T-Pot
An all-in-one multi-honeypot platform with dashboards for analysing collected attack data.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About T-Pot
T-Pot is a honeypot platform from Deutsche Telekom's security team that runs many honeypots at once in Docker containers, along with tools for collecting, storing and visualising the attacks they record. An installer sets up the whole stack on a dedicated host.
It suits researchers, educators and security teams who want to observe real-world attack traffic against exposed services. It is a large deployment rather than a single small daemon.
Strengths
- Many honeypots in one installation
- Dashboards for exploring attack data
- Container-based deployment with an installer
- Widely used and actively maintained
Limitations
- Needs a dedicated machine with considerable resources
- Exposing honeypots to the internet needs care and network isolation
Details
- Pricing
- FreeFree and open source.
- License
- GPL-3.0
- Developer
- Telekom Security
- Platforms
- Linux, Self-hosted
- How it runs
- Self-hosted
- Account
- Not required
- Best suited for
- Security researchers who want to collect and study real attack traffic
- Categories
- Network tools, Security tools
- Last verified
- Added
- Provenance
- Facts checked against the developer's own pages and store listings, 1 sources on file.
Alternatives to T-Pot
Compare allSoftware that can replace T-Pot for an important use case, and what changes if you switch.
OpenCanary
A lightweight multi-protocol honeypot daemon that alerts when someone touches fake network services.
OpenCanary is a lightweight single honeypot daemon for internal early warning, needing far fewer resources but lacking T-Pot's many honeypots and dashboards.
T-Pot as an alternative
Listings that name T-Pot as an alternative.
Canarytokens
A free web tool that creates tripwire tokens which alert you when an attacker triggers them.
T-Pot is a self-hosted multi-honeypot platform with dashboards for studying attack traffic, heavier to run than Canarytokens' hosted tripwires.
Similar software
Related functionality, not necessarily a direct replacement.
Security Onion
A free Linux distribution for network security monitoring, packet capture, detection and threat hunting.
Malcolm
A self-hosted network traffic analysis suite that turns PCAP files, Zeek logs and Suricata alerts into searchable dashboards.
Suricata
Inspect network traffic with an intrusion-detection engine.
MISP
An open-source threat intelligence platform for sharing, storing and correlating indicators of compromise.