a dynamic deception engine capable of adaptive interactions with attackers. The
T-Pot is a multi-honeypot platform that deploys containerized decoy services to detect and log attacker behavior, with Docker-based deployment, threat intelligence integration, and monitoring dashboards — exactly the self-hosted deception platform this search targets.
OpenCanary is a network service simulator and honeypot designed for network intrusion detection. It functions as a security decoy that creates fake server personalities and open ports to identify unauthorized users scanning a private network. The system uses deception technology to mimic various server protocols, luring attackers into revealing their presence and activity. When a simulated service is accessed, it acts as an intrusion alerting gateway, transmitting notifications via email or webhooks. The project covers internal network monitoring and intrusion source tracking to identify the
OpenCanary is a self-hosted honeypot that simulates multiple network services to detect and alert on attacker activity, fitting the core need for decoy service emulation and attack detection, though it lacks a built-in real-time dashboard and traffic redirection.
T-Pot is a multi-honeypot orchestration platform and threat intelligence collector. It utilizes a Docker-based security sandbox to deploy and manage a collection of diverse decoy services that simulate vulnerable targets to lure attackers and record their activity. The system features a distributed sensor network where remote nodes capture attack logs and transmit them via encrypted communication to a central hub. This central hub employs an analytics stack to transform raw logs into geographic maps and interactive dashboards for adversary behavior visualization. To increase the realism of si
T-Pot is a multi-honeypot orchestration platform that deploys decoy services to detect and log attacker activity, with Docker-based easy deployment, real-time dashboards, and support for multiple protocols — exactly the self-hosted deception platform with attack detection and network deception you're looking for.
Advanced Honeypot framework.
Honeytrap is a Go-based honeypot framework that emulates decoy services to detect attackers, fitting the category of a self-hosted deception platform. You can deploy it on-premises to run various protocol honeypots, though it may lack a built-in monitoring dashboard or Docker packaging.
.. SPDX-FileCopyrightText: 2014 Upi Tamminen .. SPDX-FileCopyrightText: 2014-2025 Michel Oosterhof .. .. SPDX-License-Identifier: BSD-3-Clause
Cowrie is a well-known SSH and telnet honeypot that emulates decoy services and logs attacker activity, fitting the self-hosted honeypot category; however, it focuses on SSH/telnet and may lack a built-in monitoring dashboard, so it's a solid match but not the most comprehensive platform.
ICS/SCADA honeypot
Conpot is a self-hosted honeypot that emulates ICS/SCADA services to detect and alert on attacks targeting industrial control systems, which fits your query as a deception platform, though its focus on industrial protocols means it may lack broader service emulation and a built-in dashboard.