A multi-protocol network honeypot designed to detect intruders after they have breached non-public networks.

OpenCanary is an open-source network honeypot designed to detect intruders after they have breached non-public networks. It runs as a daemon and implements various common network protocols to attract and identify unauthorized activity. The software is deployed as a server application on Linux or macOS, and it can also be run via Docker containers using the host network engine for accurate information.
The application operates by mimicking network-accessible services that appear as legitimate targets to an attacker. When an intruder interacts with these services, the software generates alerts that identify the source IP address and the specific point where the breach occurred. It is designed with low resource requirements, allowing it to run on minimal hardware such as a Raspberry Pi or a small virtual machine without impacting system performance.
Implemented in Python, the core honeypot is cross-platform, though specific modules like port scanning require Linux-based operating systems and the use of iptables. Configuration is managed through a JSON file where users enable specific protocols and define logging options. The software can be installed via pip, uv, or pkgx, and it supports deployment via Ansible roles for automated setup across multiple nodes. It is intended for security administrators who need a lightweight mechanism to detect lateral movement within a private network environment.
OpenCanary serves as a detection tool for internal network security monitoring.
A self-hosted personal AI assistant that integrates with multiple messaging apps to perform tasks and automate workflows.
Automate workflows by connecting hundreds of applications through a visual interface with support for custom code.
Join our newsletter to get shiny new open source software delivered to your inbox. Unsubscribe anytime.