Honeypot & Deception Tools
Honeypots and deception tools deploy decoy assets that trigger an alert when touched. Because legitimate users have no reason to reach a decoy, alerts from these tools carry little false-positive noise.
| Tool | License | Platforms | Pricing | Action |
|---|---|---|---|---|
| Beelzebub | GPL-3.0-or-later | Linux, macOS, Windows | Open Source | Profile→ |
| Canarytokens | GPL-3.0-or-later | Web | Free | Profile→ |
| Conpot | GPL-2.0-or-later | Linux | Open Source | Profile→ |
| Cowrie | BSD-3-Clause | Linux | Open Source | Profile→ |
| Dionaea | GPL-2.0-or-later | Linux | Open Source | Profile→ |
| OpenCanary | BSD-3-Clause | Linux, macOS | Open Source | Profile→ |
| T-Pot | GPL-3.0-or-later | Linux | Open Source | Profile→ |
| Thinkst Canary | Proprietary | Web, Hardware | Commercial | Profile→ |
Software in Honeypot & Deception Tools
Beelzebub
Open SourceLow-code deception framework that virtualizes honeypot services, with optional LLM-driven responses.
Canarytokens
FreeFree tripwire token service that alerts when attacker-tripped files, URLs, or credentials are used.
Conpot
Open SourceLow-interaction ICS/SCADA honeypot simulating industrial controllers and protocols.
Cowrie
Open SourceMedium to high interaction SSH and Telnet honeypot that records attacker sessions.
Dionaea
Open SourceLow-interaction honeypot that captures attacking malware over SMB, HTTP, FTP, and MQTT.
OpenCanary
Open SourceOpen source multi-protocol daemon honeypot from the Thinkst Canary project.
T-Pot
Open SourceAll-in-one honeypot platform that Dockerizes more than twenty honeypots with an ELK dashboard.
Thinkst Canary
CommercialCommercial deception platform built around canary devices, decoys, and a hosted console.
Frequently Asked Questions
What is Honeypot & Deception Tools?→
Honeypots and deception tools deploy decoy assets that trigger an alert when touched. Because legitimate users have no reason to reach a decoy, alerts from these tools carry little false-positive noise.
What topics does the Honeypot & Deception Tools category cover?→
Network Honeypots, Deception Grids, Canary Tokens, Attacker Fingerprinting, Threat Detection Decoys
About Honeypot & Deception Tools
Honeypots and deception tools place fake assets where only an attacker should find them. The category includes service honeypots that imitate SSH servers, databases, web applications, or industrial controllers and log every interaction, canary tokens that are files, URLs, or credentials which alert when used, and deception platforms that coordinate many decoys across a network. Alerts from deception assets are high fidelity, so defenders use them to detect intrusions that signature and anomaly systems miss, to learn attacker tradecraft, and to slow intruders down while response starts. Interactivity is the main design axis: low-interaction honeypots emulate a protocol enough to capture scans and automated malware, while high-interaction honeypots run real services in a controlled cage and capture more behavior at higher risk. The category overlaps with detection engineering, since honeypot alerts usually route into the same pipelines as other detections, and with threat intelligence, since captured payloads and attacker sources feed IOC collection.
Covered Topics & Disciplines
Related Security Categories
Packet capture tools, protocol analyzers, and network security monitors for traffic visibility.
SIEM platforms, EDR agents, SOAR automation, and detection rule engines for security operations.
Threat intelligence platforms, IOC sharing communities, and STIX/TAXII tooling for collecting and distributing threat data.