Skip to main content
ToolLicensePlatformsPricingAction
BeelzebubGPL-3.0-or-laterLinux, macOS, WindowsOpen SourceProfile
CanarytokensGPL-3.0-or-laterWebFreeProfile
ConpotGPL-2.0-or-laterLinuxOpen SourceProfile
CowrieBSD-3-ClauseLinuxOpen SourceProfile
DionaeaGPL-2.0-or-laterLinuxOpen SourceProfile
OpenCanaryBSD-3-ClauseLinux, macOSOpen SourceProfile
T-PotGPL-3.0-or-laterLinuxOpen SourceProfile
Thinkst CanaryProprietaryWeb, HardwareCommercialProfile

Software in Honeypot & Deception Tools

Beelzebub

Open Source

Low-code deception framework that virtualizes honeypot services, with optional LLM-driven responses.

LicenseGPL-3.0-or-later
PlatformLinux, macOS, Windows

Free tripwire token service that alerts when attacker-tripped files, URLs, or credentials are used.

LicenseGPL-3.0-or-later
PlatformWeb

Conpot

Open Source

Low-interaction ICS/SCADA honeypot simulating industrial controllers and protocols.

LicenseGPL-2.0-or-later
PlatformLinux

Cowrie

Open Source

Medium to high interaction SSH and Telnet honeypot that records attacker sessions.

LicenseBSD-3-Clause
PlatformLinux

Dionaea

Open Source

Low-interaction honeypot that captures attacking malware over SMB, HTTP, FTP, and MQTT.

LicenseGPL-2.0-or-later
PlatformLinux

OpenCanary

Open Source

Open source multi-protocol daemon honeypot from the Thinkst Canary project.

LicenseBSD-3-Clause
PlatformLinux, macOS

T-Pot

Open Source

All-in-one honeypot platform that Dockerizes more than twenty honeypots with an ELK dashboard.

LicenseGPL-3.0-or-later
PlatformLinux

Thinkst Canary

Commercial

Commercial deception platform built around canary devices, decoys, and a hosted console.

LicenseProprietary
PlatformWeb, Hardware

Frequently Asked Questions

What is Honeypot & Deception Tools?

Honeypots and deception tools deploy decoy assets that trigger an alert when touched. Because legitimate users have no reason to reach a decoy, alerts from these tools carry little false-positive noise.

What topics does the Honeypot & Deception Tools category cover?

Network Honeypots, Deception Grids, Canary Tokens, Attacker Fingerprinting, Threat Detection Decoys

About Honeypot & Deception Tools

Honeypots and deception tools place fake assets where only an attacker should find them. The category includes service honeypots that imitate SSH servers, databases, web applications, or industrial controllers and log every interaction, canary tokens that are files, URLs, or credentials which alert when used, and deception platforms that coordinate many decoys across a network. Alerts from deception assets are high fidelity, so defenders use them to detect intrusions that signature and anomaly systems miss, to learn attacker tradecraft, and to slow intruders down while response starts. Interactivity is the main design axis: low-interaction honeypots emulate a protocol enough to capture scans and automated malware, while high-interaction honeypots run real services in a controlled cage and capture more behavior at higher risk. The category overlaps with detection engineering, since honeypot alerts usually route into the same pipelines as other detections, and with threat intelligence, since captured payloads and attacker sources feed IOC collection.

Covered Topics & Disciplines

Network HoneypotsDeception GridsCanary TokensAttacker FingerprintingThreat Detection Decoys