An open-source community edition.
A complete, self-contained deception deployment for a single organization, released under an open-source license. Not a trial, not a feature-limited demo. You can deploy it, catch a real intruder, get labeled intelligence into your SIEM, and never talk to us.
- The deception runtime: protocol emulators for SSH, HTTP, Redis, MySQL, PostgreSQL, MongoDB, and Memcached.
- Monitored canary credentials: issue trackable fake credentials and get told when one is used.
- Rule-based detection, with the same deterministic engine that runs in the commercial product.
- STIX 2.1 export over a standard TAXII 2.1 feed, so your existing SIEM ingests it without a translation layer.
- A single-node control surface and local dashboard.
- Runs standalone. No account, no phone-home, no cloud dependency.