T-Pot
All-in-one honeypot platform that Dockerizes more than twenty honeypots with an ELK dashboard.
Technical Architecture & Overview
T-Pot, maintained by Deutsche Telekom Security, packages honeypots such as Cowrie, Dionaea, and Herald into a single Docker Compose deployment with shared logging, an Elastic stack, and attack map dashboards. A standard install turns one host into a multi-protocol sensor, and attack data can feed community dashboards or be kept private. The project releases on a regular cadence.
Targeted Technical Use Cases
Running a broad external-facing sensor platform on a single host to collect attacker tradecraft.
Evaluation & Trade-offs
Core Strengths
- +Many honeypots in one maintained deployment.
- +Dashboards and storage included.
- +Active maintenance by a corporate security team.
Trade-Offs & Limitations
- -Resource footprint is substantial for a single host.
- -Mostly oriented to internet-facing collection rather than internal deception.
Defensive Security Application
Observing real attacker behavior in the wild and converting it into detections and indicators.
Frequently Asked Questions
What is T-Pot?→
T-Pot, maintained by Deutsche Telekom Security, packages honeypots such as Cowrie, Dionaea, and Herald into a single Docker Compose deployment with shared logging, an Elastic stack, and attack map dashboards. A standard install turns one host into a multi-protocol sensor, and attack data can feed community dashboards or be kept private. The project releases on a regular cadence.
What is T-Pot used for?→
Running a broad external-facing sensor platform on a single host to collect attacker tradecraft.
What are the strengths of T-Pot?→
- +Many honeypots in one maintained deployment.
- +Dashboards and storage included.
- +Active maintenance by a corporate security team.
What are the limitations of T-Pot?→
- +Resource footprint is substantial for a single host.
- +Mostly oriented to internet-facing collection rather than internal deception.
How is T-Pot used defensively?→
Observing real attacker behavior in the wild and converting it into detections and indicators.