Case study2026
Review: Public pageCritical readingProofpoint observed post-compromise activity for over a month in a Deception.Pro decoy environment; adversary behavior research, not a commercial effectiveness trial.
EndpointNetworkDecoyAdversary engagement
Dataset or lab2026
Review: Public pageCritical readingJSONL shell-conversation datasets for training and testing language-model SSH honeypots, according to Zenodo.
NetworkHoneypot
Dataset or lab2026
Review: Public pageCritical readingZenodo record of DICOM/PACS telemetry from medical-imaging honeypot research; it documents periods of data loss.
ApplicationOT/ICSHoneypot
Case study2026
Review: Public pageCritical readingIBM X-Force and Deception.Pro recorded two incidents in simulated organizations, observing reconnaissance, malware deployment and fake-document exfiltration.
EndpointOT/ICSDecoyAdversary engagement
Dataset or lab2025
Review: Public pageCritical readingCSV of seven days of Suricata events from T-Pot, according to the Zenodo record.
NetworkHoneypot
Dataset or lab2025
Review: Public pageCritical readingData from a T-Pot honeynet spread across Azure regions, according to its Zenodo record.
CloudHoneypot
Case study2025
Review: Public pageCritical readingInstitutional report on deception trials involving UK organizations and providers.
NetworkCloudHoneypotDecoy
Dataset or lab2025
Review: Public pageCritical readingRecord of access and attack data against a VSAT honeynet.
OT/ICSHoneypot
Dataset or lab2024
Review: Public pageCritical readingZeek traffic record from geographically distributed low-interaction sensors; the page says no conventional honeypot software was used.
NetworkHoneypot
Paper2024
Review: AbstractCritical readingSurvey proposing a taxonomy and comparing cyber deception research lines, including AI-based work.
NetworkCloudAdversary engagement
Paper2024
Review: AbstractCritical readingPresents a language-model terminal honeypot architecture and describes a field evaluation.
NetworkHoneypot
Paper2024
Review: AbstractCritical readingPresents an interactive honeypot using a language model fine-tuned with attacker command data.
NetworkHoneypot
Paper2023
Review: AbstractCritical readingSurvey of network requirements for implementing cyber deception techniques.
NetworkDecoy
Paper2023
Review: AbstractCritical readingProposes a simulation method for evaluating honeypots and moving target defense in networks.
NetworkHoneypotMoving target defense
Paper2020
Review: AbstractCritical readingSurvey of defensive deception models and techniques in networks, hosts and cryptographic mechanisms.
NetworkEndpointDecoy
Dataset or lab2020
Review: Public pageCritical readingCowrie honeypot session data from a distributed deployment, according to Zenodo.
NetworkHoneypot
Paper2017
Review: AbstractCritical readingGame-theoretic taxonomy distinguishing several forms of defensive deception.
NetworkMoving target defenseHoneytoken
Open software—
Review: RepositoryCritical readingLow-interaction honeypot simulating the Android Debug Bridge service.
IoTHoneypot
Product—
Review: Public pageCritical readingPrimarily a microsegmentation product whose documentation includes dynamic redirection into a deception environment; this related capability is recorded.
NetworkOT/ICSDecoyMoving target defense
Open software—
Review: RepositoryCritical readingOpen project for creating decoy tokens that alert when someone uses them.
IdentityCloudHoneytoken
Case study—
Review: Public pageCritical readingVendor-published story of Fidelis Deception use at a North American children’s hospital.
NetworkIdentityDecoy
Open software—
Review: RepositoryCritical readingSSH and Telnet honeypot that records login attempts and attacker sessions.
NetworkHoneypot
Service—
Review: Public pageCritical readingECCA offering in Egypt and GCC listing integration, independent services, training and managed deception.
NetworkIdentityDecoy
Service—
Review: Public pageCritical readingACSG publishes a managed decoy and continuous-monitoring offering for IT, cloud and ICS.
NetworkCloudDecoyHoneytoken