Mastodon Mastodon Mastodon Mastodon

Honeypot

Updated: · CyberSecureFox Editorial Team

A honeypot is a decoy system or resource deliberately exposed to attackers in order to detect, deflect or study their activity.

How honeypots work

A honeypot looks like a real target – a server with open ports, a database, a login page or an industrial controller – but has no legitimate users. Any connection to it is therefore suspicious by definition. Honeypots are usually classified by how much interaction they allow:

  • Low-interaction honeypots emulate a few services and record connection attempts and credentials; they are cheap and safe.
  • High-interaction honeypots are real systems that attackers can fully compromise, revealing their tools and techniques, but they need careful isolation.

Networks of honeypots are called honeynets; the Honeynet Project has researched attackers this way since 1999. A related idea is the honeytoken or canary token: a fake password, API key, document or database record that raises an alert as soon as someone uses it.

Why honeypots matter

Internet-facing honeypots collect fresh threat intelligence: scanning campaigns, exploits for new vulnerabilities, malware samples and indicators of compromise. Inside a corporate network, decoys catch intruders during reconnaissance and lateral movement, with almost no false positives – a legitimate employee has no reason to touch them. This makes them a useful complement to threat hunting.

Best practices

  • Isolate honeypots so that they cannot be used to attack other systems.
  • Make decoys believable: realistic names, data and services.
  • Send their alerts to the SOC with high priority.
  • Seed fake credentials and documents in places real attackers look.
Synonyms:
honey pot