An awesome collection of articles, papers, conferences, guides, and tools relating to deception in cybersecurity.
-
Updated
Jun 10, 2026
An awesome collection of articles, papers, conferences, guides, and tools relating to deception in cybersecurity.
Signature based honeypot detector tool written in Golang
HoneyWire: The Open-Source, Unlimited Deception Platform. Turn any Linux machine into an enterprise-grade canary in 60 seconds.
Automation tool for Windows Deception Host Burn-In
A simple SSH gateway for deception deployments
Deceptive Operations: Lure, Observe, and Secure Tool
A portable active cyber defense tool that uses decoy-based delaying tactics to mislead and restrain attackers in untrusted networks.
Deploys 14 Honeypot services (SSH, Telnet, ADB, MongoDB, VNC, MySQL, etc). Real-time dashboard with live WebSocket updates, attack geolocation, automated alerts + IP blocking, and payload/IOC analysis.
A distributed, AI-powered honeypot system for Kubernetes. Uses OpenRouter to access 100+ LLMs (GPT-4o, Claude, Gemini) for generating realistic, context-aware vulnerable server responses. Features advanced scanner detection, session memory, and detailed artifact logging to trick attackers and capture threat intelligence.
Behavioral User-driven Deceptive Activities Framework
HTTP honeypot on autopilot
Adversarial Cognitive Portal Trap Architecture — A multi-layered defensive system that contains, degrades, disrupts, and commandeers autonomous offensive AI agents via a reverse kill chain (L0-L4).
A deceptive web application designed to lure and monitor potential attackers by simulating a real, sensitive environment. It logs IPs, geolocation, user-agents, and suspicious interactions, and runs on a Dockerized Flask app deployed via AWS EC2 for scalable cybersecurity analysis.
🛡️ Zero-config hardware honeypot on a single ESP32-S3 — fake RTSP/HTTP/Telnet/SSH/FTP traps that capture attacker credentials, MAC/vendor & User-Agent, with Telegram alerts and a dark-mode dashboard. Pure ESP-IDF / C, no cloud, no Raspberry Pi.
ML-powered deception-based banking honeypot system using React, FastAPI, and behavioral biometrics.
A fork of the original mailhoney SMTP honeypot rewritten due to library deprecation
New and improved ESP32-P4 based PoE honeypot
Single-binary network honeypot sensor and self-hosted console. Captures the credentials, prompts, and tokens intruders offer — including on LLM, Kubernetes, and MCP infrastructure.
A research-grade stateful adaptive honeypot leveraging a machine learning ensemble (Random Forest, XGBoost, Isolation Forest) and a Q-learning reinforcement learning engine to dynamically optimize deception environments in real-time.
Defensive Active Directory hardening & deception dashboard
Add a description, image, and links to the deception-technology topic page so that developers can more easily learn about it.
To associate your repository with the deception-technology topic, visit your repo's landing page and select "manage topics."