Skip to content

A honeypot for intruders inside the perimeter

The appliance deploys a decoy in your network. A legitimate employee has no reason to touch it, so any request is a signal: somebody is already inside and looking around.

emulated decoy services
10emulated decoy services
interaction levels
2interaction levels
false positives by design
0false positives by design
Vulnerability emulator · Sessions
Сессии высокоинтерактивного эмулятора уязвимостей: карточки Telnet- и SSH-подключений злоумышленников с индикаторами активности
Every intrusion attempt is a session card with the source address, start time and an activity indicator. An active session can be watched in real time.

How it works

The decoy is a deliberately vulnerable and misconfigured system left open to attack. Its only job is to draw the attention of somebody who already made it into the internal infrastructure, and to collect information about their tools and tactics.

The low interaction part emulates a set of network services on characteristic ports and records everything that arrives, down to a hexadecimal dump of the received data. It answers the question of who is scanning what inside the network.

The high interaction part exposes Telnet and SSH and lets the intruder in. Every command they type lands in the session log: login attempts, password guessing, directory traversal, utility launches. A session can be watched live in the console while it is still running.

What gets recorded

Session events
  • Successful login with a guessed password
  • Failed login attempt
  • Entered command with exact timing
  • Connection established and closed
  • Session duration in seconds
  • Source address and port
Summary statistics
  • Daily chart of trigger counts
  • Top 10 addresses by number of requests
  • Distribution by country on a world map
  • Distribution across decoy ports
  • Counter of requests from local addresses
Vulnerability emulator · Session log
Журнал сессии ловушки с командами, которые вводил злоумышленник, и живая консоль наблюдения за сессией
The high interaction decoy records every command entered, with exact timing and session duration. You can see what the intruder did and which tools they used.
Vulnerability emulator · Source map
Карта мира с подсветкой стран, из которых зафиксированы обращения к ловушке
A world map highlighting the countries requests came from, plus a counter of local addresses. Local addresses matter most: those come from inside your own network.

Which services are emulated

Low interaction decoy

Ten services on characteristic ports: MQTT, BitTorrent, SMTP, RDP, SMB, FTP, SIP, Jabber on two ports and Memcache. Every request lands in the log with its handler.

High interaction decoy

Telnet on four external ports and SSH on a dedicated port. The intruder gets a working shell, and the appliance gets a full record of their actions.

Statistics period

The last month is shown by default. The maximum statistics period is 31 days.

Decoy ports

ServicePortWhat is usually sought
RDP3389Windows remote desktop
SMB445Shared folders and file transfer
FTP21File exchange with weak authentication
SMTP25Open mail relay
SIP5060IP telephony
MQTT1883Industrial sensors and telemetry
Memcache11211Cache without authentication
Jabber5222, 5223Corporate messaging
BitTorrent6969File sharing traffic
Telnet23, 2223, 2323, 23231Equipment with factory passwords
SSH22222Password guessing and remote control

We will prepare a quote for your network

Tell us about your infrastructure: how many sites, which switch sits in the core, whether you already run a SIEM. We will pick the edition and the connection scheme, and calculate the cost.

  • We reply within one business day
  • We design the connection scheme for your topology
  • We show the interface on a live demo unit

Request a quote

Leave a phone number or an email so we can reply.

By submitting this form you agree to our privacy policy.