---
title: "Honeypots: Is This Thing On?"
description: Honeypots are one of the most powerful internal detection mechanisms a network can have.  A fully configured honeypot can help detect cyber attacks.
image: https://email.networksgroup.com/hubfs/Blogs/honey-206907_1920.jpg
---

- info@networksgroup.com
- [Contact Us](https://www.networksgroup.com/contact/)

- <https://www.facebook.com/networksgroupinc/>
- <https://www.facebook.com/networksgroupinc/>
- <https://twitter.com/networksgroup>
- [mailto:info@networksgroup.com](mailto:info@networksgroup.com)

[![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_300-154x42.png "NetWorks Group") ![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_750px.png "NetWorks Group") ![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_1500px.png "NetWorks Group")](https://www.networksgroup.com/)

- [Home](https://www.networksgroup.com/)
- Detect & Respond 
    - [Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/)
    - [Endpoint Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/endpoint-mdr/)
- Ethical Hacking 
    - [Full Scope Penetration Test](https://www.networksgroup.com/full-scope-penetration-test/)
    - [Web Application Security Test](https://www.networksgroup.com/web-application-security-test/)
- Security Services 
    - [Managed Security Infrastructure](https://www.networksgroup.com/managed-security-services/)
    - [Compliance Services](https://www.networksgroup.com/pci/)
    - [Vulnerability Management](https://www.networksgroup.com/vulnerability-management/)
    - [Security Architecture Review](https://www.networksgroup.com/security-architecture-review/)
- Resources 
    - [Blog](http://blog.networksgroup.com/)
    - [Library](https://www.networksgroup.com/library/)
- Company 
    - [About](https://www.networksgroup.com/about/)
    - [Contact Us](https://www.networksgroup.com/contact/)
    - [Careers](https://www.networksgroup.com/careers/)
    - [Partners](https://www.networksgroup.com/partners/)

<https://email.networksgroup.com/honeypots-is-this-thing-on#sidr>

[![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_750px.png "NetWorks Group")](https://www.networksgroup.com/)

- [Home](https://www.networksgroup.com/)
- Detect & Respond 
    - [Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/)
    - [Endpoint Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/endpoint-mdr/)
- Ethical Hacking 
    - [Full Scope Penetration Test](https://www.networksgroup.com/full-scope-penetration-test/)
    - [Web Application Security Test](https://www.networksgroup.com/web-application-security-test/)
- Security Services 
    - [Managed Security Infrastructure](https://www.networksgroup.com/managed-security-services/)
    - [Compliance Services](https://www.networksgroup.com/pci/)
    - [Vulnerability Management](https://www.networksgroup.com/vulnerability-management/)
    - [Security Architecture Review](https://www.networksgroup.com/security-architecture-review/)
- Resources 
    - [Blog](http://blog.networksgroup.com/)
    - [Library](https://www.networksgroup.com/library/)
- Company 
    - [About](https://www.networksgroup.com/about/)
    - [Contact Us](https://www.networksgroup.com/contact/)
    - [Careers](https://www.networksgroup.com/careers/)
    - [Partners](https://www.networksgroup.com/partners/)

# NetWorks Group Blog

# Honeypots: Is This Thing On?

Posted by [Nick Brigmon](https://email.networksgroup.com/author/nick-brigmon) on Oct 30, 2017 10:19:48 AM

![](https://email.networksgroup.com/hubfs/Blogs/Nick%20Brigmon.png)

Find me on:

[LinkedIn](https://www.linkedin.com/in/nicholas-brigmon-27247798) [Twitter](https://twitter.com/CaffeinatedSec)

- [Tweet](https://twitter.com/share)

Honeypots once were a dying technology. In the age of generic anti-virus, a device that did not show immediate results wasn’t well received by most I.T. that had trouble understanding the security benefits behind the stealthy device. The truth of the matter is these honeypots are one of the most powerful internal detection mechanisms a network can have. A fully configured honeypot can help detect and stop a full blown internal attack.

A honeypot is a networked device that appears to contain valuable and/or vulnerable data that waits for someone to act on it. Whether a threat actor tries to login to the interface, scans the device using a scanning tool, or attempts to access anything on the device such as a file, the alerting component will instantly inform your team that something threatening is happening. The beauty of a honeypot is that no matter what the alert is for, it’s either a legitimate attack or a user poking around on a network where they shouldn’t be. This is not in any way a noisy device, all notifications from a honeypot can and should be acted upon.

![honeypot_Picture1.png](https://email.networksgroup.com/hs-fs/hubfs/Blogs/honeypot_Picture1.png?width=267&height=536&name=honeypot_Picture1.png)

## Setting up your Honeypot

One of the biggest arguments against honeypots that we hear is the fact that something that costs so much should be producing results daily rather than possibly never. The fact is, there are a few opensource honeypots made by the same teams that sell them for a high price. Here at NetWorks Group, we’ve had the best experience with Open Canary ([https://github.com/thinkst/opencanary](https://github.com/thinkst/opencanary)). You may be asking, why would we pay thousands of dollars for a possibly free honeypot platform from GitHub? When it comes down to configuration and deployment of your own honeypot, the complex part is knowing what an attacker is looking for and what will trick the attacker into thinking this a legitimate device. Honeypots services and products are built to be tweaked correctly and all you have to do is plug it into the network. The Open Canary configuration can be a challenging task but with the right modifications, your company can have a fully functioning honeypot that may as well be a file server waiting to be hacked.

![honeypot_Picture2.png](https://email.networksgroup.com/hs-fs/hubfs/Blogs/honeypot_Picture2.png?width=711&height=399&name=honeypot_Picture2.png)

> *Screenshot of what a honeypot should like through an attackers’ eyes*

## Is a Honeypot Right for My Company?

Any added layer of security on a company network is an excellent choice. If that added layer of security is a honeypot, it makes it even better from a final detection layer perspective. Having a well-configured honeypot is invaluable to any company that wants to detect and stop attacks. If a dedicated security team is able to domain join a honeypot, run your own vulnerability scan against it, and configure real-time alerting, we would highly suggest every company deploy at least a handful of these devices.

## My honeypot is set up, now what?

As an added bonus, you can equip honeypots with tools that will make any attacker/ethical hackers day much worse. Loading tools such as Malware code detector or Responder poisoning onto your honeypot will slow down attacker significantly and provide clear detection capabilities. Many defensive tools related to honeypots can be found across the open source community as well! ([https://github.com/paralax/awesome-honeypots#honeyd](https://github.com/paralax/awesome-honeypots#honeyd)) Tools such as Responder and Bloodhound are notorious for giving hackers an “easy win” which usually leads into accessing a domain admin account on the network. If you are not only able to detect these tools but also stop these tools from running successfully and can trick them into thinking they have legitimate data, you bought yourself more time to completely taking them off the network.  Happy hunting!

 Topics: [Managed Detection & Response](https://email.networksgroup.com/topic/managed-detection-response), [Ethical Hacking](https://email.networksgroup.com/topic/ethical-hacking), [Threat Hunting](https://email.networksgroup.com/topic/threat-hunting), [Threat Management](https://email.networksgroup.com/topic/threat-management)

### Subscribe to our blog!

### Stay Informed!

### Recent Posts

### Posts by Topic

- [Information Security (50)](https://email.networksgroup.com/topic/information-security)
- [Threat Management (34)](https://email.networksgroup.com/topic/threat-management)
- [Ethical Hacking (31)](https://email.networksgroup.com/topic/ethical-hacking)
- [Managed Detection & Response (25)](https://email.networksgroup.com/topic/managed-detection-response)
- [Penetration Testing (21)](https://email.networksgroup.com/topic/penetration-testing)
- [Vulnerability Management (12)](https://email.networksgroup.com/topic/vulnerability-management)
- [Compliance (11)](https://email.networksgroup.com/topic/compliance)
- [Security Monitoring (11)](https://email.networksgroup.com/topic/security-monitoring)
- [Healthcare (9)](https://email.networksgroup.com/topic/healthcare)
- [Threat Advisory (8)](https://email.networksgroup.com/topic/threat-advisory)
- [Threat Hunting (7)](https://email.networksgroup.com/topic/threat-hunting)
- [Security Architecture Review (6)](https://email.networksgroup.com/topic/security-architecture-review)
- [HIPAA (5)](https://email.networksgroup.com/topic/hipaa)
- [Device Management (4)](https://email.networksgroup.com/topic/device-management)
- [Incident Response (4)](https://email.networksgroup.com/topic/incident-response)
- [Events (1)](https://email.networksgroup.com/topic/events)
- [PCI (1)](https://email.networksgroup.com/topic/pci)

see all

###### About Us

NetWorks Group is a Managed Detection & Response (MDR) and Ethical Hacking Service provider. We help organizations detect and respond to advanced cyber security threats through a powerful combination of our proprietary threat detection platform, expertise and security tools. Our unique approach to security not only helps you stay ahead of cyber criminals but also helps you reduce cost and increase efficiency.

###### More Links

- [Home](https://www.networksgroup.com/)
- [Blog](http://blog.networksgroup.com/)
- [About](https://www.networksgroup.com/about/)

###### Contact Us

(888) 798-1012  
 info@networksgroup.com  
 www.networksgroup.com

- <https://www.facebook.com/networksgroupinc/>
- <https://www.linkedin.com/company/networks-group>
- <https://twitter.com/networksgroup>

© 2017 - NetWorks Group