HunPot.

Traps that look real. Alerts you can trust.

MVP
HunPot dashboard

A different view of the problem

Real incidents can be buried in alert queues. HunPot records unexpected activity when an intruder interacts with a decoy.

Decoys that look like real servers record intruder activity. Legitimate users have no reason to touch them, so every interaction becomes an actionable signal.

How it works

01Attacker
02Decoy
03Sensor
04Backend
05SOC / SIEM

SSH decoy

Looks like a real server. Records commands without running them.

Incident management

One incident per attack, with severity and status.

Attack map

See attack sources and activity by country.

Fleet monitoring

Decoy health, uptime and resource use.

SIEM integrations

Log forwarding with syslog, CEF, LEEF and JSON.

Access and audit

Role-based access, LDAP and an operator audit log.

Your infrastructure.
Your data.

Fully on-premises. The backend, console and databases run on your hardware. Data stays inside your network.

Integrations

Syslog RFC 5424 · CEF · LEEF · JSON · LDAP

Who is it for?

Banking and finance, energy and critical infrastructure, government, MSSPs and integrators.

HUNPOT

See it in
your network.

Explore the platform with your team.