Imported from mukul975/anthropic-cybersecurity-skills (skills/implementing-network-deception-with-honeypots/SKILL.md). Install upstream with npx skills add mukul975/anthropic-cybersecurity-skills --skill implementing-network-deception-with-honeypots. Copyright stays with the author (Apache-2.0).
Implementing Network Deception with Honeypots
When to Use
When deploying deception technology to detect lateral movement
To create early warning indicators for network intrusion
During security architecture design to add detection depth
When monitoring for unauthorized internal scanning or credential theft
To gather threat intelligence on attacker techniques and tools
Prerequisites
Linux server or VM for honeypot deployment (Ubuntu 22.04+ recommended)
Python 3.8+ with pip for OpenCanary installation
Docker for T-Pot or containerized deployment
Network segment with appropriate VLAN configuration
SIEM integration for alert forwarding (syslog, webhook, or file-based)
Firewall rules allowing inbound connections to honeypot services
Workflow
Plan Deployment: Select honeypot types and network placement strategy.
Install Honeypot: Deploy OpenCanary, Cowrie, or T-Pot on dedicated host.
Copy one of these into your project. Installing also returns the manifest and these snippets.
yaml
targets:
- https://api.opensmartroute.ai/api/v1/registry/mukul975-anthropic-cybersecurity-skills-implementing-net-780e17/manifest # or paste the manifest below
Manifest
An Open Capability Manifest: the router reads it to know what this does, what it costs and when to pick it.