Cobian Honeypot

You can detect connections on lock ports and block senders via the firewall.

Developer Luis Cobian

1.0.00 · Free to use · Windows · Linux

Cobian Honeypot runs as service or daemon on Windows and Linux. A plug-in processes connections and can add blocking rules to Windows Firewall or ufw.

The configuration is done via the command line. Exceptions are essential: a wrong rule can also block your own management connection.

Get more from Cobian Honeypot

A decoy port can make unwanted connection attempts visible. The meaning of a notification depends on the network setup: a legitimate scanner or management app can also try connections. Therefore, look at the origin and conditions before you automatically block.

A honeypot is an additional signal, not full security. Limit computer exposure and carefully check firewall rules. An over-wide blockade can also affect your own management connection or other desired services.

Version and updates

Version 1.0.00.

Who is it for?

You manage a Windows or Linux server.

Getting started

Follow the service or daemon installation and configure exceptions via the command line. Ensure a recovery connection before you activate firewall blocking.

Privacy

Logs may contain IP addresses and connection times; determine who may view them.

Good to know

Advanced configuration. Risk on your own access block.

Please note

Add your management address to exceptions and keep recovery access available.

Advantages

  • Service of daemon Firewall coupler Exceptions adjustable

Things to consider

  • Advanced configuration Risk on own access block

Download Cobian Honeypot

The download page opens in a new tab.

Version history

No previous versions are listed yet.

Report a new version

Is there a newer version of Cobian Honeypot? Send the version number and a link to the official announcement. Our editors will check it. No login is required.

More from Luis Cobian

View all software from Luis Cobian →

Our verdict

Cobian Honeypot is intended for administrators who know exactly what ports and addresses they want to handle. Test for a separate machine and keep a recovery route available outside the network connection. A connection to a decoy port is a signal, not a complete analysis of an attack. Use it as an additional measure, not as a replacement for updates and access management.

Ratings

No ratings yet. Share your experience.

Log in to rate this software.

Comments

Share your experience. Comments appear after approval.

No comments yet.