Library / sourced records

Resource library

Search by kind, technique, environment or critical readings. Each record states its source and review depth.

132published resources

Results

50 found
Case study2026

Cargo Theft Actor in a Persistent Decoy

Review: Public pageCritical reading

Proofpoint observed post-compromise activity for over a month in a Deception.Pro decoy environment; adversary behavior research, not a commercial effectiveness trial.

EndpointNetworkDecoyAdversary engagement
Dataset or lab2026

CTU-HONEY-LLM-2

Review: Public pageCritical reading

JSONL shell-conversation datasets for training and testing language-model SSH honeypots, according to Zenodo.

NetworkHoneypot
Dataset or lab2026

DICOMHawk Medical Imaging Deception Dataset

Review: Public pageCritical reading

Zenodo record of DICOM/PACS telemetry from medical-imaging honeypot research; it documents periods of data loss.

ApplicationOT/ICSHoneypot
Case study2026

Trapping a Mustang Panda

Review: Public pageCritical reading

IBM X-Force and Deception.Pro recorded two incidents in simulated organizations, observing reconnaissance, malware deployment and fake-document exfiltration.

EndpointOT/ICSDecoyAdversary engagement
Dataset or lab2025

Honeypot-Anomaly-Self Attack

Review: Public pageCritical reading

CSV of seven days of Suricata events from T-Pot, according to the Zenodo record.

NetworkHoneypot
Dataset or lab2025

Multi-Regional Cloud Honeynet Dataset

Review: Public pageCritical reading

Data from a T-Pot honeynet spread across Azure regions, according to its Zenodo record.

CloudHoneypot
Case study2025

NCSC Cyber Deception Trials

Review: Public pageCritical reading

Institutional report on deception trials involving UK organizations and providers.

NetworkCloudHoneypotDecoy
Dataset or lab2025

Salty Seagull Dataset

Review: Public pageCritical reading

Record of access and attack data against a VSAT honeynet.

OT/ICSHoneypot
Dataset or lab2024

CTU Hornet 65 Niner

Review: Public pageCritical reading

Zeek traffic record from geographically distributed low-interaction sensors; the page says no conventional honeypot software was used.

NetworkHoneypot
Dataset or lab2020

CyberLab Honeynet Dataset

Review: Public pageCritical reading

Cowrie honeypot session data from a distributed deployment, according to Zenodo.

NetworkHoneypot
Open software

ADBHoney

Review: RepositoryCritical reading

Low-interaction honeypot simulating the Android Debug Bridge service.

IoTHoneypot
Product

Akamai Guardicore Segmentation: Dynamic Deception

Review: Public pageCritical reading

Primarily a microsegmentation product whose documentation includes dynamic redirection into a deception environment; this related capability is recorded.

NetworkOT/ICSDecoyMoving target defense
Open software

Canarytokens

Review: RepositoryCritical reading

Open project for creating decoy tokens that alert when someone uses them.

IdentityCloudHoneytoken
Case study

Children’s Hospital / Fidelis Deception

Review: Public pageCritical reading

Vendor-published story of Fidelis Deception use at a North American children’s hospital.

NetworkIdentityDecoy
Open software

Cowrie

Review: RepositoryCritical reading

SSH and Telnet honeypot that records login attempts and attacker sessions.

NetworkHoneypot
Service

Deception as a Service

Review: Public pageCritical reading

ECCA offering in Egypt and GCC listing integration, independent services, training and managed deception.

NetworkIdentityDecoy
Service

Deception as a Service

Review: Public pageCritical reading

ACSG publishes a managed decoy and continuous-monitoring offering for IT, cloud and ICS.

NetworkCloudDecoyHoneytoken

Each record shows the source reviewed. Vendor claims and independent results are labeled separately.