Honeypot
A decoy system that looks real but carries no business workload, set up only to attract attackers and raise an alert when touched.
- 01
Why it matters
Because legitimate users have no reason to reach a honeypot, every connection to it is an almost certain sign of attack. That gives a clear signal, rare in environments full of false alarms. It warns early, at the stage when an attacker starts moving around inside the network.
- 02
Example
There is a decoy on the network called “backup-server” that looks like an old file server. One night someone tries to connect to it; the investigation reveals that a compromised printer is scanning the network.
- 03
Common mistake
Setting up a decoy with real data or open to the production network. A honeypot must not become a new stepping stone for the attacker; it should be isolated and contain no sensitive information.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.