product image
product image

Decoy

$29/ month
14 day trial

Self-hosted canary tokens & honeypots — silent until an intruder trips one

Intruders spend weeks inside before anyone notices. Decoy shrinks that to seconds: plant bait only an intruder would touch, so a trip is rarely a false alarm.

Features

  • Web/URL tokens: unguessable links that alert the instant they are fetched
  • Document beacons: .docx/.xlsx/.pdf that phone home when opened, with the opener’s IP
  • Honeypot services: fake SSH/RDP/admin/database ports logging every connection and credential
  • DNS and cloud-credential traps: catch scanners resolving, and harvested fake keys
  • Alerts with the attacker’s fingerprints (IP, time, what was touched), worst first; repeats folded, not flooded
  • Passive only: records who came, never attacks back

Server requirements

  • Linux x86-64; single static binary or Docker
  • Measured: ~10 MB binary, ~10 MB RAM idle, SQLite file — no database server
  • Minimum host: 1 vCPU, 512 MB RAM, 200 MB disk
  • Dashboard 127.0.0.1:8424; honeypots bind the ports you choose; DNS traps need UDP 53 + a delegated zone; web tokens a reachable URL (-base-url)

Tiers. Free: 3 tokens, 1 honeypot, 14-day history (GitHub). Pro: 50 tokens, 10 honeypots, DNS/cloud-cred traps, email/Slack/Telegram. Team: unlimited, PagerDuty/MS Teams. 14-day trial.

Plant only in your own systems. Evidence never leaves your server; offline activation; an expired key never disarms traps.

Delivery. Automatic: key by Whop DM after checkout; download in the Downloads tab.

Whop sells paid licences only. Free: github.com/nizartuanku/decoy