Alternatives to T-Pot
An all-in-one multi-honeypot platform with dashboards for analysing collected attack data. The listings below can replace it for an important use case. Each note says what changes if you switch.
The original
T-Pot
An all-in-one multi-honeypot platform with dashboards for analysing collected attack data.
Replacements
Listings that take over the same core job as T-Pot.
OpenCanary
A lightweight multi-protocol honeypot daemon that alerts when someone touches fake network services.
OpenCanary is a lightweight single honeypot daemon for internal early warning, needing far fewer resources but lacking T-Pot's many honeypots and dashboards.
Also worth comparing
These listings name T-Pot as their own alternative, so the relationship runs both ways.
Canarytokens
A free web tool that creates tripwire tokens which alert you when an attacker triggers them.
T-Pot is a self-hosted multi-honeypot platform with dashboards for studying attack traffic, heavier to run than Canarytokens' hosted tripwires.
Similar software
Related functionality, not a direct replacement.
Security Onion
A free Linux distribution for network security monitoring, packet capture, detection and threat hunting.
Malcolm
A self-hosted network traffic analysis suite that turns PCAP files, Zeek logs and Suricata alerts into searchable dashboards.
Suricata
Inspect network traffic with an intrusion-detection engine.
MISP
An open-source threat intelligence platform for sharing, storing and correlating indicators of compromise.