Deployment environment

Networks and services

Lures for network services, protocols and assets, internal or exposed.

Research question

What traffic is unexpected and where is the sensor placed?

Context and method

Definitions and technical considerations should be checked against the primary source. Atlas records are a selection tagged with this topic; a matching tag does not demonstrate operational outcomes.

Cross-reference

This topic across source types

These counts describe tagged Atlas records, not the worldwide number of studies or offerings.

Linked library

Associated records

86 tagged records
Case study2026

Cargo Theft Actor in a Persistent Decoy

Review: Public pageCritical reading

Proofpoint observed post-compromise activity for over a month in a Deception.Pro decoy environment; adversary behavior research, not a commercial effectiveness trial.

EndpointNetworkDecoyAdversary engagement
Dataset or lab2026

CTU-HONEY-LLM-2

Review: Public pageCritical reading

JSONL shell-conversation datasets for training and testing language-model SSH honeypots, according to Zenodo.

NetworkHoneypot
Open software2026

Cyber Deception Playground

Review: RepositoryEditor contribution

Open Docker Compose lab with vulnerable services, configurable deception levels, monitoring and an attacker environment for controlled training and research.

NetworkApplicationHoneypotDecoy
Dataset or lab2026

Four-Month SSH Botnet Interaction Dataset

Review: Public page

SSH interaction data collected by a honeypot between July and November 2025; event count comes from the authors.

NetworkHoneypot