License & Deployment Mix: 10 tools – 7 OSS, 3 commercial.
Color: Blue team.
What Is This Category?
Decoy systems, services, credentials, files, and tokens that generate high-fidelity alerts the moment an attacker touches them.
Deception technology plants fake assets that have no legitimate purpose – a fake domain controller, a planted credential, a canary file in a share. Real users have no reason to interact with them, so any touch is a high-fidelity alert. Where IDS / EDR have to distinguish bad from noisy-normal, deception alerts are signal-only by construction.
Distinct from neighbouring categories
- IDS / IPS – IDS detects known-bad patterns; deception detects any interaction with planted assets
- EDR / XDR – EDR watches real hosts for behavioural anomalies; deception watches honeypot hosts that should never see traffic
- SIEM & Log Analytics – SIEM is the consumer of deception alerts, not the deception layer
- Network Detection & Response (NDR) – NDR finds attackers in legitimate traffic; deception waits for them to touch obvious-but-fake bait
The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.
Comparison
Deception Type
What each tool actually is.
| Tool | Type | Surface | Layer |
|---|---|---|---|
| T-Pot | Bundle (20+ honeypots) | Internet / DMZ | Network |
| OpenCanary | Service honeypot | LAN / internal | Network |
| Cowrie | SSH / Telnet medium-interaction | LAN / DMZ | Network |
| Honeytrap | Plugin-based honeypot | Any | Network |
| Conpot | ICS / SCADA honeypot | OT network | Network |
| Dionaea | Low-interaction malware capture | Internet / DMZ | Network |
| Canarytokens (OSS) | Honeytokens | Any | Token / file |
| Thinkst Canary | Managed network honeypots + tokens | LAN / cloud | Network + token |
| Illusive / Proofpoint | Endpoint-side deception | Workstations | Endpoint |
| Acalvio ShadowPlex | Full-fabric distributed | All | Network + endpoint + OT |
License Comparison
| Tool | License | OSI | Type |
|---|---|---|---|
| T-Pot | GPL-3.0-only | yes | OSS bundle |
| OpenCanary | BSD-3-Clause | yes | OSS service |
| Cowrie | BSD-3-Clause | yes | OSS service |
| Honeytrap | Apache-2.0 | yes | OSS framework |
| Conpot | GPL-2.0-only | yes | OSS ICS honeypot |
| Dionaea | GPL-2.0-only | yes | OSS malware-capture |
| Canarytokens (OSS) | BSD-3-Clause | yes | OSS service + free SaaS |
| Thinkst Canary | Proprietary | – | Commercial appliance + SaaS |
| Illusive / Proofpoint | Proprietary | – | Commercial endpoint agent |
| Acalvio ShadowPlex | Proprietary | – | Commercial hybrid platform |
Protocol / Service Coverage
What each network-honeypot tool emulates.
| Tool | SSH | Telnet | SMB | HTTP | MySQL | MSSQL | ICS | VoIP |
|---|---|---|---|---|---|---|---|---|
| T-Pot (bundle) | yes | yes | yes | yes | yes | yes | yes | yes |
| OpenCanary | yes | yes | yes* | yes | yes | yes | – | yes |
| Cowrie | yes | yes | – | – | – | – | – | – |
| Honeytrap | yes | yes | yes | yes | – | – | – | – |
| Conpot | – | – | – | yes | – | – | yes | – |
| Dionaea | – | – | yes | yes | yes | yes | – | yes |
* OpenCanary’s SMB is a banner-only emulator; Dionaea goes deeper on SMB-exploit capture.
SSO / OIDC
Network honeypots are typically headless services with no UI of their own; the SaaS / managed tier handles auth on the console side.
| Tool | OIDC | SAML | SCIM | Notes |
|---|---|---|---|---|
| T-Pot | n/a | n/a | n/a | Kibana UI; Authentik via Traefik forward-auth |
| OpenCanary | n/a | n/a | n/a | No UI; alerts via webhook |
| Cowrie | n/a | n/a | n/a | No UI |
| Honeytrap | n/a | n/a | n/a | No UI |
| Conpot | n/a | n/a | n/a | No UI |
| Dionaea | n/a | n/a | n/a | No UI |
| Canarytokens | n/a | n/a | n/a | Self-hosted; Authentik forward-auth |
| Thinkst Canary | paid | paid | paid | Enterprise tier |
| Illusive / Proofpoint | paid | paid | paid | Enterprise tier |
| Acalvio ShadowPlex | paid | paid | – | Enterprise tier |
Deployment Comparison
| Tool | Deployment | Resources | Privileges |
|---|---|---|---|
| T-Pot | Docker bundle (20+ containers) | 4 CPU / 8 GB / 128 GB | Root for ports + Docker |
| OpenCanary | pip / Docker / package | <50 MB RAM | Listen on chosen ports |
| Cowrie | Docker / virtualenv / package | <100 MB RAM | Listen on ports 22 / 23 |
| Honeytrap | Docker / native | <100 MB RAM | Listen on chosen ports |
| Conpot | Docker / native | <100 MB RAM | Listen on chosen ports |
| Dionaea | Docker / native | <200 MB RAM | Listen on chosen ports |
| Canarytokens (OSS) | Docker Compose | Modest | Public DNS / mail setup |
| Thinkst Canary | Managed appliance + SaaS | – | Switch port for the bird |
| Illusive / Proofpoint | Endpoint agent + SaaS | Endpoint footprint | MDM / SCCM rollout |
| Acalvio ShadowPlex | Distributed controllers + SaaS | Variable | Per-segment controllers |
Composition Patterns
Three canonical deception deployments.
1. Customer external perimeter
T-Pot in DMZ -- catches internet-scale scans Cowrie standalone -- one-protocol depth where T-Pot is overkill Dionaea standalone -- when malware-capture is the priority
Output: high-signal external sensors feeding the customer’s SIEM and a threat-intel platform (MISP).
2. Customer internal network
OpenCanary on each VLAN -- fake internal services Cowrie internal SSH -- fake jump host Canarytokens (kubeconfig, AD canary, AWS key)
Output: high-signal lateral-movement detection inside the customer’s perimeter.
3. Endpoint + identity tier
Proofpoint Identity Threat Defense -- endpoint deception Canarytokens (Office watermark) -- exfil detection
Output: per-host fake credentials / files; alerts on attacker enumeration of real endpoint state.
Cost Tier
Rough TCO for a single customer site.
| Tier | Tooling | Approx Cost |
|---|---|---|
| Free | T-Pot + OpenCanary + Cowrie + Canarytokens (self-host) | $0 + 1 small VM |
| Mid | Thinkst Canary (3-5 birds) | $7,500 / bird / year |
| High | Acalvio ShadowPlex / Illusive enterprise-wide | Enterprise contract |
Tools
10 tools.
Acalvio ShadowPlex
Distributed-deception platform; covers cloud, on-prem, OT, and identity layers; AI-driven deception fabric.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
Canarytokens (OSS)
Honeytoken generator from Thinkst Labs; planted credentials, fake files, beacons that alert on any use; free public service + OSS self-host.
License: BSD-3-Clause (OSS) · Kind: web · Deploy: docker, native · SSO: none
Conpot
ICS / SCADA honeypot emulating PLCs, RTUs, HMIs; Modbus, S7Comm, BACnet, HTTP, SNMP, IPMI; MushMush Foundation.
License: GPL-2.0-only (OSS) · Kind: service · Deploy: docker, native · SSO: none
Cowrie
Medium-interaction SSH and Telnet honeypot; emulates a full shell, records sessions; the dominant SSH honeypot in research and OSS.
License: BSD-3-Clause (OSS) · Kind: service · Deploy: native, docker, package · SSO: none
Dionaea
Low-interaction honeypot specialising in malware capture; emulates SMB, HTTP, FTP, TFTP, MSSQL, MySQL, SIP.
License: GPL-2.0-only (OSS) · Kind: service · Deploy: docker, native · SSO: none
Honeytrap
Plugin-based extensible honeypot from DTAG (Deutsche Telekom); designed for modular protocol coverage.
License: Apache-2.0 (OSS) · Kind: service · Deploy: docker, native · SSO: none
Illusive Networks
Endpoint-deception platform planting fake credentials and lateral- movement traps; acquired by Proofpoint in 2023.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
OpenCanary
Lightweight open-source honeypot from Thinkst Labs; minimal- footprint service emulators for FTP/SSH/HTTP/MySQL and many more.
License: BSD-3-Clause (OSS) · Kind: service · Deploy: native, docker, package · SSO: none
T-Pot
All-in-one Dockerised multi-honeypot platform from T-Mobile / Telekom Security; 20+ honeypots, ELK stack, attack-map dashboard.
License: GPL-3.0-only (OSS) · Kind: service · Deploy: docker, native · SSO: none
Thinkst Canary
The flagship commercial deception platform; turnkey honeypots + honeytokens with the best signal-to-noise ratio in the category.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: OIDC, SAML