About this project

T-Pot is an all‑in‑one, optionally distributed, multi‑architecture honeypot platform that bundles more than 20 distinct honeypot images and a wide range of security tools. It runs on Linux, macOS and Windows via Docker and Docker‑Compose, allowing the host’s hardware to be fully utilized. The system requires at least 8 GB RAM (sensor) or 16 GB RAM (hive) and 128 GB–256 GB SSD storage, a non‑filtered IPv4 internet connection and the ability to open required inbound and outbound ports. Installation is performed from a user’s home directory using a single curl command that fetches and runs an installer script; the process can be unattended and supports various Linux distributions, Raspberry Pi, and cloud images. After installation the platform provides SSH access, a web‑based management UI through Nginx reverse proxy, and dashboards built on the Elastic Stack (Elasticsearch, Logstash, Kibana) for visualising attacks, logs and threat intelligence. Additional web tools include CyberChef, Elasticvue, T‑Pot Attack Map, Spiderfoot and others. Users can select which honeypots to run via a configurable docker‑compose file, enable or disable community data submission, and manage users through basic‑auth credentials. Maintenance features automatic updates, a daily reboot option, factory reset, log persistence, container inspection and rollback capabilities. T‑Pot is designed for security researchers, red‑team operators and incident responders who need a ready‑to‑deploy, extensible environment for deception and traffic analysis.