About Members News Events Trainings Career Catalog Log In Join TR

Products

Features

Automated Honeypot Deployment

  • Honeypots can be deployed across all systems with a single click and can start collecting data immediately by assigning profiles through the control panel.

Wide Operating System Compatibility

  • GuardPot Honeypots are compatible with all operating systems and can turn any machine into a Honeypot with a single command, without any additional requirements.

Centralized Management

  • Honeypots are managed through a central control panel, where assigned profiles are applied by the Honeypot. Data monitoring can also be performed centrally.

User Directory Integration

  • User information used on Honeypots is queried against integrated active user directories, and if compliance issues are detected, alarms can be generated, and user accounts can be deactivated.

Cloud IoC

  • During development, Priente Cloud Honeypot data collected globally is shared with all users, ensuring you always have up-to-date IoC data.

Superior Imitation Capability

  • Unlike traditional Honeypot approaches, GuardPot fully imitates systems. It replicates all visible and invisible actions of the emulated products to create credibility with attackers.

Wide Protocol Support

  • It imitates most modern protocols like SSH, FTP, SMTP, HTTP, HTTPS, without using plugins, as all protocols are developed internally. Applications specific to your organization that need to be imitated can be directly integrated into the system.

Attacker Flow Map

  • After querying attackers, their past actions are displayed on a timeline, allowing you to see the paths followed during the investigation of suspicious activities. These screens can also be used for APT detection.

Live Monitoring

  • Attacker activities can be viewed in a limited way by all potential customers. Registered members of the system can perform live monitoring without data restrictions and track attacker activities in real-time.

Description

Guardpot is a project designed to help organizations automate the detection and prevention of security threats. The system creates endpoints that mimic real security software, network products, and various protocols. These endpoints record attacks based on their characteristics, and the data is sent to a central system for analysis. Attacks are assessed using a scoring system to identify and block attackers. Guardpot's central management panel controls all honeypot devices and allows security status to be monitored from a single screen. The project also provides access to Priente Cloud, which offers up-to-date threat intelligence based on globally collected data. This feature enables users to integrate global data into their security devices, creating a continuously updated security structure. By automating security monitoring and management, Guardpot aims to help organizations respond quickly and effectively to constantly evolving threat sources. This proactive approach allows institutions to manage their own security more effectively through advanced threat detection.

For our organizations with intranet-only access, the entire system can be installed and operated on-premises and used for lateral movement detection. In such setups, methods similar to those used for pulling IP lists from sources like USOM can be applied to utilize these lists for blocking purposes, ensuring that Cloud data is still leveraged.