A honeypot is a decoy system or resource deliberately exposed to attackers in order to detect, deflect or study their activity.
How honeypots work
A honeypot looks like a real target – a server with open ports, a database, a login page or an industrial controller – but has no legitimate users. Any connection to it is therefore suspicious by definition. Honeypots are usually classified by how much interaction they allow:
- Low-interaction honeypots emulate a few services and record connection attempts and credentials; they are cheap and safe.
- High-interaction honeypots are real systems that attackers can fully compromise, revealing their tools and techniques, but they need careful isolation.
Networks of honeypots are called honeynets; the Honeynet Project has researched attackers this way since 1999. A related idea is the honeytoken or canary token: a fake password, API key, document or database record that raises an alert as soon as someone uses it.
Why honeypots matter
Internet-facing honeypots collect fresh threat intelligence: scanning campaigns, exploits for new vulnerabilities, malware samples and indicators of compromise. Inside a corporate network, decoys catch intruders during reconnaissance and lateral movement, with almost no false positives – a legitimate employee has no reason to touch them. This makes them a useful complement to threat hunting.
Best practices
- Isolate honeypots so that they cannot be used to attack other systems.
- Make decoys believable: realistic names, data and services.
- Send their alerts to the SOC with high priority.
- Seed fake credentials and documents in places real attackers look.