HoneyPot · Internal decoy

Trap the attacker
before it gets any further.

A honeypot VM deployed inside the LAN. 14 decoy services (SSH, RDP, SMB, fake Veeam, MSSQL…) that catch lateral movement immediately — often 14 days before the ransomware reaches the real servers.

Proxmox / VMware14 services leurresLateral movementLocal threat intel
14 j
ahead of ransomware
14
credible decoy services
≈ 0
faux positif

Nobody has a legitimate reason to connect to a fake backup server or a fake SQL database. HoneyPot plants 14 credible decoys on the LAN — a Veeam banner, Samba shares for finance and HR, MSSQL with logs, RDP on the right hostname, a "BackupServer" dashboard with 200 simulated jobs. On first contact: a critical alert. The SOC sees the lateral movement in progress, isolates the source machine and fires a playbook — before the ransomware starts.

How it works

From threat to evidence, in real time.

The module captures the signal, SYLink AI correlates it and decides — you keep control.

Attacker inside the LAN
Lateral movement
HoneyPot decoy
It touches a fake server
SYLink AI
Traces the source machine
Source isolated
14 j avant le chiffrement
Capabilities

The technology, in detail.

What the module actually does — functions, not promises.

14 services leurres

  • SSH (Cowrie) + Telnet
  • RDP (xrdp + recorder)
  • SMB (Samba finance / HR / management)
  • FTP + 193 canary files (UUID)
  • MSSQL + MySQL + PostgreSQL + Redis + VNC
  • Fake Veeam (HTTPS) plus an HTTP honeytrap (25 booby-trapped routes)

Detection

  • Any SSH/RDP/SMB connection to the VM is suspicious
  • Capture of the credentials attempted
  • Commands executed (whoami, net user…)
  • HASSH fingerprint of the SSH client
  • Inotify on canary files (read / copy)
  • Windows OS spoofing (TTL=128) to fool scanners

SYLink AI driven

  • Automatic triage (critical / high / medium)
  • Reconstruction of the attacker's path (source → decoy)
  • DPI cross-correlation (who talked to the decoy?)
  • EDR cross-correlation (which process on the source?)
  • SOAR playbook generated automatically

VM licence & robustness

  • Hardware fingerprint (UUID + machine-id + MAC)
  • Lock mode when no licence is present
  • HMAC-signed enrolment token
  • QR activation with automatic tenant assignment
  • Remote revocation means immediate lock

Local threat intel

  • Attacking IPs propagated into unified_iocs
  • If the attacker strikes elsewhere → tenant alert
  • Scan, DDoS and SYN-flood detection
  • Boot event analysis
  • SOC watchdog: VM down → events replayed

SOAR loop

  • Auto IP block → tenant firewall + DPI
  • Rotation of the Cowrie user database
  • Escalation to an analyst in high mode
  • Decoy files regenerated
  • TCP reset traceable back to the endpoint
Use cases

What is it actually for?

Detect an attacker already inside the LAN

Ransomware takes 7 to 14 days to prepare, moving laterally. HoneyPot catches the first SMB attempt on the fake backup server → an alert 14 days before the encryption.

Fool the scanners

An attacker runs nmap: the VM answers as Windows Server, Veeam, MSSQL, RDP. They waste 30 minutes on a fake server — time enough for the SOC to react.

Capture lateral credentials

A script tries psexec with admin/admin1234. Cowrie captures the credentials → the SOC knows which account is compromised elsewhere.

Threat intel propagated

The attacking IP is added to the internal CTI feeds. If it reappears on the DPI sensor or the EDR, the alert is instant. One detection feeds the whole chain.

The method, in four steps
From raw signal to defensible evidence.
Detect
Understand
Decide
Prove
01The module captures the raw signal — traffic, behaviour or indicator.signal captured
Specifications
HypervisorProxmox VE 7+ / VMware ESXi 6.7+ / Hyper-V
Resources2 vCPU / 2 GB RAM / 8 GB disk
VM operating systemMinimal Debian 13
Active services14 (SSH, RDP, SMB, MSSQL, Veeam fake…)
Listening ports21, 22, 23, 80, 139, 443, 445, 1433, 3389, 6379…
Delivery.ova / .qcow2 / .iso
Heartbeat60 s + 5 min command poll
DeploymentOn-premise · inside your own infrastructure
Natively integrated with
SYLink AI — lateral kill chain
DPI probe — LAN traffic → decoy
EDR agent — the machine the movement came from
Automated pentesting — decoys inside the scope
Compliance module — NIS2 art. 21 evidence
Sovereign

Driven by SYLink AI, hosted 100% in France (HDS v2), with no Cloud Act exposure. Every decision is logged and defensible under NIS2 and DORA.

Live in under 48 hours

Ready to see what is really
happening on your network?

First trial free, no credit card, no commitment. On your existing infrastructure.

Cookie settings

We use cookies to improve your experience on our site. By continuing to browse, you accept our privacy policy and our use of cookies under the GDPR.