Skip to main content

OneFirewall DeceptionGrid

Overview

DeceptionGrid is OneFirewall’s honeynet platform: a distributed network of honeypots deployed across multiple geolocations to attract, monitor, and study real-world cyber adversaries. It converts attacker activity into threat intelligence. Each node simulates a digital environment using a set of decoy services. By observing how threat actors interact with these services, OneFirewall extracts telemetry, attack patterns, and behavioral indicators that feed its Threat Intelligence Data Lake, giving early visibility into emerging threats and attacker tactics, techniques, and procedures (TTPs).

Services Deployed per Honeypot Node

Each node simulates services across the following categories:

Network & Remote Access

  • SSH (Port 22) – credential brute-force and key abuse
  • Telnet (Port 23) – legacy devices and insecure admin access
  • RDP (Port 3389) – Windows remote desktop environment
  • OpenVPN/IPsec (Port 1194/500) – corporate VPN gateway emulation

Web & API Services

  • HTTP/HTTPS (Port 80/443) – fake websites, admin panels, and CMS
  • RESTful APIs (custom ports) – mimicking microservices or internal APIs
  • WebSocket endpoints – real-time protocol interaction analysis

IoT & OT Protocols

  • Modbus (Port 502) – industrial control simulation
  • MQTT (Port 1883) – IoT message broker
  • UPnP/SSDP – smart home broadcast traffic
  • BACnet (Port 47808) – building automation system protocol
  • Zigbee (simulated stack) – wireless sensor activity

File & Data Access

  • FTP/SFTP (Port 21/22) – insecure file transfer protocols
  • SMB/CIFS (Port 445) – Windows file sharing with weak credentials
  • NFS (Port 2049) – Unix/Linux network file system
  • ElasticSearch (Port 9200) – open data analytics nodes

Databases

  • MySQL (Port 3306)
  • PostgreSQL (Port 5432)
  • MongoDB (Port 27017)
  • Redis (Port 6379)
  • Cassandra (Port 9042)
These are configured with known vulnerabilities or weak configurations.

DevOps & Cloud Services

  • Docker Daemon API (Port 2375) – exposed container runtime
  • Kubernetes API/Kubelet (Port 10250) – open clusters
  • Jenkins (Port 8080) – continuous integration tool interface
  • GitLab CI (Port 8929) – self-hosted pipelines

Email & Messaging

  • SMTP (Port 25)
  • IMAP (Port 143) / POP3 (Port 110) – enterprise mailboxes

Authentication & Directory Services

  • LDAP/LDAPS (Port 389/636) – enterprise directory services
  • Kerberos (Port 88) – Windows domain controller simulation
  • OAuth/OpenID Connect endpoints – federated auth flows

VoIP & Legacy Communication

  • SIP (Port 5060) – VoIP endpoint attracting toll fraud attempts
  • XMPP/IRC – chat/C2 environments

Application & Custom Decoys

  • Vulnerable web apps – DVWA, Juice Shop, fake ERP/CRM systems
  • Fake admin portals – SCADA dashboards, CMS panels
  • Geo-localized interfaces – banking portals or ISP panels specific to the node’s region

Deployment Architecture

Each node is:
  • Isolated and sandboxed for controlled observation
  • Geographically distributed for visibility across regions
  • Tuned for low-interaction or high-interaction deception, depending on the node’s risk tolerance and role
  • Instrumented for full telemetry, including session recording, packet capture, and real-time alerting

How It Works

  1. Lure & Engage: nodes respond to global scans and targeted probing with realistic service banners and behaviors.
  2. Record & Analyze: all activity is logged, enriched, and correlated in real time.
  3. Extract Intelligence: attacker behavior is converted into IOCs, TTPs, and threat actor fingerprints.
  4. Feed Defense: threat data flows into OneFirewall’s threat intelligence sharing platform.

For integration or research partnerships, contact the OneFirewall team.