Conpot

Conpot ICS/SCADA Honeypot

Conpot (ICS/SCADA-Honeypot)

Conpot is an open-source honeypot that emulates industrial control systems (ICS/Supervisory Control and Data Acquisition (SCADA)) — including typical Operational Technology (OT) protocols such as Modbus or S7comm. It makes attacks on industrial infrastructure visible without endangering real plants. This makes it especially relevant for OT security.

History & facts. Conpot is a low-interaction honeypot from the environment of the Honeynet Project and emulates the services and protocols of industrial controllers. Attackers searching for vulnerable Industrial Control Systems (ICS) systems thus encounter a deceptively real bait whose activity is fully logged. Conpot is part of T-Pot — The All-In-One Multi Honeypot Platform (T-Pot) and makes it possible to measure interest in Operational Technology (OT) targets without exposing real programmable logic controllers (PLC).

Outlook & recommendation. Conpot is one of the few open-source ways to observe attacks on industrial protocols specifically — an area that is gaining greatly in importance in view of threats such as Industroyer / CrashOverride (Industroyer) or PIPEDREAM / INCONTROLLER (PIPEDREAM). For critical-infrastructure operators, a well-placed Industrial Control Systems (ICS) honeypot can provide an early-warning signal. It does not, however, replace genuine Operational Technology (OT) monitoring: the actual level of protection arises from passive monitoring of the real plants, segmentation and access control — core fields of OT security as NEOSEC addresses them.

Conpot — Conpot ICS/SCADA Honeypot