
OneFirewall DeceptionGrid
Overview
DeceptionGrid is OneFirewall’s honeynet platform: a distributed network of honeypots deployed across multiple geolocations to attract, monitor, and study real-world cyber adversaries. It converts attacker activity into threat intelligence. Each node simulates a digital environment using a set of decoy services. By observing how threat actors interact with these services, OneFirewall extracts telemetry, attack patterns, and behavioral indicators that feed its Threat Intelligence Data Lake, giving early visibility into emerging threats and attacker tactics, techniques, and procedures (TTPs).Services Deployed per Honeypot Node
Each node simulates services across the following categories:Network & Remote Access
- SSH (Port 22) – credential brute-force and key abuse
- Telnet (Port 23) – legacy devices and insecure admin access
- RDP (Port 3389) – Windows remote desktop environment
- OpenVPN/IPsec (Port 1194/500) – corporate VPN gateway emulation
Web & API Services
- HTTP/HTTPS (Port 80/443) – fake websites, admin panels, and CMS
- RESTful APIs (custom ports) – mimicking microservices or internal APIs
- WebSocket endpoints – real-time protocol interaction analysis
IoT & OT Protocols
- Modbus (Port 502) – industrial control simulation
- MQTT (Port 1883) – IoT message broker
- UPnP/SSDP – smart home broadcast traffic
- BACnet (Port 47808) – building automation system protocol
- Zigbee (simulated stack) – wireless sensor activity
File & Data Access
- FTP/SFTP (Port 21/22) – insecure file transfer protocols
- SMB/CIFS (Port 445) – Windows file sharing with weak credentials
- NFS (Port 2049) – Unix/Linux network file system
- ElasticSearch (Port 9200) – open data analytics nodes
Databases
- MySQL (Port 3306)
- PostgreSQL (Port 5432)
- MongoDB (Port 27017)
- Redis (Port 6379)
- Cassandra (Port 9042)
DevOps & Cloud Services
- Docker Daemon API (Port 2375) – exposed container runtime
- Kubernetes API/Kubelet (Port 10250) – open clusters
- Jenkins (Port 8080) – continuous integration tool interface
- GitLab CI (Port 8929) – self-hosted pipelines
Email & Messaging
- SMTP (Port 25)
- IMAP (Port 143) / POP3 (Port 110) – enterprise mailboxes
Authentication & Directory Services
- LDAP/LDAPS (Port 389/636) – enterprise directory services
- Kerberos (Port 88) – Windows domain controller simulation
- OAuth/OpenID Connect endpoints – federated auth flows
VoIP & Legacy Communication
- SIP (Port 5060) – VoIP endpoint attracting toll fraud attempts
- XMPP/IRC – chat/C2 environments
Application & Custom Decoys
- Vulnerable web apps – DVWA, Juice Shop, fake ERP/CRM systems
- Fake admin portals – SCADA dashboards, CMS panels
- Geo-localized interfaces – banking portals or ISP panels specific to the node’s region
Deployment Architecture
Each node is:- Isolated and sandboxed for controlled observation
- Geographically distributed for visibility across regions
- Tuned for low-interaction or high-interaction deception, depending on the node’s risk tolerance and role
- Instrumented for full telemetry, including session recording, packet capture, and real-time alerting
How It Works
- Lure & Engage: nodes respond to global scans and targeted probing with realistic service banners and behaviors.
- Record & Analyze: all activity is logged, enriched, and correlated in real time.
- Extract Intelligence: attacker behavior is converted into IOCs, TTPs, and threat actor fingerprints.
- Feed Defense: threat data flows into OneFirewall’s threat intelligence sharing platform.
For integration or research partnerships, contact the OneFirewall team.

