T-Pot
T-Pot — The All-In-One Multi Honeypot Platform
T-Pot — Multi-Honeypot-Plattform
T-Pot is an open-source all-in-one honeypot platform that bundles numerous individual honeypots together with network monitoring and visualisation in a Docker-based system. It is maintained by Telekom Security. It is the easiest entry point to make attacks from the internet visible.
History & facts. T-Pot is developed by Telekom Security (Deutsche Telekom) and provided via GitHub (telekom-security/tpotce). The platform unites more than twenty honeypots — including Cowrie SSH/Telnet Honeypot (Cowrie) (SSH/Telnet), Dionaea Malware Honeypot (Dionaea) (malware), Conpot ICS/SCADA Honeypot (Conpot) (Industrial Control Systems (ICS)/Supervisory Control and Data Acquisition (SCADA)), Heralding, ElasticPot and many more — with the IDS/IPS engine Suricata and the ELK stack (Elasticsearch, Logstash, Kibana) for evaluation. Everything runs in Docker containers, which lets the services be cleanly isolated and conveniently updated. By default, data is submitted to the Sicherheitstacho; this can be disabled in the configuration. As a rule of thumb, around 8–16 GB RAM and 128 GB storage apply; new versions appear roughly every six to twelve months.
Outlook & recommendation. T-Pot is excellently suited to quickly gain a broad picture of current attack patterns and to generate one's own threat data. Important: a honeypot must never contain productive or sensitive data and must be strictly segmented so that it does not itself become a springboard. In a Security Operations Center (SOC) context, the findings can be connected to a Security Information and Event Management (SIEM) — at NEOSEC, for instance, to derive usable indicators for Extended Security Incident and Event Management (XIEM)® and the threat intelligence platform from real attack attempts. For pure Operational Technology (OT) scenarios, the included Conpot ICS/SCADA Honeypot (Conpot) is especially interesting.