Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Honeypots
  3. T-Pot

T-Pot

GPL-3.0Shell24.04.1

An all-in-one, optionally distributed, multi-architecture honeypot platform with 20+ honeypots, visualization via Elastic Stack, and live attack maps.

GitHubGitHub
9.4k stars1.4k forks0 contributors

What is T-Pot?

T-Pot is an all-in-one honeypot platform that combines over 20 different honeypots and security tools into a single, optionally distributed system. It captures and analyzes attack data, providing visualization through the Elastic Stack and live attack maps to help security researchers and organizations understand threats.

Target Audience

Security researchers, SOC analysts, and cybersecurity professionals who need a comprehensive, self-hosted honeypot solution for threat intelligence, attack analysis, and deception.

Value Proposition

T-Pot offers a unified, open-source platform with extensive honeypot coverage, real-time visualization, and community-driven threat data sharing, eliminating the need to deploy and manage multiple standalone honeypots.

Overview

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

Use Cases

Best For

  • Security teams building a centralized honeypot deployment for threat intelligence
  • Researchers analyzing attack patterns across multiple protocols and services
  • Organizations needing a self-hosted, customizable honeypot platform
  • Educational environments for teaching cybersecurity and honeypot concepts
  • SOC analysts visualizing live attack data with Kibana dashboards
  • Deploying distributed honeypot sensors across network segments

Not Ideal For

  • Teams needing a lightweight, single-purpose honeypot for specific protocol monitoring
  • Environments with limited hardware resources, such as small VMs or embedded systems
  • Projects requiring quick, out-of-the-box deployment without Docker or complex configuration
  • Organizations that prioritize data privacy and prefer no default community data sharing

Pros & Cons

Pros

Extensive Honeypot Variety

Integrates over 20 different honeypots like Cowrie, Dionaea, and Conpot, covering a wide range of protocols from SSH to industrial control systems, as listed in the README.

Powerful Visualization Suite

Leverages the Elastic Stack (Elasticsearch, Logstash, Kibana) for storing and visualizing attack data, plus animated live attack maps and tools like CyberChef for analysis.

Scalable Distributed Architecture

Supports hive-sensor deployment for distributing honeypots across networks, allowing centralized logging and management, as detailed in the distributed deployment section.

Community and Customization

Open-source and community-driven with options to customize honeypot selection via docker-compose files and tools like customizer.py, enabling tailored setups.

Cons

Heavy Resource Footprint

Requires at least 8-16 GB of RAM and 128 GB of disk space, making it unsuitable for low-resource environments or lightweight deployments.

Complex Installation and Maintenance

Installation is non-trivial, requiring specific Linux distros, port conflict management, and regular updates; the README warns about potential issues and recommends fresh installs for problems.

Default Data Sharing Mandate

By default, captured data is submitted to a community backend (Sicherheitstacho), which requires manual opt-out by editing configuration files, potentially a concern for private deployments.

Frequently Asked Questions

Quick Stats

Stars9,360
Forks1,379
Contributors0
Open Issues1
Last commit1 month ago
CreatedSince 2014

Tags

#honeypot#self-hosted-security#elastic-stack#security#network-security#threat-intelligence#docker#elk#security-monitoring#cybersecurity#deception#attack-visualization

Built With

D
Docker Compose
a
ansible
D
Docker
N
Nginx

Included in

Honeypots10.2k
Auto-fetched 3 hours ago

Related Projects

EndlesshEndlessh

SSH tarpit that slowly sends an endless banner

Stars8,496
Forks300
Last commit2 years ago
CowrieCowrie

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

Stars6,480
Forks1,041
Last commit1 day ago
AndroguardAndroguard

Reverse engineering and pentesting for Android applications

Stars6,161
Forks1,139
Last commit1 month ago
OpenCanaryOpenCanary

Modular and decentralised honeypot

Stars2,939
Forks405
Last commit1 day ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub