
OpenCanary
#Threat Defense#Honeypots
A honeypot system that detects and identifies attack commands, recon attempts, and download commands, mimicking a vulnerable Elasticsearch instance.
OpenCanary: A Multi-Protocol Network Honeypot
OpenCanary is a multi-protocol network honeypot that operates as a daemon. It supports several common network protocols.
It has extremely low resource requirements and versatile capabilities
It has very low resource requirements and can be easily adjusted, modified, and expanded. When attackers infiltrate networks and engage with the honeypot, OpenCanary promptly sends alerts through various mechanisms.
Implementation in Python and Cross-Platform Compatibility
This is implemented in Python and is compatible across different platforms, though some features may require specific operating systems. Running the application on Linux offers the most flexibility, and it can be deployed on low-resource devices such as a Raspberry Pi or a virtual machine (VM). OpenCanary serves as the open-source version of the commercial Thinkst Canary honeypot.