Honeypots are systems with no productive purpose whose sole job is to be attacked – which makes every interaction at least suspicious by definition. Low-interaction honeypots emulate individual services or protocols only superficially; they are resource-efficient, quick to deploy and low-risk, but provide limited insight and are easier for attackers to identify as decoys. High-interaction honeypots run real operating systems and applications and allow deep analysis of attacker tools and techniques – at the cost of significantly higher operational and hardening effort. In its foundational study, ENISA evaluated 30 honeypot solutions along exactly this taxonomy, covering both server-side and client-side variants.
Honeypots & Deception
How honeypots, honeytokens and deception platforms help you detect attackers inside your internal network early – with high signal quality and, by design, very few false positives.
30honeypot solutions evaluated by ENISA in its foundational study – server-side and client-side
30+token types in Thinkst's freely available Canarytokens service – from AWS keys to kubeconfig files
2022since then, MITRE Engage has structured denial, deception and adversary engagement activities
49GDPR recital explicitly mentions ensuring network and information security
Attackers who have breached perimeter and endpoint defenses often move through internal networks undetected for long periods. Deception technologies address exactly this gap: decoy systems (honeypots), planted data and credentials (honeytokens), and centrally orchestrated deception environments that serve no purpose whatsoever for legitimate users. Because nobody has a reason to touch these resources, virtually every interaction is a reliable attack signal – the number of false positives is inherently low by design. This article puts the different variants into perspective, along with sensible placement, the legal situation in Germany, and the limitations and operational effort involved.
The Essentials at a Glance
Six topic blocks — tap to expand.
Low vs. High Interaction Compared
Two honeypot classes, one taxonomy – ENISA evaluated 30 solutions along exactly this divide. Pick a tab.
- Emulates individual services or protocols only superficially.
- Resource-efficient, quick to deploy and low-risk.
- Provides limited insight and is easier for attackers to identify as a decoy.
ServicesProtocolsResource-efficientLow-risk
- Runs real operating systems and applications.
- Allows deep analysis of attacker tools and techniques.
- The price: significantly higher operational and hardening effort.
Operating systemsApplicationsToolsTechniques
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Proactive Detection of Security Incidents II – Honeypots
Foundational study evaluating 30 honeypot solutions along the low-/high-interaction taxonomy (server-side and client-side), including the hurdles to deployment.
MITRE Engage v1.0
Framework for planning denial, deception and adversary engagement activities; successor to MITRE Shield, released in spring 2022.
NIST SP 800-160 Vol. 2 Rev. 1: Developing Cyber-Resilient Systems
Describes deception as a cyber resiliency technique with the approaches misdirection (diverting attackers into controlled environments) and tainting (marked resources).
Canarytokens Documentation
Documentation of the free honeytoken service with more than 30 token types, including cloud keys, Office documents and DNS-based triggers.
Research Honeypots – Strafbarkeitsrisiken für IT-Sicherheitsforschende?
Legal analysis of criminal liability risks in honeypot operation, including the aiding-and-abetting issue when a honeypot is abused as a stepping stone for attacks.
Gesetz über das Bundesamt für Sicherheit in der Informationstechnik (BSIG)
Section 31 BSIG obliges operators of critical facilities to deploy state-of-the-art attack detection systems; version following the NIS2 transposition.
Related Services
Ready to integrate deception into your detection strategy?
We work with you to assess where honeypots and honeytokens deliver the greatest detection gain in your environment – vendor-neutral, legally sound and integrated into your SOC. Talk to us.