Ross ROSS = Recommend OSS · open-source software intelligence for agents

telekom-security/tpotce

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝 observed · 2026-08-28

github.com/telekom-security/tpotce · Shell · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

67/100

  • Activity 99
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 4296
  • days_rel: 630
  • days_push: 8
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

9443 stars · 1385 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

T-Pot is an all-in-one, optionally distributed honeypot platform that bundles 20+ honeypots with the Elastic Stack for visualization, live attack maps, and security tooling. It runs as Docker containers on multiarch (amd64/arm64) Linux systems and is maintained by Deutsche Telekom security.

Use cases

  • set up a honeypot to capture and analyze attacks
  • monitor malicious traffic on a network
  • visualize attack sources on a live map
  • collect threat intelligence from attackers
  • deploy a distributed network of deception sensors
  • study attacker behavior and techniques

When to choose

  • you want a turnkey honeypot platform with dashboards and attack maps out of the box
  • you need to run many honeypots in one deployment with centralized logging via the Elastic Stack
  • you want to deploy distributed sensors reporting to a central hive
  • you have adequate hardware (8-16 GB RAM, 128 GB disk) and a dedicated system/VM for deception

When to avoid

  • you need a lightweight intrusion detection solution on resource-constrained hardware
  • you want a production firewall or IDS rather than a research/deception tool
  • you cannot expose a system to the internet or dedicate ports to honeypots
  • you need a managed cloud service rather than self-hosted infrastructure

Facets

application · maturity active

security monitoring logging data-visualization container-runtime security networking monitoring self-hosted self-hosted cli honeypot deception elastic-stack threat-intelligence attack-maps intrusion-detection containers linux docker

1 source

Member repositories

RepositoryRoleHealth v2
telekom-security/tpotcemain67

For agents

markdown · JSON · MCP: product_card(name="telekom-security/tpotce")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem