honeypot-SKILL.md

Deploy OpenCanary, Cowrie, or T-Pot honeypots to detect and log attacker activity.

Updated Apr 20, 2026
One-click install
npx skills add https://github.com/DCx7C5/ai-marketplace --skill honeypot-skill-md
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: honeypot-SKILL.md
Source: https://github.com/DCx7C5/ai-marketplace/tree/main/skills/deception/honeypot
Command: npx skills add https://github.com/DCx7C5/ai-marketplace --skill honeypot-skill-md

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance.

Core Features & Use Cases

  • Deploy and configure OpenCanary, Cowrie, or T-Pot to attract, observe, and log attacker interactions.
  • Integrate with SIEM and threat intel workflows to derive indicators of compromise from honeypot data.
  • Use cases include early warning of intra-network activity, credential stuffing experiments, and studying attacker techniques.

Quick Start

Install and run the honeypot deployment on a Linux host to begin capturing attacker interactions.

Frequently Asked Questions about honeypot-SKILL.md

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I deploy honeypot networks to detect lateral movement in an enterprise environment?

Deploy honeypot networks by configuring OpenCanary, Cowrie, or T-Pot on Linux hosts to attract and observe attacker activity. This skill coordinates multiple deception technologies to detect unauthorized access and lateral movement within enterprise networks, providing structured outputs for incident response.

What is the best way to extract threat intelligence from honeypot data?

Extract threat intelligence from honeypot data by integrating honeypot logs with SIEM and threat intel workflows. This skill supports logging and threat intel extraction from deployed OpenCanary and Cowrie instances to derive actionable indicators of compromise for incident response.

Does this honeypot deployment support OpenCanary, Cowrie, and T-Pot simultaneously?

Yes, this honeypot deployment supports OpenCanary, Cowrie, and T-Pot simultaneously. The skill coordinates multiple deception technologies, allowing security operators to configure and manage these platforms together to observe credential theft and attacker reconnaissance.

How do I configure Cowrie to study attacker techniques and credential stuffing?

Configure Cowrie through this skill to attract and log attacker interactions, enabling the study of attacker techniques and credential stuffing experiments. It provides a structured output for incident response by observing unauthorized access attempts and capturing attacker activity.

Can I integrate honeypot logs with my existing SIEM workflows?

Yes, you can integrate honeypot logs with existing SIEM workflows. The skill supports logging and threat intel extraction, allowing security operators to feed indicators of compromise derived from OpenCanary or T-Pot data directly into broader security monitoring and incident response pipelines.