Canarytokens generates honeytokens (URLs, files, credentials, docs) that alert you when an attacker touches them, helping detect breaches early.

3k stars410 forksBSD-3-Clauselast commit Actively maintained
Cloud-hosted enterprise deception platform that deploys decoys, lures, and breadcrumbs across networks and endpoints to detect lateral movement, credential theft, and insider threats, generate high-fidelity alerts, and provide forensic context for incident response.
Canarytokens generates honeytokens (URLs, files, credentials, docs) that alert you when an attacker touches them, helping detect breaches early.

3k stars410 forksBSD-3-Clauselast commit Actively maintained
Secure low-code honeypot framework that uses LLMs to simulate high-interaction systems across SSH/HTTP/TCP and MCP, with metrics and cloud-native deployment options.

2.2k stars206 forksGPL-3.0last commit Actively maintained
Every option on this page is open source and free to run on your own hardware, so you own the data and there is no subscription to cancel. 2 of 2 shipped a commit in the last six months. Licences in this list: BSD-3-Clause, GPL-3.0. In exchange you take on hosting, backups and updates yourself.
Browse everything in Threat Detection, SIEM & Incident Response.