Overview
Sensor by IP Intelligence offers unique data collection capabilities through facilitating honeypot deployment directly onto existing customer infrastructure, without risking real production assets.
By deploying the Sensor agent onto user-provided hosts, security teams can centrally manage and execute specialized honeypot containers mapped to custom profiles. Because these decoys store no real assets and serve no legitimate operational traffic, any inbound connection is considered unsolicited, generating immediate, zero-false-positive alerts for unauthorized activity.
- Your Linux hostRuns the Sensor agent
- Assigned profileDefines the honeypots
- Attacker activityCaptured as events
Benefits of Sensor
Customized Data Collection
Place honeypots in the countries, clouds, and autonomous systems that match your organization's digital footprint, without any risks to critical production data.
Exposes Attacker Tooling
Every credential tried, command run, file uploaded, and packet sent is recorded and can be converted to valuable threat intelligence.
Centrally Managed
Profiles decide how honeypots are deployed and where they run. Any changes will reach the whole fleet almost instantly.
Fast Configuration
Start capturing threat data in minutes with just a few simple commands.
Sensors collect interactions with emulated services, not production traffic. Run them on isolated hosts with no route into production or corporate networks.
Use cases
-
Attacker Deception — Decoy assets increase the time, effort, and noise required for an adversary to navigate a network, forcing them to reveal their presence while trying to distinguish real assets from traps.
-
Perimeter Collection — Deploy honeypots beside your production ranges to intercept and log potential attacker campaigns before they reach production environments
-
Regional and Provider Risk — Compare traffic across systems, regions and providers to see where your exposure is concentrated
-
Personalized Data Collection — Honeypots serve as a low-cost, versatile source of threat intelligence that can be tailored to your organization's specific objectives and reporting priorities.
Machine collection
Users are able to operate machines, internal Linux hosts running the Sensor agent, for one or several containers. Each container consists of a single honeypot. All actions and deployments are centrally managed by the profile assigned to it.
Machines record interactions with the honeypots they run: connection metadata, protocol exchanges, credentials, commands, request bodies, uploaded files, and packet captures. They are not designed to observe your production traffic, and should only be run on dedicated hosts.
A tenant can have machines write a copy of all recorded events to an internally controlled S3 bucket, configured centrally rather than per host.
Next Steps
Related documentation: IP Intelligence.