awesome-repositories.com
博客
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
dtag-dev-sec avatar

dtag-dev-sec/tpotce

0
View on GitHub↗
9,281 星标·1,375 分支·Shell·GPL-3.0·7 次浏览

Tpotce

T-Pot is a multi-honeypot orchestration platform and threat intelligence collector. It utilizes a Docker-based security sandbox to deploy and manage a collection of diverse decoy services that simulate vulnerable targets to lure attackers and record their activity.

The system features a distributed sensor network where remote nodes capture attack logs and transmit them via encrypted communication to a central hub. This central hub employs an analytics stack to transform raw logs into geographic maps and interactive dashboards for adversary behavior visualization. To increase the realism of simulated targets, the platform integrates large language models.

Broad capabilities include automated environment installation across Linux distributions, passive network fingerprinting, and the ability to filter out mass scanner traffic to reduce noise. The platform also supports exporting captured security event data to community backends and third-party global threat feeds.

Features

  • Honeypot Environments - Integrates large language models and diverse services to create realistic targets that trick attackers.
  • Threat Intelligence Platforms - Manages a distributed network of sensors to collect and transmit attacker logs to a central hub.
  • Threat Intelligence - Enables the contribution of captured attack data to community backends and global threat intelligence feeds.
  • Analytics Dashboards - Transforms raw attack logs into interactive dashboards and geographic maps for behavioral visualization.
  • Container Environment Orchestrators - Deploys diverse vulnerable services in isolated containers to simulate targets and capture attacker activity.
  • Decoy Service Deployments - Deploys a collection of diverse services in a single environment to analyze network attack data across various ports.
  • Distributed Deployment - Coordinates a network of remote sensors that relay captured intruder activity back to a central server.
  • Remote Monitoring Transmission - Transmits captured attack data from distributed remote installations to a central hub for aggregated analysis.
  • Attack Data Collection - Captures and persists network traffic and attacker logs to facilitate detailed security analysis.
  • Cyber Threat Intelligence Maps - Visualizes captured network traffic and intruder behavior using centralized dashboards and geographic maps.
  • Secure Sandboxing - Uses Docker containers to create isolated security sandboxes that simulate vulnerable services without risking the host system.
  • Decoy Services - Deploys a collection of diverse decoy services to simulate vulnerable targets and capture network attack data.
  • Centralized Logging Systems - Aggregates attack logs from multiple remote sensors into a centralized system for unified monitoring.
  • Distributed Log Aggregation - Collects and synchronizes security event data from multiple remote sensors into a centralized hub for analysis.
  • Sensor Network Coordination - Deploys and coordinates multiple remote sensors to collect threat intelligence across different network locations.
  • Interactive Honeypots - Integrates large language models to power interactive simulations that act as realistic targets for attackers.
  • Behavior Visualizations - Visualizes captured attack traffic through integrated dashboards and geographic maps to analyze adversary behavior.
  • Data Persistence and Storage - Stores collected attack logs and artifacts with configurable retention and purging policies.
  • Automated System Installers - Automates dependency installation, firewall configuration, and system setup across various Linux distributions.
  • Communication Encryption - Protects data transit between remote collection nodes and the central server using SSL certificates.
  • Device Fingerprinting - Extracts metadata and device identifiers from live traffic using passive network fingerprinting.
  • Infrastructure Fingerprinters - Extracts network metadata and fingerprints from live traffic using passive fingerprinting engines to identify infrastructure.
  • Open Source Intelligence Tools - Collects open source intelligence and utilizes encoding and decryption tools to investigate attacker behavior.
  • Security Analysis Dashboards - Provides a centralized security analysis dashboard using the ELK stack to visualize attack patterns and geographic maps.
  • Traffic Filtering Systems - Null-routes traffic from known mass scanners at the network level to reduce noise in threat intelligence.
  • Honeypot Management - All-in-one honeypot appliance for rapid deployment.

Star 历史

dtag-dev-sec/tpotce 的 Star 历史图表dtag-dev-sec/tpotce 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

常见问题解答

dtag-dev-sec/tpotce 是做什么的?

T-Pot is a multi-honeypot orchestration platform and threat intelligence collector. It utilizes a Docker-based security sandbox to deploy and manage a collection of diverse decoy services that simulate vulnerable targets to lure attackers and record their activity.

dtag-dev-sec/tpotce 的主要功能有哪些?

dtag-dev-sec/tpotce 的主要功能包括:Honeypot Environments, Threat Intelligence Platforms, Threat Intelligence, Analytics Dashboards, Container Environment Orchestrators, Decoy Service Deployments, Distributed Deployment, Remote Monitoring Transmission。

dtag-dev-sec/tpotce 有哪些开源替代品?

dtag-dev-sec/tpotce 的开源替代品包括: stamparm/maltrail — Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network… telekom-security/tpotce — T-Pot is a multi-honeypot platform and threat intelligence framework that deploys a collection of containerized decoy… crowdsecurity/crowdsec — CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection.… cube-js/cube — Cube is a semantic data layer that provides a unified framework for defining business metrics, dimensions, and… linkedin/school-of-sre — This project is a comprehensive educational resource and curriculum focused on site reliability engineering,… misp/misp — MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing…

Tpotce 的开源替代方案

相似的开源项目,按与 Tpotce 的功能重合度排序。
  • stamparm/maltrailstamparm 的头像

    stamparm/maltrail

    8,498在 GitHub 上查看↗

    Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o

    Pythonattack-detectionintrusion-detectionmalware
    在 GitHub 上查看↗8,498
  • telekom-security/tpotcetelekom-security 的头像

    telekom-security/tpotce

    9,298在 GitHub 上查看↗

    T-Pot is a multi-honeypot platform and threat intelligence framework that deploys a collection of containerized decoy services to capture attacker behavior and network telemetry. It functions as a Docker-based deception system, simulating vulnerable network environments to gather intelligence on threat actors. The system features a distributed sensor network using a hub-and-spoke architecture, allowing remote sensors to transmit logs back to a central management hub. It integrates large language models to create a dynamic deception engine capable of adaptive interactions with attackers. The

    Shelldeceptiondockerelk
    在 GitHub 上查看↗9,298
  • crowdsecurity/crowdseccrowdsecurity 的头像

    crowdsecurity/crowdsec

    12,574在 GitHub 上查看↗

    CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection. It functions as an intrusion detection system that parses logs and network traffic to identify malicious patterns, utilizing a bucket-based threshold detection model to aggregate events and trigger alerts. The platform is built on a modular architecture that includes a centralized local API server for managing security signals and a relational database for persistent storage of remediation decisions. What distinguishes the project is its decoupled enforcement model, which offl

    Goattacks-preventiondetectionids
    在 GitHub 上查看↗12,574
  • cube-js/cubecube-js 的头像

    cube-js/cube

    20,251在 GitHub 上查看↗

    Cube is a semantic data layer that provides a unified framework for defining business metrics, dimensions, and relationships across diverse data sources. By acting as a headless business intelligence engine, it transforms raw data into a governed model that can be queried via SQL, REST, and GraphQL interfaces. This architecture ensures consistent data definitions and logic across all downstream analytical applications and reporting tools. The platform distinguishes itself through its integrated conversational AI capabilities, which allow users to explore data using natural language. It orches

    Rustagentic-analyticsagentsai
    在 GitHub 上查看↗20,251
  • 查看 Tpotce 的所有 30 个替代方案→