Defensive technique

Honeypots and honeynets

Systems and services prepared to observe interactions that ordinary operations should not produce.

Research question

What interaction does the lure simulate and what data does it collect?

Context and method

Definitions and technical considerations should be checked against the primary source. Atlas records are a selection tagged with this topic; a matching tag does not demonstrate operational outcomes.

Cross-reference

This topic across source types

These counts describe tagged Atlas records, not the worldwide number of studies or offerings.

Linked library

Associated records

71 tagged records
Dataset or lab2026

CTU-HONEY-LLM-2

Review: Public pageCritical reading

JSONL shell-conversation datasets for training and testing language-model SSH honeypots, according to Zenodo.

NetworkHoneypot
Open software2026

Cyber Deception Playground

Review: RepositoryEditor contribution

Open Docker Compose lab with vulnerable services, configurable deception levels, monitoring and an attacker environment for controlled training and research.

NetworkApplicationHoneypotDecoy
Dataset or lab2026

DICOMHawk Medical Imaging Deception Dataset

Review: Public pageCritical reading

Zenodo record of DICOM/PACS telemetry from medical-imaging honeypot research; it documents periods of data loss.

ApplicationOT/ICSHoneypot
Dataset or lab2026

Four-Month SSH Botnet Interaction Dataset

Review: Public page

SSH interaction data collected by a honeypot between July and November 2025; event count comes from the authors.

NetworkHoneypot