telekom-security/tpotce
🍯 T-Pot - The All In One Multi Honeypot Platform 🐝 observed · 2026-08-28
Health v2 · maintenance only
67/100
- Activity 99
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 4296
- days_rel: 630
- days_push: 8
- n_releases_24m: 1
Adoption not part of the score
9443 stars · 1385 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
T-Pot is an all-in-one, optionally distributed honeypot platform that bundles 20+ honeypots with the Elastic Stack for visualization, live attack maps, and security tooling. It runs as Docker containers on multiarch (amd64/arm64) Linux systems and is maintained by Deutsche Telekom security.
Use cases
- set up a honeypot to capture and analyze attacks
- monitor malicious traffic on a network
- visualize attack sources on a live map
- collect threat intelligence from attackers
- deploy a distributed network of deception sensors
- study attacker behavior and techniques
When to choose
- you want a turnkey honeypot platform with dashboards and attack maps out of the box
- you need to run many honeypots in one deployment with centralized logging via the Elastic Stack
- you want to deploy distributed sensors reporting to a central hive
- you have adequate hardware (8-16 GB RAM, 128 GB disk) and a dedicated system/VM for deception
When to avoid
- you need a lightweight intrusion detection solution on resource-constrained hardware
- you want a production firewall or IDS rather than a research/deception tool
- you cannot expose a system to the internet or dedicate ports to honeypots
- you need a managed cloud service rather than self-hosted infrastructure
Facets
application · maturity active
security monitoring logging data-visualization container-runtime security networking monitoring self-hosted self-hosted cli honeypot deception elastic-stack threat-intelligence attack-maps intrusion-detection containers linux docker
1 source
- readme: https://github.com/telekom-security/tpotce · fetched 2026-08-28 · 6c5e4af1f56a
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| telekom-security/tpotce | main | 67 |
For agents
markdown · JSON · MCP: product_card(name="telekom-security/tpotce")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem