Parameter | Description |
Region | Supports all regions in China and cannot be changed after the instance is created. |
Instance Name | Customize the instance name. |
Honeypot service | Includes ELASTICSEARCH honeypot, MYSQL honeypot, NGINX honeypot, SALTSTACK honeypot, SSH honeypot, STRUTS honeypot, WEBLOGIC honeypot, and WEB honeypot. Except for the WEB honeypot, all other types of honeypots have built-in decoys and vulnerabilities. |
Interaction Type | Actual service: a high-interaction type. The backend runs real services and decoys, and responds authentically to every attacker request, thereby fully deceiving attackers and buying time for real protection. Simulated service: a medium-interaction type. The backend runs simulated services and decoys, which can generate corresponding responses based on some attacker requests and lure attackers into continuing, thereby buying time for real protection. |
Bait | ELASTICSEARCH Honeypot: cve-2014-3120. SALTSTACK Honeypot: cve-2020-11651. SSH Honeypot: weak password. STRUTS Honeypot: cve-2017-12611. WEBLOGIC Honeypot: cve-2017-10271. Other honeypots: None. |
Custom bait | MYSQL Honeypot and SSH Honeypot: you can select a login credential and set a password. WEB Honeypot: you can select existing SSH/MySQL honeypots as custom baits. If no SSH/MySQL honeypot is available, create one and bind it to a probe first. Other honeypots: None. |
Configure Probe | Select from existing probes: Select the desired probe instance and port number. Configure later: no probe is bound. |

피드백