Low interaction
Emulated services
A script that answers a few protocol requests: a banner, a login prompt.
- Cheap and quick to deploy
- Little risk if attacked
- Easy to recognise for a threat that looks twice
- Says little beyond "someone crossed a line"
Deception, explained
A short guide: what a honeypot does, where it fits in your security, and the questions worth asking any provider before you sign. Including us.
A honeypot is a decoy: it looks like a real, valuable machine on your network, but has no legitimate purpose. No employee, application or backup job has a reason to reach it. So whatever does is a threat.
Intent isn't inferred, it is self-declared. No tuning, no baselines, no guessing.
Threats rarely go straight for the prize. They probe and move from machine to machine, and that is where they meet a decoy.
A convincing decoy keeps a threat busy on something worthless while you respond.
01
You can spot a phishing email today, and tomorrow. But every time? Every colleague? A threat only needs one mistake, and the risk adds up.
02
After the breach comes the delicate part for the threat: moving between machines, escalating privileges, getting data out. That time is called dwell time, and industry reports put it at around ten days. Ten days in which the defender has the advantage, and the threat can't afford a mistake.
03
AI is finding vulnerabilities, new zero-days included, faster than they can be patched, and the gap between disclosure and exploitation keeps closing. Detection that takes days to sort through arrives too late.
Until recently
With AI
With decoys
Why those days favour the defender: The strategic importance of layered defense
A honeypot doesn't replace what you already have. It tells you when that wasn't enough.
01
Firewalls, email filtering, endpoint protection, patching
Prevention. Necessary, and never perfect.
02
Honeypots
Detection of what got past, with alerts you can act on without an analyst.
03
Your team, your MSSP, your provider
Act on a confirmed threat, with time bought by the decoy.
It's good to have emergency braking on your car, but it's not a good reason to stop using your foot.
Low interaction
A script that answers a few protocol requests: a banner, a login prompt.
Full interaction
A real machine that can actually be broken into, with something plausible inside.
Some designs remove this trade-off. Ours is one of them. See how Hoxey removes it
The questions to ask
Five questions worth asking any vendor, us included. Not every one needs a positive answer: consistency is what's being tested.
Accept drawbacks consciously. Refuse inconsistencies, because your security is at stake.
Our answers to questions 2 and 4 are public: the Hoxey security model.
Red flags worth knowing
A real command answers in milliseconds; model inference takes seconds. That delay gives the decoy away almost at once, and generated output stops being consistent as soon as a threat looks around.
It sounds like more coverage, but the addresses share one fingerprint. A basic scan, an SSH banner or TCP behaviour, gives them away before any meaningful interaction.
Deception seems easy. It isn't.
We'll answer every one on a technical call, including the ones we're still working on.
Prefer writing?
Threat intel from our own decoys, first-hand. Not another newsletter.
Low volume, high quality.