deception-honeypot

Deploy honeypot decoys to collect attacker telemetry and IOCs.

60|14|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/brucesongs/kali-claw --skill deception-honeypot-brucesongs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: deception-honeypot
Source: https://github.com/brucesongs/kali-claw/tree/main/skills/deception-honeypot
Command: npx skills add https://github.com/brucesongs/kali-claw --skill deception-honeypot-brucesongs

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides a comprehensive deception and honeypot framework to generate high-fidelity attacker telemetry, collect IOCs, and support threat-intelligence workflows.

Core Features & Use Cases

  • Deploy multiple decoys (Cowrie, OpenCanary, Conpot, HFish, T-Pot, Beelzebub) across DMZ, internal, and OT networks to lure attackers.
  • Capture rich logs, credentials, payloads, and command sequences for IOC extraction and ATT&CK mapping.
  • Integrate with SIEMs and threat-intel platforms (MISP, VirusTotal, Shodan) and support Sigma-based alerting.

Quick Start

Set up an isolated lab with Cowrie/OpenCanary/Conpot/HFish and begin collecting honeypot sessions and IOC data.

Frequently Asked Questions about deception-honeypot

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I deploy honeypots to collect attacker telemetry and IOCs across enterprise networks?

You can deploy decoys like Cowrie, OpenCanary, Conpot, HFish, T-Pot, and Beelzebub across DMZ, internal, and OT networks to capture attacker telemetry, credentials, payloads, and command sequences for IOC extraction.

What is the best way to integrate honeypot logs with SIEM and threat-intel platforms?

The best way involves funneling honeypot data into SIEM and threat-intel pipelines like MISP, VirusTotal, and Shodan, enabling Sigma-based alerting and ATT&CK mapping for comprehensive threat intelligence workflows.

Can I use deception techniques to map attacker behavior against the MITRE ATT&CK framework?

Yes, deception techniques capture rich logs, credentials, payloads, and command sequences from honeypot sessions, allowing you to extract IOCs and accurately map observed attacker behavior to the MITRE ATT&CK framework.

What network isolation and OPS security precautions are required for honeypot deployment?

Honeypot deployment requires careful OPS security, network isolation, and log forwarding to prevent attackers from pivoting into production systems while ensuring collected telemetry is securely transmitted to SIEM pipelines.

How do I extract IOCs and set up Sigma-based SOC workflows from captured honeypot sessions?

You extract IOCs from captured honeypot sessions containing payloads and command sequences, then feed them into threat-intel platforms and SIEMs to support Sigma-based SOC workflows and automated alerting.