# Ecosystem map

**15 September 2026**

This map uses categories and relationships. Its counts come from published catalog records and represent editorial coverage, not worldwide market share.

The current selection contains **132 records**: 13 products, 11 services, 38 papers, 49 open projects, 9 field stories, 8 datasets, 2 frameworks and 2 community resources. Coverage remains open: a record describes its reviewed source and does not itself establish performance, regional availability or global adoption.

## Institutions and frameworks

[MITRE Engage](https://github.com/mitre/engage) organizes deception, denial and adversary engagement. [MITRE D3FEND](https://d3fend.mitre.org/) provides a knowledge base of defensive techniques. The [UK NCSC](https://www.ncsc.gov.uk/blog-post/cyber-deception-trials-what-weve-learned-so-far) investigates operational effectiveness through trials with organizations and suppliers. These actors contribute vocabulary, classification and evaluation in different ways.

## Open software

Some tools focus on a protocol, such as [Cowrie](https://github.com/cowrie/cowrie). Others are multi-protocol, like [OpenCanary](https://github.com/thinkst/opencanary), or combine deployment and analysis, like [T-Pot](https://github.com/telekom-security/tpotce). Language-model honeypots are an emerging line represented by [Galah](https://github.com/0x4D31/galah). The catalog records licenses and maintenance signals when sources support them.

## Providers and services

Products such as [ShadowPlex](https://www.acalvio.com/products/), [The Platform](https://www.countercraftsec.com/products/) and [Zscaler Deception](https://www.zscaler.com/products-and-solutions/deception-technology) describe commercial capabilities across different surfaces. A product-provider link does not establish managed-service availability in every region. Service offerings are added with their own sources.

The second review adds deception features within [InsightIDR](https://docs.rapid7.com/insightidr/deception-technology/) and [Defender for Identity](https://learn.microsoft.com/en-us/defender-for-identity/entity-tags), plus [Proofpoint Shadow](https://www.proofpoint.com/us/products/identity-threat-detection-response/shadow) and managed offerings such as [ECCA](https://ecca-group.com/deception-as-a-service/). Guardicore is classified as a segmentation product with a related capability; its primary purpose is distinct from a dedicated deception platform.

## Research and experience

Surveys classify techniques; experiments study deployment and measurement; field stories highlight adoption. The [Riot Games/Tracebit story](https://tracebit.com/customer/riot-games) is vendor-published. The [NCSC trials](https://www.ncsc.gov.uk/blog-post/cyber-deception-trials-what-weve-learned-so-far) offer an institutional perspective. The interface links cases to tools and identifies who published results.

Adversary observations in simulated environments published by [Proofpoint](https://www.proofpoint.com/us/blog/threat-insight/beyond-breach-inside-cargo-theft-actors-post-compromise-playbook) and [IBM X-Force](https://www.ibm.com/think/x-force/trapping-a-mustang-panda) help study behavior; vendor-published customer stories remain labelled accordingly. Open records such as [CTU-HONEY-LLM-2](https://zenodo.org/records/21108705) and [DICOMHawk](https://zenodo.org/records/20698626) support reproducibility, with data limitations noted at the source.
