{"total":187,"items":[{"id":"gh2-cossacklabs-acra","slug":"gh2-cossacklabs-acra","kind":"software","name":"Acra","summary_es":"Repositorio que documenta database security suite. Database proxy with field-level encryption, search through encrypted data, SQL injections prevention, intrusion detection, honeypots. Supports client-side and proxy-side (\"transparent\") encryption. SQL, NoSQL.","summary_en":"Database security suite. Database proxy with field-level encryption, search through encrypted data, SQL injections prevention, intrusion detection, honeypots. Supports client-side and proxy-side (\"transparent\") encryption. SQL, NoSQL.","organization":"cossacklabs","year":2026,"source_url":"https://github.com/cossacklabs/acra","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"playground-experiential-learning-2026","slug":"playground-experiential-learning-2026","kind":"paper","name":"Aprendizaje experimental de ciberengaño mediante un entorno educativo reproducible","summary_es":"Artículo de Pacheco y Staino publicado en las memorias SACS 2026 que describe el diseño educativo reproducible de Cyber Deception Playground.","summary_en":"Pacheco and Staino paper in the SACS 2026 proceedings describing the reproducible educational design of Cyber Deception Playground.","organization":"Federico Pacheco y Diego Staino","year":2026,"source_url":"https://55jaiio.sadio.org.ar/wp-content/uploads/2026/07/21.pdf","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Honeypot","Decoy","Honeytoken"],"environments":["Network","Application"],"doi":null,"review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Entorno educativo reproducible con ejercicios controlados y una secuencia de aprendizaje práctico.","design_en":"Reproducible educational environment with controlled exercises and a practical learning sequence.","finding_es":"Conecta conceptos, despliegue, observación y análisis en una experiencia de laboratorio.","finding_en":"Connects concepts, deployment, observation and analysis in a laboratory experience.","evidence_limits_es":"La publicación presenta diseño y uso educativo; faltan cohortes comparables y medición longitudinal de aprendizaje.","evidence_limits_en":"The paper presents design and educational use; comparable cohorts and longitudinal learning measurement are missing.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"es, en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":"El artículo presenta una contribución de diseño. Sus autores indican que no ofrece evaluación empírica de aprendizaje ni una comparación de eficacia.","limitations_en":"The paper is a design contribution. Its authors state that it provides neither empirical learning evaluation nor comparative effectiveness results.","question_es":null,"question_en":null},{"id":"gh2-mariocandela-beelzebub","slug":"gh2-mariocandela-beelzebub","kind":"software","name":"beelzebub","summary_es":"Repositorio que documenta a secure low code deception runtime framework, leveraging AI for System Virtualization.","summary_en":"A secure low code deception runtime framework, leveraging AI for System Virtualization.","organization":"mariocandela","year":2026,"source_url":"https://github.com/beelzebub-labs/beelzebub","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Decoy"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"proofpoint-cargo-decoy-2026","slug":"proofpoint-cargo-decoy-2026","kind":"case-study","name":"Cargo Theft Actor in a Persistent Decoy","summary_es":"Proofpoint observó durante más de un mes acciones posteriores a la intrusión en un entorno señuelo operado con Deception.Pro; estudio de conducta adversaria, no prueba de eficacia comercial.","summary_en":"Proofpoint observed post-compromise activity for over a month in a Deception.Pro decoy environment; adversary behavior research, not a commercial effectiveness trial.","organization":"Proofpoint Threat Research","year":2026,"source_url":"https://www.proofpoint.com/us/blog/threat-insight/beyond-breach-inside-cargo-theft-actors-post-compromise-playbook","evidence":"threat-research-observation","reviewed_at":"2026-09-15","techniques":["Decoy","Adversary engagement"],"environments":["Endpoint","Network"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"Proofpoint narra observaciones posteriores a la intrusión durante más de un mes en un señuelo.","critical_observation_en":"Proofpoint reports over a month of post-compromise observations in a decoy.","limitations_es":"Un caso seleccionado no mide tasa de detección de ataques ausentes ni generalización.","limitations_en":"A selected case does not measure detection of missed attacks or generalizability.","question_es":"¿Qué hipótesis de comportamiento adversario cambió con esa observación?","question_en":"Which adversary-behavior hypothesis changed from that observation?"},{"id":"doi-10-1109-noms69089-2026-11668367","slug":"doi-10-1109-noms69089-2026-11668367","kind":"paper","name":"CowLLMpot: Toward an LLM-Based Honeypot Fine-Tuned Using Cowrie Honeypot Data","summary_es":"Registro bibliográfico sobre honeypot con modelo ajustado a datos de Cowrie. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on language-model honeypot tuned on Cowrie data. The abstract and findings still require review.","organization":"Amal Rami, Adrien Fégar","year":2026,"source_url":"https://doi.org/10.1109/noms69089.2026.11668367","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":"10.1109/noms69089.2026.11668367","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"ctu-honey-llm-2","slug":"ctu-honey-llm-2","kind":"dataset","name":"CTU-HONEY-LLM-2","summary_es":"Conjuntos JSONL de conversaciones de shell para entrenar y probar honeypots SSH basados en modelos de lenguaje, según Zenodo.","summary_en":"JSONL shell-conversation datasets for training and testing language-model SSH honeypots, according to Zenodo.","organization":"CTU research authors","year":2026,"source_url":"https://zenodo.org/records/21108705","evidence":"dataset-record","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":"10.5281/zenodo.21108705","review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"Zenodo identifica conversaciones de shell en JSONL para entrenamiento y evaluación.","critical_observation_en":"Zenodo identifies JSONL shell conversations for training and evaluation.","limitations_es":"No se comprobó aquí que las muestras representen conversaciones adversarias actuales.","limitations_en":"This record does not verify that samples represent current adversarial conversations.","question_es":"¿Cómo se separan las sesiones de entrenamiento y prueba para evitar fuga?","question_en":"How are training and test sessions separated to prevent leakage?"},{"id":"base4-cyberdeception-playground","slug":"base4-cyberdeception-playground","kind":"software","name":"Cyber Deception Playground","summary_es":"Laboratorio abierto con Docker Compose, servicios vulnerables, niveles configurables de engaño, monitoreo y un entorno atacante para formación e investigación controlada.","summary_en":"Open Docker Compose lab with vulnerable services, configurable deception levels, monitoring and an attacker environment for controlled training and research.","organization":"BASE4 Security","year":2026,"source_url":"https://github.com/Base4Security/cyberdeception-playground","evidence":"repository-documentation","reviewed_at":"2026-09-15","techniques":["Honeypot","Decoy","Honeytoken"],"environments":["Network","Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":"El laboratorio contiene vulnerabilidades deliberadas y debe ejecutarse aislado. La ficha no demuestra mejoras de aprendizaje ni eficacia defensiva frente a otras prácticas.","limitations_en":"The lab contains intentional vulnerabilities and should run in isolation. This record does not establish learning gains or defensive effectiveness versus other approaches.","question_es":null,"question_en":null},{"id":"dicomhawk-medical-deception","slug":"dicomhawk-medical-deception","kind":"dataset","name":"DICOMHawk Medical Imaging Deception Dataset","summary_es":"Registro Zenodo de telemetría DICOM/PACS de una investigación de honeypots para infraestructura de imagen médica; incluye notas de pérdida de datos.","summary_en":"Zenodo record of DICOM/PACS telemetry from medical-imaging honeypot research; it documents periods of data loss.","organization":"DICOMHawk research authors","year":2026,"source_url":"https://zenodo.org/records/20698626","evidence":"dataset-record","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Application","OT/ICS"],"doi":"10.5281/zenodo.20698626","review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"El registro Zenodo documenta telemetría DICOM/PACS y períodos de pérdida de datos.","critical_observation_en":"The Zenodo record documents DICOM/PACS telemetry and data-loss periods.","limitations_es":"Los períodos faltantes limitan comparaciones de volumen o tasas de ataque.","limitations_en":"Missing periods limit comparisons of volume or attack rates.","question_es":"¿Qué análisis siguen siendo válidos con los intervalos de captura incompletos?","question_en":"Which analyses remain valid with incomplete capture intervals?"},{"id":"gh2-nsmfoo-dicompot","slug":"gh2-nsmfoo-dicompot","kind":"software","name":"dicompot","summary_es":"Repositorio que documenta dICOM Honeypot","summary_en":"DICOM Honeypot","organization":"nsmfoo","year":2026,"source_url":"https://github.com/nsmfoo/dicompot","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-eymengunay-eohoneypotbundle","slug":"gh2-eymengunay-eohoneypotbundle","kind":"software","name":"EoHoneypotBundle","summary_es":"Repositorio que documenta honeypot type for Symfony forms","summary_en":"Honeypot type for Symfony forms","organization":"eymengunay","year":2026,"source_url":"https://github.com/eymengunay/EoHoneypotBundle","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-christophe77-express-honeypot","slug":"gh2-christophe77-express-honeypot","kind":"software","name":"Express honeypot","summary_es":"Repositorio que documenta express honeypot for remote file inclusion (RFI) and local file inclusion (LFI).","summary_en":"Express honeypot for remote file inclusion (RFI) and local file inclusion (LFI).","organization":"christophe77","year":2026,"source_url":"https://github.com/christophe77/express-honeypot","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-andrewmichaelsmith-flux","slug":"gh2-andrewmichaelsmith-flux","kind":"software","name":"flux","summary_es":"Repositorio que documenta hTTP honeypot on autopilot","summary_en":"HTTP honeypot on autopilot","organization":"andrewmichaelsmith","year":2026,"source_url":"https://github.com/andrewmichaelsmith/flux","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-petergabaldon-fortigate-vpn-ssl-honeypot","slug":"gh2-petergabaldon-fortigate-vpn-ssl-honeypot","kind":"software","name":"FortiGate SSL-VPN Honeypot","summary_es":"Repositorio que documenta fortigate VPN-SSL Honeypot","summary_en":"Fortigate VPN-SSL Honeypot","organization":"PeterGabaldon","year":2026,"source_url":"https://github.com/PeterGabaldon/Fortigate.VPN-SSL.Honeypot","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"ssh-botnet-2025-odessa","slug":"ssh-botnet-2025-odessa","kind":"dataset","name":"Four-Month SSH Botnet Interaction Dataset","summary_es":"Datos de interacciones SSH recopilados por un honeypot entre julio y noviembre de 2025; la cifra de eventos procede de los autores.","summary_en":"SSH interaction data collected by a honeypot between July and November 2025; event count comes from the authors.","organization":"Odesa Law Academy researchers","year":2026,"source_url":"https://zenodo.org/records/20435481","evidence":"dataset-record","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":"10.5281/zenodo.20435481","review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-mushorg-glutton","slug":"gh2-mushorg-glutton","kind":"software","name":"glutton","summary_es":"Repositorio que documenta generic Low Interaction Honeypot","summary_en":"Generic Low Interaction Honeypot","organization":"mushorg","year":2026,"source_url":"https://github.com/mushorg/glutton","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-phin3has-mailoney","slug":"gh2-phin3has-mailoney","kind":"software","name":"Mailoney","summary_es":"Repositorio que documenta an SMTP Honeypot","summary_en":"An SMTP Honeypot","organization":"phin3has","year":2026,"source_url":"https://github.com/phin3has/mailoney","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-ivre-masscanned","slug":"gh2-ivre-masscanned","kind":"software","name":"Masscanned","summary_es":"Repositorio que documenta let's be scanned. A low-interaction honeypot focused on network scanners and bots. It integrates very well with IVRE to build a self-hosted alternative to GreyNoise.","summary_en":"Let's be scanned. A low-interaction honeypot focused on network scanners and bots. It integrates very well with IVRE to build a self-hosted alternative to GreyNoise.","organization":"ivre","year":2026,"source_url":"https://github.com/ivre/masscanned","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-chaitin-mimicry","slug":"gh2-chaitin-mimicry","kind":"software","name":"Mimicry","summary_es":"Repositorio que documenta mimicry is a dynamic deception tool that actively deceives an attacker during exploitation and post-exploitation.","summary_en":"Mimicry is a dynamic deception tool that actively deceives an attacker during exploitation and post-exploitation.","organization":"chaitin","year":2026,"source_url":"https://github.com/chaitin/mimicry","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Decoy"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"neroswarm-research-access","slug":"neroswarm-research-access","kind":"community","name":"NeroSwarm Research Access Program","summary_es":"Programa publicado en septiembre de 2026 que ofrece acceso temporal a una plataforma de deception para investigación no comercial; los requisitos se consultan en la fuente.","summary_en":"September 2026 program offering time-limited deception-platform access for non-commercial research; eligibility is listed at the source.","organization":"NeroSwarm","year":2026,"source_url":"https://neroswarm.com/research-access","evidence":"research-access-program","reviewed_at":"2026-09-15","techniques":["Honeypot","Honeytoken"],"environments":["Network"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-christophe77-node-ftp-honeypot","slug":"gh2-christophe77-node-ftp-honeypot","kind":"software","name":"node-ftp-honeypot","summary_es":"Repositorio que documenta nodejs ftp honeypot","summary_en":"nodejs ftp honeypot","organization":"christophe77","year":2026,"source_url":"https://github.com/christophe77/node-ftp-honeypot","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-bartnv-portlurker","slug":"gh2-bartnv-portlurker","kind":"software","name":"portlurker","summary_es":"Repositorio que documenta port listener / honeypot in Rust with protocol guessing and safe string display","summary_en":"Port listener / honeypot in Rust with protocol guessing and safe string display","organization":"bartnv","year":2026,"source_url":"https://github.com/bartnv/portlurker","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-f0rw4rd-potsnitch","slug":"gh2-f0rw4rd-potsnitch","kind":"software","name":"potsnitch","summary_es":"Repositorio que documenta honeypot detection toolkit","summary_en":"Honeypot detection toolkit","organization":"f0rw4rd","year":2026,"source_url":"https://github.com/f0rw4rd/potsnitch","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"buda-user-behavior-2026","slug":"buda-user-behavior-2026","kind":"paper","name":"Refuerzo de estrategias de ciber engaño mediante comportamiento simulado de usuarios","summary_es":"Pacheco y Staino presentan BUDA como propuesta para simular actividad de usuarios ficticios y reforzar la credibilidad de señuelos, alineada con MITRE Engage.","summary_en":"Pacheco and Staino present BUDA as an approach to simulating fictitious-user activity and strengthening decoy credibility, aligned with MITRE Engage.","organization":"Federico Pacheco y Diego Staino","year":2026,"source_url":"https://revistas.unlp.edu.ar/ejs/article/view/20422","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Decoy","Adversary engagement"],"environments":["Endpoint","Network"],"doi":"10.24215/15146774e095","review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Diseño y prototipo de perfiles señuelo y actividad simulada alineados con MITRE Engage.","design_en":"Design and prototype of decoy profiles and simulated activity aligned with MITRE Engage.","finding_es":"Propone añadir coherencia temporal y rastros de usuario a activos técnicos estáticos.","finding_en":"Proposes adding temporal coherence and user traces to static technical decoys.","evidence_limits_es":"El trabajo define una estrategia de evaluación futura; todavía no aporta resultados comparativos de campo.","evidence_limits_en":"The work defines a future evaluation strategy and does not yet provide comparative field results.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"es","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":"La ficha se basa en el resumen editorial; no se analizaron resultados del texto completo ni se verificó experimentalmente la eficacia de BUDA.","limitations_en":"This record is based on the publisher abstract; full-text results were not analyzed and BUDA effectiveness was not independently tested.","question_es":null,"question_en":null},{"id":"gh2-justinazoff-ssh-auth-logger","slug":"gh2-justinazoff-ssh-auth-logger","kind":"software","name":"ssh-auth-logger","summary_es":"Repositorio que documenta a low/zero interaction ssh authentication logging honeypot","summary_en":"A low/zero interaction ssh authentication logging honeypot","organization":"JustinAzoff","year":2026,"source_url":"https://github.com/JustinAzoff/ssh-auth-logger","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-sjinks-ssh-honeypotd","slug":"gh2-sjinks-ssh-honeypotd","kind":"software","name":"ssh-honeypotd","summary_es":"Repositorio que documenta a low-interaction SSH honeypot written in C","summary_en":"A low-interaction SSH honeypot written in C","organization":"sjinks","year":2026,"source_url":"https://github.com/sjinks/ssh-honeypotd","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-1109-ojcs-2026-3669021","slug":"doi-10-1109-ojcs-2026-3669021","kind":"paper","name":"Toward Realistic and Efficient Cyber Deception","summary_es":"Registro bibliográfico sobre realismo y eficiencia de deception. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on realism and efficiency of deception. The abstract and findings still require review.","organization":"Hind Alrubaish, Walid Aljoby","year":2026,"source_url":"https://doi.org/10.1109/ojcs.2026.3669021","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Network"],"doi":"10.1109/ojcs.2026.3669021","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"ibm-itg27-deception-2026","slug":"ibm-itg27-deception-2026","kind":"case-study","name":"Trapping a Mustang Panda","summary_es":"IBM X-Force y Deception.Pro registraron dos incidentes en organizaciones simuladas y observaron reconocimiento, despliegue de malware y exfiltración de documentos falsos.","summary_en":"IBM X-Force and Deception.Pro recorded two incidents in simulated organizations, observing reconnaissance, malware deployment and fake-document exfiltration.","organization":"IBM X-Force","year":2026,"source_url":"https://www.ibm.com/think/x-force/trapping-a-mustang-panda","evidence":"threat-research-observation","reviewed_at":"2026-09-15","techniques":["Decoy","Adversary engagement"],"environments":["Endpoint","OT/ICS"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"IBM X-Force describe dos incidentes en organizaciones simuladas con documentos falsos.","critical_observation_en":"IBM X-Force describes two incidents in simulated organizations with fake documents.","limitations_es":"Dos incidentes ilustran conducta; no establecen una tasa de éxito general.","limitations_en":"Two incidents illustrate behavior; they do not establish a general success rate.","question_es":"¿Qué partes de la simulación condicionaron la conducta observada?","question_en":"Which parts of the simulation shaped the observed behavior?"},{"id":"gh2-0xballpoint-trapster-community","slug":"gh2-0xballpoint-trapster-community","kind":"software","name":"Trapster Commmunity","summary_es":"Repositorio que documenta modern honeypot supporting multiple services, realistic website cloning, and AI-powered features","summary_en":"Modern honeypot supporting multiple services, realistic website cloning, and AI-powered features","organization":"0xBallpoint","year":2026,"source_url":"https://github.com/0xBallpoint/trapster-community","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-jekil-udpot","slug":"gh2-jekil-udpot","kind":"software","name":"UDPot Honeypot","summary_es":"Repositorio que documenta simple DNS honeypot script","summary_en":"Simple DNS honeypot script","organization":"jekil","year":2026,"source_url":"https://github.com/jekil/UDPot","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-webdecoy-wordpress-plugin","slug":"gh2-webdecoy-wordpress-plugin","kind":"software","name":"WebDecoy","summary_es":"Repositorio que documenta webDecoy Bot Detection — zero-config WordPress plugin for bot protection, spam prevention, and WooCommerce carding defense","summary_en":"WebDecoy Bot Detection — zero-config WordPress plugin for bot protection, spam prevention, and WooCommerce carding defense","organization":"WebDecoy","year":2026,"source_url":"https://github.com/WebDecoy/wordpress-plugin","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Decoy"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"agents-shared-memory-2026","slug":"agents-shared-memory-2026","kind":"paper","name":"When Agents Talk: Honeytokens under Shared Memory","summary_es":"Análisis formal de límites de honeytokens cuando agentes confiables y atacantes comparten memoria o políticas.","summary_en":"Formal analysis of honeytoken limits when trusted agents and attackers share memory or policies.","organization":"Joshua S. Gans","year":2026,"source_url":"https://arxiv.org/abs/2608.11436","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Honeytoken"],"environments":["Application","Identity"],"doi":null,"review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Análisis formal con límites de variación total y aprendizaje repetido bajo memoria compartida.","design_en":"Formal analysis using total-variation bounds and repeated learning under shared memory.","finding_es":"Muestra que políticas observables por agentes confiables pueden filtrar cómo distinguir honeytokens; propone un monitor privado de referencia.","finding_en":"Shows that policies observable to trusted agents can leak how to distinguish honeytokens; proposes a private reference monitor.","evidence_limits_es":"Los resultados son teóricos y dependen de supuestos sobre conocimiento, repetición y leyes de respuesta.","evidence_limits_en":"Results are theoretical and depend on assumptions about knowledge, repetition and response laws.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"base4-buda","slug":"base4-buda","kind":"software","name":"BUDA","summary_es":"Framework experimental que genera perfiles ficticios y actividad de usuarios para dar contexto a entornos señuelo; el repositorio documenta narrativas, perfiles e integración con modelos de lenguaje.","summary_en":"Experimental framework generating fictitious user profiles and activity for decoy environments; the repository documents narratives, profiles and language-model integration.","organization":"BASE4 Security","year":2025,"source_url":"https://github.com/Base4Security/BUDA","evidence":"repository-documentation","reviewed_at":"2026-09-15","techniques":["Decoy","Adversary engagement"],"environments":["Endpoint","Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":"El repositorio y el paper describen el diseño y las funciones previstas. Esta ficha no verificó la calidad de las huellas generadas ni una mejora de detección en producción.","limitations_en":"The repository and paper describe the design and intended features. This record did not verify generated-trace quality or improved detection in production.","question_es":null,"question_en":null},{"id":"gh-tg12-dns-honeypot","slug":"gh-tg12-dns-honeypot","kind":"software","name":"dns-honeypot","summary_es":"Repositorio sobre simulación de DNS; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about DNS simulation; documentation and maintenance require further review.","organization":"tg12","year":2025,"source_url":"https://github.com/tg12/dns-honeypot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-11591-ijece-v15i1-pp1089-1098","slug":"doi-10-11591-ijece-v15i1-pp1089-1098","kind":"paper","name":"Fortifying industrial cybersecurity: a novel industrial internet of things architecture enhanced by honeypot integration","summary_es":"Registro bibliográfico sobre integración de honeypots en IIoT. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on honeypot integration in industrial IoT. The abstract and findings still require review.","organization":"Oumaima El Kouari, Saiida Lazaar","year":2025,"source_url":"https://doi.org/10.11591/ijece.v15i1.pp1089-1098","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["OT/ICS"],"doi":"10.11591/ijece.v15i1.pp1089-1098","review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Arquitectura conceptual de IIoT que integra honeypots y threat intelligence a niveles de Industria 4.0.","design_en":"Conceptual IIoT architecture integrating honeypots and threat intelligence across Industry 4.0 levels.","finding_es":"Describe un flujo automatizado para reunir observaciones y compartir inteligencia.","finding_en":"Describes an automated flow for collecting observations and sharing intelligence.","evidence_limits_es":"La validación empírica y la seguridad operacional de una planta concreta no quedan demostradas.","evidence_limits_en":"Empirical validation and operational safety in a specific plant are not established.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-yunginnanet-hellpot","slug":"gh2-yunginnanet-hellpot","kind":"software","name":"HellPot","summary_es":"Repositorio que documenta hellPot is a cross-platform portal to endless suffering meant to punish unruly HTTP bots.","summary_en":"HellPot is a cross-platform portal to endless suffering meant to punish unruly HTTP bots.","organization":"yunginnanet","year":2025,"source_url":"https://github.com/yunginnanet/HellPot","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-referefref-honeydet","slug":"gh2-referefref-honeydet","kind":"software","name":"honeydet","summary_es":"Repositorio que documenta signature based honeypot detector tool written in Golang","summary_en":"Signature based honeypot detector tool written in Golang","organization":"referefref","year":2025,"source_url":"https://github.com/referefref/honeydet","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"tpot-anomaly-7-days","slug":"tpot-anomaly-7-days","kind":"dataset","name":"Honeypot-Anomaly-Self Attack","summary_es":"Archivo CSV de siete días de eventos Suricata procedentes de T-Pot, según el registro Zenodo.","summary_en":"CSV of seven days of Suricata events from T-Pot, according to the Zenodo record.","organization":"University of Baghdad","year":2025,"source_url":"https://zenodo.org/records/15830438","evidence":"dataset-record","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":"10.5281/zenodo.15830438","review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"Zenodo ofrece siete días de eventos Suricata procedentes de T-Pot.","critical_observation_en":"Zenodo offers seven days of Suricata events from T-Pot.","limitations_es":"Una ventana semanal puede omitir estacionalidad y no revela por sí sola calidad de etiquetas.","limitations_en":"A one-week window may miss seasonality and does not itself reveal label quality.","question_es":"¿Qué eventos son ataques confirmados y cuáles alertas del sensor?","question_en":"Which events are confirmed attacks and which are sensor alerts?"},{"id":"gh2-logoilab-honeyup","slug":"gh2-logoilab-honeyup","kind":"software","name":"honeyup","summary_es":"Repositorio que documenta an uploader honeypot designed to look like poor website security.","summary_en":"An uploader honeypot designed to look like poor website security.","organization":"LogoiLab","year":2025,"source_url":"https://github.com/mrcbax/honeyup","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-blessedrebus-krawl","slug":"gh-blessedrebus-krawl","kind":"software","name":"Krawl","summary_es":"Repositorio sobre aplicaciones falsas para desviar atacantes; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about fake applications for attacker diversion; documentation and maintenance require further review.","organization":"BlessedRebuS","year":2025,"source_url":"https://github.com/BlessedRebuS/Krawl","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"zenodo-cloud-honeynet","slug":"zenodo-cloud-honeynet","kind":"dataset","name":"Multi-Regional Cloud Honeynet Dataset","summary_es":"Datos de una honeynet con T-Pot distribuida en varias regiones Azure, según el registro de Zenodo.","summary_en":"Data from a T-Pot honeynet spread across Azure regions, according to its Zenodo record.","organization":"Feito-Casares et al.","year":2025,"source_url":"https://zenodo.org/records/15716735","evidence":"dataset-record","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Cloud"],"doi":"10.5281/zenodo.15716735","review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"La ficha Zenodo identifica un dataset de honeynet cloud multirregional.","critical_observation_en":"The Zenodo record identifies a multiregional cloud honeynet dataset.","limitations_es":"El depósito de datos no confirma representatividad ni calidad de etiquetas para todos los escenarios.","limitations_en":"A data deposit does not establish representativeness or label quality for all scenarios.","question_es":"¿Qué regiones, períodos, sensores y criterios de anonimización documenta el dataset?","question_en":"Which regions, periods, sensors and anonymization criteria does the dataset document?"},{"id":"ncsc-deception-trials","slug":"ncsc-deception-trials","kind":"case-study","name":"NCSC Cyber Deception Trials","summary_es":"Informe institucional de pruebas de cyberdeception con organizaciones y proveedores del Reino Unido.","summary_en":"Institutional report on deception trials involving UK organizations and providers.","organization":"UK National Cyber Security Centre","year":2025,"source_url":"https://www.ncsc.gov.uk/blog-post/cyber-deception-trials-what-weve-learned-so-far","evidence":"institutional-evaluation","reviewed_at":"2026-09-15","techniques":["Honeypot","Decoy"],"environments":["Network","Cloud","OT/ICS"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"NCSC describe ensayos institucionales y vacíos de medición del campo.","critical_observation_en":"NCSC describes institutional trials and measurement gaps in the field.","limitations_es":"El informe público no permite extrapolar resultados de una prueba a todas las organizaciones.","limitations_en":"The public report does not allow extrapolation of one trial’s outcomes to all organizations.","question_es":"¿Qué métricas de resultados deberían exigirse en futuras pruebas?","question_en":"Which outcome metrics should future trials require?"},{"id":"zenodo-salty-seagull","slug":"zenodo-salty-seagull","kind":"dataset","name":"Salty Seagull Dataset","summary_es":"Registro de datos de acceso y ataques a una honeynet VSAT.","summary_en":"Record of access and attack data against a VSAT honeynet.","organization":"Dataset authors","year":2025,"source_url":"https://zenodo.org/records/18088113","evidence":"dataset-record","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["OT/ICS"],"doi":"10.5281/zenodo.18088113","review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"La ficha Zenodo presenta un dataset relacionado con deception y telemetría.","critical_observation_en":"The Zenodo record presents a deception-related telemetry dataset.","limitations_es":"La ficha de depósito no sustituye una auditoría de etiquetas, sesgos y condiciones de captura.","limitations_en":"The deposit record does not replace an audit of labels, biases and capture conditions.","question_es":"¿Qué baseline y tareas de investigación permite reproducir?","question_en":"What baseline and research tasks does it support reproducing?"},{"id":"gh2-shiva-spampot-shiva","slug":"gh2-shiva-spampot-shiva","kind":"software","name":"Shiva","summary_es":"Repositorio que documenta spam Honeypot with Intelligent Virtual Analyzer","summary_en":"Spam Honeypot with Intelligent Virtual Analyzer","organization":"shiva-spampot","year":2025,"source_url":"https://github.com/shiva-spampot/shiva","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"honeytoken-generator-2024","slug":"honeytoken-generator-2024","kind":"paper","name":"Act as a Honeytoken Generator! An Investigation into Honeytoken Generation with Large Language Models","summary_es":"Publicación identificada por DOI sobre generación de honeytokens mediante modelos de lenguaje; análisis pendiente del texto.","summary_en":"DOI-identified publication on language-model honeytoken generation; text analysis is pending.","organization":"Publication authors","year":2024,"source_url":"https://doi.org/10.1145/3689935.3690394","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Honeytoken"],"environments":["Identity"],"doi":"10.1145/3689935.3690394","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-1109-eurospw61312-2024-00053","slug":"doi-10-1109-eurospw61312-2024-00053","kind":"paper","name":"Application Layer Cyber Deception Without Developer Interaction","summary_es":"Registro bibliográfico sobre deception en capa de aplicación. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on application-layer deception. The abstract and findings still require review.","organization":"Mario Kahlhofer, Stefan Rass","year":2024,"source_url":"https://doi.org/10.1109/eurospw61312.2024.00053","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Decoy"],"environments":["Application"],"doi":"10.1109/eurospw61312.2024.00053","review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Revisión técnica de 19 métodos para introducir deception en aplicaciones sin modificar su código fuente.","design_en":"Technical review of 19 methods for adding application deception without source-code changes.","finding_es":"Clasifica opciones por contenedor, kernel, red, plataforma y métodos auxiliares.","finding_en":"Classifies options by container, kernel, network, platform and supporting methods.","evidence_limits_es":"Es una comparación de mecanismos; no mide una implementación común bajo carga o ataque.","evidence_limits_en":"It compares mechanisms but does not measure one common implementation under load or attack.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-morian-blacknet","slug":"gh2-morian-blacknet","kind":"software","name":"Blacknet","summary_es":"Repositorio que documenta multi-head SSH honeypot system.","summary_en":"Multi-head SSH honeypot system.","organization":"morian","year":2024,"source_url":"https://github.com/morian/blacknet","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-sap-cloud-active-defense","slug":"gh-sap-cloud-active-defense","kind":"software","name":"cloud-active-defense","summary_es":"Repositorio sobre señuelos en aplicaciones cloud; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about cloud-application decoys; documentation and maintenance require further review.","organization":"SAP","year":2024,"source_url":"https://github.com/SAP/cloud-active-defense","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Cloud"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"ctu-hornet-65-niner","slug":"ctu-hornet-65-niner","kind":"dataset","name":"CTU Hornet 65 Niner","summary_es":"Registro de tráfico Zeek de sensores de baja interacción distribuidos geográficamente; la página indica que no empleó software honeypot convencional.","summary_en":"Zeek traffic record from geographically distributed low-interaction sensors; the page says no conventional honeypot software was used.","organization":"CTU researchers","year":2024,"source_url":"https://zenodo.org/records/13920267","evidence":"dataset-record","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"El registro describe tráfico Zeek de sensores de baja interacción distribuidos.","critical_observation_en":"The record describes Zeek traffic from distributed low-interaction sensors.","limitations_es":"La distribución geográfica no garantiza representatividad de todas las regiones.","limitations_en":"Geographic distribution does not ensure representation of all regions.","question_es":"¿Qué diferencia aporta cada región en origen, protocolo y horario?","question_en":"What difference does each region contribute in origin, protocol and time?"},{"id":"cydec-state-2024","slug":"cydec-state-2024","kind":"paper","name":"Cyber Deception: State of the Art, Trends and Open Challenges","summary_es":"Revisión que propone una taxonomía y compara líneas de investigación en cyberdeception, incluidas las que usan IA.","summary_en":"Survey proposing a taxonomy and comparing cyber deception research lines, including AI-based work.","organization":"Beltrán López et al.","year":2024,"source_url":"https://arxiv.org/abs/2409.07194","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Adversary engagement"],"environments":["Network","Cloud"],"doi":null,"review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Revisión con selección objetiva y subjetiva de 83 trabajos publicados entre 2019 y 2023.","design_en":"Survey using objective and subjective selection of 83 works published from 2019 to 2023.","finding_es":"Integra taxonomía, frameworks, técnicas con y sin IA, TRL y desafíos; identifica falta de métricas comunes.","finding_en":"Combines taxonomy, frameworks, AI and non-AI techniques, TRL and challenges; identifies the lack of common metrics.","evidence_limits_es":"La selección subjetiva y el corte temporal limitan reproducibilidad y actualidad; no compara resultados con un benchmark único.","evidence_limits_en":"Subjective selection and the time window limit reproducibility and currency; outcomes are not compared on one benchmark.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"El abstract anuncia una revisión de tendencias y desafíos del campo.","critical_observation_en":"The abstract announces a review of trends and open challenges in the field.","limitations_es":"La ficha parte del abstract; no se verificaron aquí criterios de selección, estudios incluidos ni resultados del texto completo.","limitations_en":"This record is based on the abstract; selection criteria, included studies and full-text results were not checked here.","question_es":"¿Qué subáreas quedan fuera de la taxonomía propuesta por los autores?","question_en":"Which subfields fall outside the authors’ proposed taxonomy?"},{"id":"base4-dolos-t","slug":"base4-dolos-t","kind":"software","name":"DOLOS-T","summary_es":"Framework abierto para planificar operaciones de deception y desplegar señuelos y servicios mediante Python y Docker, según el repositorio y su documentación.","summary_en":"Open framework for planning deception operations and deploying decoys and services with Python and Docker, according to its repository and documentation.","organization":"BASE4 Security","year":2024,"source_url":"https://github.com/Base4Security/DOLOS-T","evidence":"repository-documentation","reviewed_at":"2026-09-15","techniques":["Decoy","Honeypot","Adversary engagement"],"environments":["Network","Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":"No se probó en esta revisión el aislamiento, la fidelidad de los señuelos ni su rendimiento operativo. El artículo relacionado propone una metodología, no una comparación de resultados.","limitations_en":"This review did not test isolation, decoy fidelity or operational performance. The related paper proposes a methodology, not a comparative outcome study.","question_es":null,"question_en":null},{"id":"gh2-johnnykv-heralding","slug":"gh2-johnnykv-heralding","kind":"software","name":"Heralding","summary_es":"Repositorio que documenta credentials catching honeypot","summary_en":"Credentials catching honeypot","organization":"johnnykv","year":2024,"source_url":"https://github.com/johnnykv/heralding","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"honeygpt-2024","slug":"honeygpt-2024","kind":"paper","name":"HoneyGPT: Breaking the Trilemma in Terminal Honeypots with Large Language Model","summary_es":"Presenta una arquitectura de honeypot de terminal con modelo de lenguaje y describe su evaluación en campo.","summary_en":"Presents a language-model terminal honeypot architecture and describes a field evaluation.","organization":"Wang et al.","year":2024,"source_url":"https://arxiv.org/abs/2406.01882","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Arquitectura de terminal con LLM evaluada con métricas de respuesta, longitud e interacción.","design_en":"LLM terminal architecture evaluated with response, session-length and interaction metrics.","finding_es":"En las pruebas informadas, las variantes GPT responden a más comandos y sesiones que Cowrie.","finding_en":"In the reported tests, GPT variants respond to more commands and sessions than Cowrie.","evidence_limits_es":"Las métricas favorecen cobertura de respuesta; no prueban credibilidad ante adversarios humanos ni costo sostenido.","evidence_limits_en":"Metrics favor response coverage; they do not prove credibility against human adversaries or sustained cost.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"El abstract describe arquitectura y evaluación de un honeypot de terminal con modelo de lenguaje.","critical_observation_en":"The abstract describes an architecture and evaluation of a language-model terminal honeypot.","limitations_es":"No se extrajeron del texto completo métricas, condiciones de campo ni resultados negativos.","limitations_en":"Metrics, field conditions and negative outcomes were not extracted from the full text.","question_es":"¿Cuál fue el baseline y cómo se midió que el señuelo parecía auténtico?","question_en":"What was the baseline, and how was decoy realism measured?"},{"id":"gh2-bocajspear1-honeyhttpd","slug":"gh2-bocajspear1-honeyhttpd","kind":"software","name":"honeyhttpd","summary_es":"Repositorio que documenta honeyHTTPD is a Python-based web server honeypot/service imitation builder. Great for honeypots or faking HTTP services.","summary_en":"HoneyHTTPD is a Python-based web server honeypot/service imitation builder. Great for honeypots or faking HTTP services.","organization":"bocajspear1","year":2024,"source_url":"https://github.com/bocajspear1/honeyhttpd","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-alexbredo-honeypot-ftp","slug":"gh2-alexbredo-honeypot-ftp","kind":"software","name":"honeypot-ftp","summary_es":"Repositorio que documenta fTP Honeypot","summary_en":"FTP Honeypot","organization":"alexbredo","year":2024,"source_url":"https://github.com/alexbredo/honeypot-ftp","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-free5ty1e-honeypotpi","slug":"gh2-free5ty1e-honeypotpi","kind":"software","name":"honeypotpi","summary_es":"Repositorio que documenta script for turning a Raspberry Pi into a Honey Pot Pi","summary_en":"Script for turning a Raspberry Pi into a Honey Pot Pi","organization":"free5ty1e","year":2024,"source_url":"https://github.com/free5ty1e/honeypotpi","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"llm-honeypot-2024","slug":"llm-honeypot-2024","kind":"paper","name":"LLM Honeypot: Leveraging Large Language Models as Advanced Interactive Honeypot Systems","summary_es":"Presenta un honeypot interactivo basado en un modelo de lenguaje ajustado con datos de comandos de atacantes.","summary_en":"Presents an interactive honeypot using a language model fine-tuned with attacker command data.","organization":"Otal & Canbaz","year":2024,"source_url":"https://arxiv.org/abs/2409.08234","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Prototipo de honeypot SSH con un modelo abierto ajustado sobre comandos maliciosos.","design_en":"SSH honeypot prototype using an open model fine-tuned on malicious commands.","finding_es":"Muestra una ruta para producir respuestas interactivas y registrar sesiones con mayor contexto.","finding_en":"Shows a route to interactive responses and richer session recording.","evidence_limits_es":"La evaluación es acotada y no establece resistencia prolongada a fingerprinting ni costos de producción.","evidence_limits_en":"The evaluation is limited and does not establish long-term fingerprint resistance or production cost.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"El abstract describe un honeypot interactivo apoyado en un modelo ajustado con comandos.","critical_observation_en":"The abstract describes an interactive honeypot using a model fine-tuned with commands.","limitations_es":"La ficha no revisó el texto completo, la evaluación ni los costos de mantener el modelo.","limitations_en":"This record did not review the full text, evaluation or model maintenance costs.","question_es":"¿Cómo se mide coherencia de respuestas frente a un atacante que prueba inconsistencias?","question_en":"How is response coherence measured against an attacker probing inconsistencies?"},{"id":"gh2-thomaspatzke-log4pot","slug":"gh2-thomaspatzke-log4pot","kind":"software","name":"Log4Pot","summary_es":"Repositorio que documenta a honeypot for the Log4Shell vulnerability (CVE-2021-44228).","summary_en":"A honeypot for the Log4Shell vulnerability (CVE-2021-44228).","organization":"thomaspatzke","year":2024,"source_url":"https://github.com/thomaspatzke/Log4Pot","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-batchmcnulty-malbait","slug":"gh2-batchmcnulty-malbait","kind":"software","name":"Malbait","summary_es":"Repositorio que documenta simple TCP/UDP honeypot implemented in Perl","summary_en":"Simple TCP/UDP honeypot implemented in Perl","organization":"batchmcnulty","year":2024,"source_url":"https://github.com/batchmcnulty/Malbait","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-schmalle-medpot","slug":"gh2-schmalle-medpot","kind":"software","name":"medpot","summary_es":"Repositorio que documenta hL7 / FHIR honeypot","summary_en":"HL7 / FHIR honeypot","organization":"schmalle","year":2024,"source_url":"https://github.com/schmalle/medpot","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-referefref-modpot","slug":"gh-referefref-modpot","kind":"software","name":"modpot","summary_es":"Repositorio sobre framework modular de honeypots web; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about modular web honeypot framework; documentation and maintenance require further review.","organization":"referefref","year":2024,"source_url":"https://github.com/referefref/modpot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"dolos-t-minimal-deception-2024","slug":"dolos-t-minimal-deception-2024","kind":"paper","name":"Propuesta para implementación de estrategias minimalistas de ciber engaño","summary_es":"Preprint de Pacheco y Staino que propone un proceso cíclico y minimalista de deception y presenta DOLOS-T como herramienta abierta para experimentarlo.","summary_en":"Pacheco and Staino preprint proposing a cyclical, minimal deception process and presenting DOLOS-T as an open tool for exploring it.","organization":"Federico Pacheco y Diego Staino","year":2024,"source_url":"https://www.researchgate.net/publication/379404267_Proposal_for_the_implementation_of_minimalistic_cyber_deception_strategies","evidence":"paper-abstract","reviewed_at":"2026-09-15","techniques":["Decoy","Adversary engagement"],"environments":["Network","Application"],"doi":"10.13140/RG.2.2.34289.29289","review_basis":"abstract","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"es","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":"Se trata de un preprint de propuesta y arquitectura. Las expectativas de eficacia y bajo impacto operativo no equivalen a una evaluación independiente.","limitations_en":"This is a proposal and architecture preprint. Expected effectiveness and low operational impact are not independent evaluations.","question_es":null,"question_en":null},{"id":"gh2-jaksi-sshesame","slug":"gh2-jaksi-sshesame","kind":"software","name":"sshesame","summary_es":"Repositorio que documenta an easy to set up and use SSH honeypot, a fake SSH server that lets anyone in and logs their activity","summary_en":"An easy to set up and use SSH honeypot, a fake SSH server that lets anyone in and logs their activity","organization":"jaksi","year":2024,"source_url":"https://github.com/jaksi/sshesame","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"network-requirements-2023","slug":"network-requirements-2023","kind":"paper","name":"A Survey of Network Requirements for Enabling Effective Cyber Deception","summary_es":"Revisión de requisitos de red necesarios para implementar técnicas de cyberdeception.","summary_en":"Survey of network requirements for implementing cyber deception techniques.","organization":"Sayed et al.","year":2023,"source_url":"https://arxiv.org/abs/2309.00184","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Decoy"],"environments":["Network"],"doi":null,"review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Revisión narrativa de requisitos de virtualización, SDN, honeynets, MTD y evaluación de red.","design_en":"Narrative review of virtualization, SDN, honeynets, MTD and network-evaluation requirements.","finding_es":"Organiza dependencias de red que condicionan despliegue y medición de mecanismos de deception.","finding_en":"Organizes network dependencies that shape deployment and measurement of deception mechanisms.","evidence_limits_es":"No documenta protocolo sistemático de búsqueda ni valida una arquitectura completa.","evidence_limits_en":"It does not document a systematic search protocol or validate a complete architecture.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"El abstract trata requisitos de red para desplegar deception eficazmente.","critical_observation_en":"The abstract addresses network requirements for effective deception deployment.","limitations_es":"La ficha no verifica cuáles requisitos fueron validados en redes de producción.","limitations_en":"This record does not verify which requirements were validated in production networks.","question_es":"¿Qué restricciones de segmentación y telemetría limitan el despliegue?","question_en":"Which segmentation and telemetry constraints limit deployment?"},{"id":"doi-10-1016-j-cose-2023-103268","slug":"doi-10-1016-j-cose-2023-103268","kind":"paper","name":"Cyber expert feedback: Experiences, expectations, and opinions about cyber deception","summary_es":"Registro bibliográfico sobre experiencias y opiniones de expertos. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on expert experiences and opinions. The abstract and findings still require review.","organization":"Kimberly J. Ferguson-Walter, Maxine M. Major","year":2023,"source_url":"https://doi.org/10.1016/j.cose.2023.103268","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Adversary engagement"],"environments":["Network"],"doi":"10.1016/j.cose.2023.103268","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-jeremyfritzen-ethereum-honey-pot","slug":"gh2-jeremyfritzen-ethereum-honey-pot","kind":"software","name":"Ethereum-honey-pot","summary_es":"Repositorio que documenta ethereum honey pot","summary_en":"Ethereum honey pot","organization":"jeremyfritzen","year":2023,"source_url":"https://github.com/jeremyfritzen/Ethereum-honey-pot","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"deception-mtd-simulation-2023","slug":"deception-mtd-simulation-2023","kind":"paper","name":"Evaluating Deception and Moving Target Defense with Network Attack Simulation","summary_es":"Propone un método de simulación para evaluar honeypots y moving target defense en redes.","summary_en":"Proposes a simulation method for evaluating honeypots and moving target defense in networks.","organization":"Research authors","year":2023,"source_url":"https://arxiv.org/abs/2301.10629","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Honeypot","Moving target defense"],"environments":["Network"],"doi":null,"review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Simulación basada en NASim con tres escenarios y tipos de atacante para variar honeypots y mutación de direcciones.","design_en":"NASim-based simulation with three scenarios and attacker types varying honeypots and address mutation.","finding_es":"El método permite explorar configuraciones frente a parámetros explícitos de red y atacante.","finding_en":"The method explores configurations against explicit network and attacker parameters.","evidence_limits_es":"Los resultados dependen de agentes y escenarios simulados y no equivalen a comportamiento en una red real.","evidence_limits_en":"Results depend on simulated agents and scenarios and do not equal behavior on a real network.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"El abstract presenta simulación de ataques para evaluar deception y moving target defense.","critical_observation_en":"The abstract presents attack simulation to evaluate deception and moving target defense.","limitations_es":"Una simulación depende de los supuestos y no sustituye mediciones de adversarios y redes reales.","limitations_en":"A simulation depends on its assumptions and does not replace measurement of real adversaries and networks.","question_es":"¿Qué parámetros y datos permiten reproducir el experimento?","question_en":"Which parameters and data make the experiment reproducible?"},{"id":"honey-infiltrator-2023","slug":"honey-infiltrator-2023","kind":"paper","name":"Honey Infiltrator: Injecting Honeytoken Using Netfilter","summary_es":"Publicación identificada por DOI sobre inserción de honeytokens con Netfilter; análisis pendiente del texto.","summary_en":"DOI-identified publication on injecting honeytokens using Netfilter; text analysis is pending.","organization":"Publication authors","year":2023,"source_url":"https://doi.org/10.1109/eurospw59978.2023.00057","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Honeytoken"],"environments":["Network"],"doi":"10.1109/eurospw59978.2023.00057","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-cymmetria-honeycomb-plugins","slug":"gh2-cymmetria-honeycomb-plugins","kind":"software","name":"honeycomb_plugins","summary_es":"Repositorio que documenta the plugin repository for Honeycomb, the honeypot framework by Cymmetria","summary_en":"The plugin repository for Honeycomb, the honeypot framework by Cymmetria","organization":"Cymmetria","year":2023,"source_url":"https://github.com/Cymmetria/honeycomb_plugins","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-referefref-honeyfs","slug":"gh2-referefref-honeyfs","kind":"software","name":"honeyfs","summary_es":"Repositorio que documenta lLM Based Honeypot File System Creator","summary_en":"LLM Based Honeypot File System Creator","organization":"referefref","year":2023,"source_url":"https://github.com/referefref/honeyfs","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-sefcom-honeyplc","slug":"gh2-sefcom-honeyplc","kind":"software","name":"HoneyPLC","summary_es":"Repositorio que documenta high-interaction Honeypot for PLCs and Industrial Control Systems","summary_en":"High-interaction Honeypot for PLCs and Industrial Control Systems","organization":"sefcom","year":2023,"source_url":"https://github.com/sefcom/honeyplc","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["OT/ICS"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-desaster-kippo","slug":"gh2-desaster-kippo","kind":"software","name":"Kippo","summary_es":"Repositorio que documenta kippo - SSH Honeypot","summary_en":"Kippo - SSH Honeypot","organization":"desaster","year":2023,"source_url":"https://github.com/desaster/kippo","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-sa7mon-miniprint","slug":"gh2-sa7mon-miniprint","kind":"software","name":"miniprint","summary_es":"Repositorio que documenta a medium interaction printer honeypot 🍯","summary_en":"A medium interaction printer honeypot 🍯","organization":"sa7mon","year":2023,"source_url":"https://github.com/sa7mon/miniprint","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-1109-csnet59123-2023-10339776","slug":"doi-10-1109-csnet59123-2023-10339776","kind":"paper","name":"Mirage: Cyber Deception against Autonomous Cyber Attacks","summary_es":"Registro bibliográfico sobre engaño frente a ataques autónomos. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on deception against autonomous attacks. The abstract and findings still require review.","organization":"Michael Kouremetis, Ron Alford","year":2023,"source_url":"https://doi.org/10.1109/csnet59123.2023.10339776","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Network"],"doi":"10.1109/csnet59123.2023.10339776","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-datasoft-nova","slug":"gh2-datasoft-nova","kind":"software","name":"NOVA","summary_es":"Repositorio que documenta repo for the Open Source version of NOVA","summary_en":"Repo for the Open Source version of NOVA","organization":"DataSoft","year":2023,"source_url":"https://github.com/DataSoft/Nova","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-referefref-smtpllmpot","slug":"gh2-referefref-smtpllmpot","kind":"software","name":"SMTPLLMPot","summary_es":"Repositorio que documenta a simple PoC for the use of GPT3.5 in creating an SMTP honeypot","summary_en":"A simple PoC for the use of GPT3.5 in creating an SMTP honeypot","organization":"referefref","year":2023,"source_url":"https://github.com/referefref/SMTPLLMPot","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-gbrindisi-wordpot","slug":"gh2-gbrindisi-wordpot","kind":"software","name":"wordpot","summary_es":"Repositorio que documenta a Wordpress Honeypot","summary_en":"A Wordpress Honeypot","organization":"gbrindisi","year":2023,"source_url":"https://github.com/gbrindisi/wordpot","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-18653-v1-2022-findings-emnlp-486","slug":"doi-10-18653-v1-2022-findings-emnlp-486","kind":"paper","name":"Controllable Fake Document Infilling for Cyber Deception","summary_es":"Registro bibliográfico sobre documentos falsos controlables. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on controllable fake documents. The abstract and findings still require review.","organization":"Yibo Hu, Yu Lin","year":2022,"source_url":"https://doi.org/10.18653/v1/2022.findings-emnlp.486","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Honeytoken"],"environments":["Identity"],"doi":"10.18653/v1/2022.findings-emnlp.486","review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Generación mask-then-infill evaluada en abstracts técnicos, patentes y noticias, con evaluación automática y humana.","design_en":"Mask-then-infill generation evaluated on technical abstracts, patents and news with automatic and human evaluation.","finding_es":"FDI busca preservar plausibilidad mientras modifica información crítica y supera los baselines reportados.","finding_en":"FDI aims to preserve plausibility while changing critical information and exceeds reported baselines.","evidence_limits_es":"La evaluación humana fue costosa, tuvo poco solapamiento entre revisores y no permitió calcular acuerdo Kappa.","evidence_limits_en":"Human evaluation was costly, had little reviewer overlap and did not allow Kappa agreement calculation.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-1109-wsc57314-2022-10015347","slug":"doi-10-1109-wsc57314-2022-10015347","kind":"paper","name":"Cyber Deception Metrics For Interconnected Complex Systems","summary_es":"Registro bibliográfico sobre métricas para sistemas complejos. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on metrics for complex systems. The abstract and findings still require review.","organization":"Md Ali Reza Al Amin, Sachin Shetty","year":2022,"source_url":"https://doi.org/10.1109/wsc57314.2022.10015347","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Adversary engagement"],"environments":["Network"],"doi":"10.1109/wsc57314.2022.10015347","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-secureworks-dcept","slug":"gh2-secureworks-dcept","kind":"software","name":"dcept","summary_es":"Repositorio que documenta a tool for deploying and detecting use of Active Directory honeytokens","summary_en":"A tool for deploying and detecting use of Active Directory honeytokens","organization":"secureworks","year":2022,"source_url":"https://github.com/secureworks/dcept","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeytoken"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-yvesago-imap-honey","slug":"gh2-yvesago-imap-honey","kind":"software","name":"imap-honey","summary_es":"Repositorio que documenta iMAP or SMTP honeypot written in Golang","summary_en":"IMAP or SMTP honeypot written in Golang","organization":"yvesago","year":2022,"source_url":"https://github.com/yvesago/imap-honey","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-deroux-longitudinal-analysis-cowrie","slug":"gh2-deroux-longitudinal-analysis-cowrie","kind":"software","name":"Longitudinal Analysis of SSH Cowrie Honeypot Logs","summary_es":"Repositorio que documenta longitudinal Analysis of SSH Cowrie Honeypot Logs","summary_en":"Longitudinal Analysis of SSH Cowrie Honeypot Logs","organization":"deroux","year":2022,"source_url":"https://github.com/deroux/longitudinal-analysis-cowrie","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"honeytoken-auth-2021","slug":"honeytoken-auth-2021","kind":"paper","name":"Cybersecurity Revisited: Honeytokens Meet Google Authenticator","summary_es":"Mecanismo de autenticación de dos factores que combina códigos señuelo y Google Authenticator.","summary_en":"Two-factor authentication mechanism combining decoy codes with Google Authenticator.","organization":"Papaspirou et al.","year":2021,"source_url":"https://arxiv.org/abs/2112.08431","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Honeytoken"],"environments":["Identity"],"doi":null,"review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Prototipo de autenticación que combina códigos reales y señuelo con un segundo factor basado en TOTP.","design_en":"Authentication prototype combining real and decoy codes with a TOTP-based second factor.","finding_es":"Busca detectar uso de secretos robados y conservar compatibilidad con autenticadores habituales.","finding_en":"Aims to detect use of stolen secrets while retaining compatibility with common authenticators.","evidence_limits_es":"La evaluación es de prototipo y análisis de ataques; faltan estudio de usuarios y despliegue a escala.","evidence_limits_en":"Evaluation is a prototype and attack analysis; user study and deployment at scale are missing.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"deception-challenges-2021","slug":"deception-challenges-2021","kind":"paper","name":"Deception for Cyber Defence: Challenges and Opportunities","summary_es":"Artículo de visión sobre generación automatizada de artefactos de engaño realistas mediante aprendizaje automático.","summary_en":"Vision paper on automated generation of realistic deception artifacts with machine learning.","organization":"Liebowitz et al.","year":2021,"source_url":"https://arxiv.org/abs/2208.07127","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Decoy"],"environments":["Network","Identity"],"doi":"10.1109/TPSISA52974.2021.00026","review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Artículo de visión que recorre generación de hosts, documentos, actividad y comunicaciones mediante ML.","design_en":"Vision paper covering ML generation of hosts, documents, activity and communications.","finding_es":"Identifica la generación realista y escalable como oportunidad central y organiza riesgos y líneas de trabajo.","finding_en":"Identifies scalable realistic generation as a central opportunity and organizes risks and research directions.","evidence_limits_es":"No es una revisión sistemática ni una evaluación de un sistema integrado.","evidence_limits_en":"It is neither a systematic review nor an evaluation of an integrated system.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-24251-hicss-2021-240","slug":"doi-10-24251-hicss-2021-240","kind":"paper","name":"Design Thinking for Cyber Deception","summary_es":"Registro bibliográfico sobre design thinking para cyberdeception. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on design thinking for cyber deception. The abstract and findings still require review.","organization":"Debi Ashenden, Rob Black","year":2021,"source_url":"https://doi.org/10.24251/hicss.2021.240","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Decoy"],"environments":["Network"],"doi":"10.24251/hicss.2021.240","review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Aplicación exploratoria de design thinking para sintetizar conceptos de engaño de varios dominios.","design_en":"Exploratory use of design thinking to synthesize deception concepts from multiple domains.","finding_es":"Produce conceptos y un proceso de ideación para ampliar el repertorio del defensor.","finding_en":"Produces concepts and an ideation process to broaden the defender repertoire.","evidence_limits_es":"Los conceptos no se evalúan como controles desplegados ni mediante métricas de seguridad.","evidence_limits_en":"Concepts are not evaluated as deployed controls or through security metrics.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-1109-lcn52139-2021-9525010","slug":"doi-10-1109-lcn52139-2021-9525010","kind":"paper","name":"Failure Modes and Effects Analysis (FMEA) of Honeypot-Based Cybersecurity Experiment for IoT","summary_es":"Registro bibliográfico sobre análisis de fallas en experimentos IoT. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on failure analysis in IoT experiments. The abstract and findings still require review.","organization":"Junaid Haseeb, Masood Mansoori","year":2021,"source_url":"https://doi.org/10.1109/lcn52139.2021.9525010","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["IoT"],"doi":"10.1109/lcn52139.2021.9525010","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-1145-3474370-3485656","slug":"doi-10-1145-3474370-3485656","kind":"paper","name":"Game Theoretic Models for Cyber Deception","summary_es":"Registro bibliográfico sobre modelos de teoría de juegos para deception. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on game-theoretic deception models. The abstract and findings still require review.","organization":"Fei Fang","year":2021,"source_url":"https://doi.org/10.1145/3474370.3485656","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Adversary engagement"],"environments":["Network"],"doi":"10.1145/3474370.3485656","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-uhh-iss-honeygrove","slug":"gh2-uhh-iss-honeygrove","kind":"software","name":"Honeygrove","summary_es":"Repositorio que documenta a multi-purpose, modular medium-interaction honeypot based on Twisted.","summary_en":"A multi-purpose, modular medium-interaction honeypot based on Twisted.","organization":"UHH-ISS","year":2021,"source_url":"https://github.com/UHH-ISS/honeygrove","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-qeeqbox-honeypots","slug":"gh-qeeqbox-honeypots","kind":"software","name":"honeypots","summary_es":"Repositorio sobre sensores de múltiples protocolos; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about multi-protocol sensors; documentation and maintenance require further review.","organization":"qeeqbox","year":2021,"source_url":"https://github.com/qeeqbox/honeypots","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-binarydefense-log4j-honeypot-flask","slug":"gh-binarydefense-log4j-honeypot-flask","kind":"software","name":"log4j-honeypot-flask","summary_es":"Repositorio sobre observación de escaneos Log4j; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about observation of Log4j scans; documentation and maintenance require further review.","organization":"BinaryDefense","year":2021,"source_url":"https://github.com/BinaryDefense/log4j-honeypot-flask","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-citronneur-rdpy","slug":"gh2-citronneur-rdpy","kind":"software","name":"RDPy","summary_es":"Repositorio que documenta remote Desktop Protocol in Twisted Python","summary_en":"Remote Desktop Protocol in Twisted Python","organization":"citronneur","year":2021,"source_url":"https://github.com/citronneur/rdpy","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-cypwnpwnsocute-redishoneypot","slug":"gh-cypwnpwnsocute-redishoneypot","kind":"software","name":"RedisHoneyPot","summary_es":"Repositorio sobre servicio señuelo Redis; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about decoy Redis service; documentation and maintenance require further review.","organization":"cypwnpwnsocute","year":2021,"source_url":"https://github.com/cypwnpwnsocute/RedisHoneyPot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-r0hi7-honeysmb","slug":"gh2-r0hi7-honeysmb","kind":"software","name":"SMB Honeypot","summary_es":"Repositorio que documenta simple High Interaction Honeypot Solution for SMB protocol","summary_en":"Simple High Interaction Honeypot Solution for SMB protocol","organization":"r0hi7","year":2021,"source_url":"https://github.com/rosehgal/HoneySMB","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"three-decades-2021","slug":"three-decades-2021","kind":"paper","name":"Three Decades of Deception Techniques in Active Cyber Defense—Retrospect and Outlook","summary_es":"Revisión histórica de honeypots, honeytokens y moving target defense entre fines de los años 1980 y 2021.","summary_en":"Historical review of honeypots, honeytokens and moving target defense from the late 1980s through 2021.","organization":"Zhang & Thing","year":2021,"source_url":"https://arxiv.org/abs/2104.03594","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Honeypot","Honeytoken","Moving target defense"],"environments":["Network","Endpoint"],"doi":"10.1016/j.cose.2021.102288","review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Revisión histórica de trabajos representativos sobre honeypots, honeytokens y MTD hasta 2021.","design_en":"Historical review of representative work on honeypots, honeytokens and MTD through 2021.","finding_es":"Muestra complementariedad entre las tres familias y reclama evaluación en plataformas realistas.","finding_en":"Shows complementarity among the three families and calls for evaluation on realistic platforms.","evidence_limits_es":"La selección representativa no equivale a un inventario exhaustivo y el corte excluye avances posteriores.","evidence_limits_en":"Representative selection is not an exhaustive inventory and the cutoff excludes later advances.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-24251-hicss-2021-244","slug":"doi-10-24251-hicss-2021-244","kind":"paper","name":"Towards Self-Adaptive Cyber Deception for Defense","summary_es":"Registro bibliográfico sobre deception autoadaptativo. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on self-adaptive deception. The abstract and findings still require review.","organization":"Jason Landsborough, Luke Carpenter","year":2021,"source_url":"https://doi.org/10.24251/hicss.2021.244","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Decoy"],"environments":["Network"],"doi":"10.24251/hicss.2021.244","review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Sistema autonómico que compara ausencia de deception, señuelos estáticos y tácticas adaptativas contra un atacante automatizado.","design_en":"Autonomic system comparing no deception, static decoys and adaptive tactics against an automated attacker.","finding_es":"Los experimentos reportan ventaja defensiva con señuelos y adaptación guiada por objetivos.","finding_en":"Experiments report defender advantage from decoys and goal-guided adaptation.","evidence_limits_es":"El atacante es automatizado y las tácticas y escenarios son acotados; no demuestra efecto frente a equipos humanos.","evidence_limits_en":"The attacker is automated and tactics and scenarios are limited; effects against human teams are not established.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-1109-secdev45635-2020-00023","slug":"doi-10-1109-secdev45635-2020-00023","kind":"paper","name":"Active Deception Framework: An Extensible Development Environment for Adaptive Cyber Deception","summary_es":"Registro bibliográfico sobre un framework adaptable de deception. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on an adaptive deception framework. The abstract and findings still require review.","organization":"Md Mazharul Islam, Ehab Al-Shaer","year":2020,"source_url":"https://doi.org/10.1109/secdev45635.2020.00023","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Application"],"doi":"10.1109/secdev45635.2020.00023","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-24251-hicss-2020-232","slug":"doi-10-24251-hicss-2020-232","kind":"paper","name":"Adaptive Cyber Deception: Cognitively Informed Signaling for Cyber Defense","summary_es":"Registro bibliográfico sobre señales adaptativas para defensa. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on adaptive signaling for cyber defense. The abstract and findings still require review.","organization":"Edward Cranford, Cleotilde Gonzalez","year":2020,"source_url":"https://doi.org/10.24251/hicss.2020.232","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Decoy"],"environments":["Network"],"doi":"10.24251/hicss.2020.232","review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Modelo de señalización adaptativa informado por un modelo cognitivo y experiencia del atacante.","design_en":"Adaptive signaling model informed by a cognitive model and attacker experience.","finding_es":"Propone ajustar señales para explotar y conservar la creencia del atacante en lugar de asumir racionalidad perfecta.","finding_en":"Proposes adapting signals to exploit and preserve attacker belief instead of assuming perfect rationality.","evidence_limits_es":"El aporte es principalmente modelado; la transferencia a adversarios y operaciones reales requiere experimentos adicionales.","evidence_limits_en":"The contribution is mainly modeling; transfer to real adversaries and operations needs further experiments.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-malwaretech-citrixhoneypot","slug":"gh-malwaretech-citrixhoneypot","kind":"software","name":"CitrixHoneypot","summary_es":"Repositorio sobre observación de explotación Citrix; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about observation of Citrix exploitation; documentation and maintenance require further review.","organization":"MalwareTech","year":2020,"source_url":"https://github.com/MalwareTech/CitrixHoneypot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"cydec-survey-2020","slug":"cydec-survey-2020","kind":"paper","name":"Cyber Deception for Computer and Network Security: Survey and Challenges","summary_es":"Revisión de modelos y técnicas de engaño defensivo en redes, sistemas y mecanismos criptográficos.","summary_en":"Survey of defensive deception models and techniques in networks, hosts and cryptographic mechanisms.","organization":"Lu et al.","year":2020,"source_url":"https://arxiv.org/abs/2007.14497","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Decoy"],"environments":["Network","Endpoint"],"doi":null,"review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Revisión conceptual de modelos, acciones y aplicaciones de deception en red, host y criptografía.","design_en":"Conceptual review of deception models, actions and applications across networks, hosts and cryptography.","finding_es":"Modela deception como interacción iterativa de planificación, despliegue y evaluación, y separa simulación de disimulación.","finding_en":"Models deception as iterative planning, deployment and evaluation, and separates simulation from dissimulation.","evidence_limits_es":"No presenta una búsqueda sistemática ni una evaluación comparable de efectividad.","evidence_limits_en":"It does not provide a systematic search or comparable effectiveness evaluation.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"El abstract presenta una revisión de modelos y técnicas de engaño defensivo.","critical_observation_en":"The abstract presents a survey of defensive deception models and techniques.","limitations_es":"La clasificación descrita por los autores no constituye una prueba operativa de cada técnica.","limitations_en":"The authors’ classification is not an operational test of every technique.","question_es":"¿Qué técnicas cuentan con evaluación reproducible y cuáles solo con modelos?","question_en":"Which techniques have reproducible evaluation, and which only models?"},{"id":"zenodo-cyberlab-honeynet","slug":"zenodo-cyberlab-honeynet","kind":"dataset","name":"CyberLab Honeynet Dataset","summary_es":"Datos de sesiones de honeypots Cowrie obtenidos en un despliegue distribuido, según Zenodo.","summary_en":"Cowrie honeypot session data from a distributed deployment, according to Zenodo.","organization":"CyberLab / University of Ljubljana","year":2020,"source_url":"https://zenodo.org/records/3687527","evidence":"dataset-record","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":"10.5281/zenodo.3687527","review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"Zenodo conserva un conjunto de datos publicado para análisis de honeynet.","critical_observation_en":"Zenodo hosts a published dataset for honeynet analysis.","limitations_es":"Sin revisar esquema, recolección y licencia no se debe asumir comparabilidad con otros datasets.","limitations_en":"Without reviewing schema, collection and license, comparability with other datasets should not be assumed.","question_es":"¿Qué campos permiten reconstruir una sesión y cuáles se omitieron?","question_en":"Which fields allow reconstruction of a session, and which were omitted?"},{"id":"gh-aelth-ddospot","slug":"gh-aelth-ddospot","kind":"software","name":"ddospot","summary_es":"Repositorio sobre observación de abusos de servicios UDP; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about observation of UDP-service abuse; documentation and maintenance require further review.","organization":"aelth","year":2020,"source_url":"https://github.com/aelth/ddospot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-ciscocsirt-dhp","slug":"gh-ciscocsirt-dhp","kind":"software","name":"dhp","summary_es":"Repositorio sobre simulación de la API de Docker; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about Docker API simulation; documentation and maintenance require further review.","organization":"ciscocsirt","year":2020,"source_url":"https://github.com/ciscocsirt/dhp","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Cloud"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-24251-hicss-2020-233","slug":"doi-10-24251-hicss-2020-233","kind":"paper","name":"HoneyBug: Personalized Cyber Deception for Web Applications","summary_es":"Registro bibliográfico sobre deception personalizado en aplicaciones web. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on personalized web-application deception. The abstract and findings still require review.","organization":"Amirreza Niakanlahiji, Jafar Haadi Jafarian","year":2020,"source_url":"https://doi.org/10.24251/hicss.2020.233","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Application"],"doi":"10.24251/hicss.2020.233","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-kungfuguapo-honeypress","slug":"gh2-kungfuguapo-honeypress","kind":"software","name":"HoneyPress","summary_es":"Repositorio que documenta python based WordPress honeypot in a docker container","summary_en":"python based WordPress honeypot in a docker container","organization":"kungfuguapo","year":2020,"source_url":"https://github.com/kungfuguapo/HoneyPress","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-rshipp-slipm-honeypot","slug":"gh2-rshipp-slipm-honeypot","kind":"software","name":"slipm-honeypot","summary_es":"Repositorio que documenta a simple low-interaction port monitoring honeypot.","summary_en":"A simple low-interaction port monitoring honeypot.","organization":"rshipp","year":2020,"source_url":"https://github.com/rshipp/slipm-honeypot","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-1109-globecom42002-2020-9348122","slug":"doi-10-1109-globecom42002-2020-9348122","kind":"paper","name":"Software Diversity for Cyber Deception","summary_es":"Registro bibliográfico sobre diversidad de software como señuelo. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on software diversity for deception. The abstract and findings still require review.","organization":"Aliou Badra Sarr, Ahmed H. Anwar","year":2020,"source_url":"https://doi.org/10.1109/globecom42002.2020.9348122","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Moving target defense"],"environments":["Network"],"doi":"10.1109/globecom42002.2020.9348122","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh2-traetox-sshforshits","slug":"gh2-traetox-sshforshits","kind":"software","name":"sshForShits","summary_es":"Repositorio que documenta framework for a high interaction SSH honeypot","summary_en":"framework for a high interaction SSH honeypot","organization":"traetox","year":2020,"source_url":"https://github.com/traetox/sshForShits","evidence":"repository-documentation","reviewed_at":"2026-09-16","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"honeytoken-fingerprinting-2020","slug":"honeytoken-fingerprinting-2020","kind":"paper","name":"Towards Systematic Honeytoken Fingerprinting","summary_es":"Publicación identificada por DOI sobre métodos de identificación de honeytokens; análisis pendiente del texto.","summary_en":"DOI-identified publication on honeytoken fingerprinting methods; text analysis is pending.","organization":"Publication authors","year":2020,"source_url":"https://doi.org/10.1145/3433174.3433599","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Honeytoken"],"environments":["Identity"],"doi":"10.1145/3433174.3433599","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-1109-cogmi48466-2019-00023","slug":"doi-10-1109-cogmi48466-2019-00023","kind":"paper","name":"Creating Cyber Deception Games","summary_es":"Registro bibliográfico sobre juegos de cyberdeception. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on cyber deception games. The abstract and findings still require review.","organization":"Maxine Major, Sunny Fugate","year":2019,"source_url":"https://doi.org/10.1109/cogmi48466.2019.00023","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Adversary engagement"],"environments":["Network"],"doi":"10.1109/cogmi48466.2019.00023","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-d1str0-drupot","slug":"gh-d1str0-drupot","kind":"software","name":"drupot","summary_es":"Repositorio sobre simulación de Drupal; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about Drupal simulation; documentation and maintenance require further review.","organization":"d1str0","year":2019,"source_url":"https://github.com/d1str0/drupot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-1145-3314058-3314067","slug":"doi-10-1145-3314058-3314067","kind":"paper","name":"Game theory for cyber deception","summary_es":"Registro bibliográfico sobre teoría de juegos aplicada a deception. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on game theory applied to deception. The abstract and findings still require review.","organization":"Quanyan Zhu","year":2019,"source_url":"https://doi.org/10.1145/3314058.3314067","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Adversary engagement"],"environments":["Network"],"doi":"10.1145/3314058.3314067","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-joda32-owa-honeypot","slug":"gh-joda32-owa-honeypot","kind":"software","name":"owa-honeypot","summary_es":"Repositorio sobre simulación de Outlook Web Access; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about Outlook Web Access simulation; documentation and maintenance require further review.","organization":"joda32","year":2019,"source_url":"https://github.com/joda32/owa-honeypot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-cymmetria-ciscoasa-honeypot","slug":"gh-cymmetria-ciscoasa-honeypot","kind":"software","name":"ciscoasa_honeypot","summary_es":"Repositorio sobre simulación de Cisco ASA; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about Cisco ASA simulation; documentation and maintenance require further review.","organization":"Cymmetria","year":2018,"source_url":"https://github.com/Cymmetria/ciscoasa_honeypot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-1109-msp-2018-1870866","slug":"doi-10-1109-msp-2018-1870866","kind":"paper","name":"Cyber Deception: Overview and the Road Ahead","summary_es":"Registro bibliográfico sobre panorama y desafíos de cyberdeception. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on cyber deception overview and challenges. The abstract and findings still require review.","organization":"Cliff Wang, Zhuo Lu","year":2018,"source_url":"https://doi.org/10.1109/msp.2018.1870866","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Network"],"doi":"10.1109/msp.2018.1870866","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-owasp-honeypot-project","slug":"gh-owasp-honeypot-project","kind":"software","name":"Honeypot-Project","summary_es":"Repositorio sobre material de honeypots de OWASP; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about OWASP honeypot material; documentation and maintenance require further review.","organization":"OWASP","year":2018,"source_url":"https://github.com/OWASP/Honeypot-Project","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-owasp-python-honeypot","slug":"gh-owasp-python-honeypot","kind":"software","name":"Python-Honeypot","summary_es":"Repositorio sobre framework de deception en Python; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about Python deception framework; documentation and maintenance require further review.","organization":"OWASP","year":2018,"source_url":"https://github.com/OWASP/Python-Honeypot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-1109-dsc-2018-00040","slug":"doi-10-1109-dsc-2018-00040","kind":"paper","name":"RansomTracer: Exploiting Cyber Deception for Ransomware Tracing","summary_es":"Registro bibliográfico sobre trazabilidad de ransomware con deception. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on ransomware tracing through deception. The abstract and findings still require review.","organization":"ZiHan Wang, Xu Wu","year":2018,"source_url":"https://doi.org/10.1109/dsc.2018.00040","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Endpoint"],"doi":"10.1109/dsc.2018.00040","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-1109-vlhcc-2018-8506515","slug":"doi-10-1109-vlhcc-2018-8506515","kind":"paper","name":"Visual Modeling of Cyber Deception","summary_es":"Registro bibliográfico sobre modelado visual de deception. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on visual modeling of deception. The abstract and findings still require review.","organization":"Cristiano De Faveri, Ana Moreira","year":2018,"source_url":"https://doi.org/10.1109/vlhcc.2018.8506515","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Network"],"doi":"10.1109/vlhcc.2018.8506515","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-cymmetria-weblogic-honeypot","slug":"gh-cymmetria-weblogic-honeypot","kind":"software","name":"weblogic_honeypot","summary_es":"Repositorio sobre simulación de Oracle WebLogic; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about Oracle WebLogic simulation; documentation and maintenance require further review.","organization":"Cymmetria","year":2018,"source_url":"https://github.com/Cymmetria/weblogic_honeypot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"game-taxonomy-2017","slug":"game-taxonomy-2017","kind":"paper","name":"A Game-Theoretic Taxonomy and Survey of Defensive Deception for Cybersecurity and Privacy","summary_es":"Taxonomía basada en teoría de juegos que distingue varios tipos de engaño defensivo.","summary_en":"Game-theoretic taxonomy distinguishing several forms of defensive deception.","organization":"Pawlick et al.","year":2017,"source_url":"https://arxiv.org/abs/1712.05441","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Moving target defense","Honeytoken"],"environments":["Network"],"doi":null,"review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Revisión y taxonomía que organiza trabajos mediante juegos entre defensor, atacante y usuarios.","design_en":"Survey and taxonomy organizing work through games among defender, attacker and users.","finding_es":"Relaciona seis clases de engaño con información privada, señales, acciones y utilidades.","finding_en":"Relates six deception classes to private information, signals, actions and utilities.","evidence_limits_es":"Los modelos abstraen conducta, información y racionalidad; su ajuste operativo debe validarse por escenario.","evidence_limits_en":"Models abstract behavior, information and rationality; operational fit requires scenario validation.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"El abstract propone una taxonomía de engaño defensivo basada en teoría de juegos.","critical_observation_en":"The abstract proposes a game-theoretic taxonomy of defensive deception.","limitations_es":"Los supuestos formales pueden no reflejar conocimiento, recursos o decisiones de un atacante real.","limitations_en":"Formal assumptions may not reflect a real attacker’s knowledge, resources or decisions.","question_es":"¿Qué supuestos del modelo cambian la elección del señuelo?","question_en":"Which model assumptions change decoy selection?"},{"id":"doi-10-1109-tifs-2017-2710945","slug":"doi-10-1109-tifs-2017-2710945","kind":"paper","name":"A Probabilistic Logic of Cyber Deception","summary_es":"Registro bibliográfico sobre lógica probabilística de deception. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on probabilistic logic of deception. The abstract and findings still require review.","organization":"Sushil Jajodia, Noseong Park","year":2017,"source_url":"https://doi.org/10.1109/tifs.2017.2710945","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Network"],"doi":"10.1109/tifs.2017.2710945","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-plazmaz-mongodb-honeyproxy","slug":"gh-plazmaz-mongodb-honeyproxy","kind":"software","name":"MongoDB-HoneyProxy","summary_es":"Repositorio sobre proxy señuelo de MongoDB; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about MongoDB decoy proxy; documentation and maintenance require further review.","organization":"Plazmaz","year":2017,"source_url":"https://github.com/Plazmaz/MongoDB-HoneyProxy","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-sjinks-mysql-honeypotd","slug":"gh-sjinks-mysql-honeypotd","kind":"software","name":"mysql-honeypotd","summary_es":"Repositorio sobre simulación de MySQL; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about MySQL simulation; documentation and maintenance require further review.","organization":"sjinks","year":2017,"source_url":"https://github.com/sjinks/mysql-honeypotd","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-betheroot-pghoney","slug":"gh-betheroot-pghoney","kind":"software","name":"pghoney","summary_es":"Repositorio sobre simulación de PostgreSQL; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about PostgreSQL simulation; documentation and maintenance require further review.","organization":"betheroot","year":2017,"source_url":"https://github.com/betheroot/pghoney","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-betheroot-sticky-elephant","slug":"gh-betheroot-sticky-elephant","kind":"software","name":"sticky_elephant","summary_es":"Repositorio sobre simulación interactiva de PostgreSQL; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about interactive PostgreSQL simulation; documentation and maintenance require further review.","organization":"betheroot","year":2017,"source_url":"https://github.com/betheroot/sticky_elephant","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-cymmetria-strutshoneypot","slug":"gh-cymmetria-strutshoneypot","kind":"software","name":"StrutsHoneypot","summary_es":"Repositorio sobre simulación de Apache Struts; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about Apache Struts simulation; documentation and maintenance require further review.","organization":"Cymmetria","year":2017,"source_url":"https://github.com/Cymmetria/StrutsHoneypot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-1109-ccst-2017-8167793","slug":"doi-10-1109-ccst-2017-8167793","kind":"paper","name":"Technologies to enable cyber deception","summary_es":"Registro bibliográfico sobre tecnologías habilitadoras de deception. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on technologies enabling deception. The abstract and findings still require review.","organization":"Vincent E. Urias, William M.S. Stout","year":2017,"source_url":"https://doi.org/10.1109/ccst.2017.8167793","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Network"],"doi":"10.1109/ccst.2017.8167793","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-helospark-tomcat-manager-honeypot","slug":"gh-helospark-tomcat-manager-honeypot","kind":"software","name":"tomcat-manager-honeypot","summary_es":"Repositorio sobre simulación del administrador Tomcat; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about Tomcat manager simulation; documentation and maintenance require further review.","organization":"helospark","year":2017,"source_url":"https://github.com/helospark/tomcat-manager-honeypot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-1109-milcom-2016-7795427","slug":"doi-10-1109-milcom-2016-7795427","kind":"paper","name":"ACyDS: An adaptive cyber deception system","summary_es":"Registro bibliográfico sobre un sistema adaptativo de deception. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on an adaptive deception system. The abstract and findings still require review.","organization":"Cho-Yu J. Chiang, Yitzchak M. Gottlieb","year":2016,"source_url":"https://doi.org/10.1109/milcom.2016.7795427","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Network"],"doi":"10.1109/milcom.2016.7795427","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"doi-10-1109-cloud-2016-0134","slug":"doi-10-1109-cloud-2016-0134","kind":"paper","name":"COR-Honeypot: Copy-On-Risk, Virtual Machine as Honeypot in the Cloud","summary_es":"Registro bibliográfico sobre máquinas virtuales señuelo en cloud. El resumen y los resultados aún requieren lectura.","summary_en":"Bibliographic record on decoy virtual machines in cloud. The abstract and findings still require review.","organization":"Denis Lavrov, Veronique Blanchet","year":2016,"source_url":"https://doi.org/10.1109/cloud.2016.0134","evidence":"publisher-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Cloud"],"doi":"10.1109/cloud.2016.0134","review_basis":"publisher-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-phype-telnet-iot-honeypot","slug":"gh-phype-telnet-iot-honeypot","kind":"software","name":"telnet-iot-honeypot","summary_es":"Repositorio sobre captura de binarios de botnets IoT; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about capture of IoT botnet binaries; documentation and maintenance require further review.","organization":"Phype","year":2016,"source_url":"https://github.com/Phype/telnet-iot-honeypot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["IoT"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-securitytw-delilah","slug":"gh-securitytw-delilah","kind":"software","name":"delilah","summary_es":"Repositorio sobre simulación de Elasticsearch; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about Elasticsearch simulation; documentation and maintenance require further review.","organization":"SecurityTW","year":2015,"source_url":"https://github.com/SecurityTW/delilah","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-jordan-wright-elastichoney","slug":"gh-jordan-wright-elastichoney","kind":"software","name":"elastichoney","summary_es":"Repositorio sobre simulación de Elasticsearch; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about Elasticsearch simulation; documentation and maintenance require further review.","organization":"jordan-wright","year":2015,"source_url":"https://github.com/jordan-wright/elastichoney","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-honeynet-ghost-usb-honeypot","slug":"gh-honeynet-ghost-usb-honeypot","kind":"software","name":"ghost-usb-honeypot","summary_es":"Repositorio sobre captura de malware propagado por USB; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about capture of USB-propagated malware; documentation and maintenance require further review.","organization":"honeynet","year":2015,"source_url":"https://github.com/honeynet/ghost-usb-honeypot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Endpoint"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-torque59-nosqlpot","slug":"gh-torque59-nosqlpot","kind":"software","name":"nosqlpot","summary_es":"Repositorio sobre simulación de servicios NoSQL; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about NoSQL-service simulation; documentation and maintenance require further review.","organization":"torque59","year":2015,"source_url":"https://github.com/torque59/nosqlpot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-mushorg-tanner","slug":"gh-mushorg-tanner","kind":"software","name":"tanner","summary_es":"Repositorio sobre análisis de eventos web de SNARE; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about SNARE web-event analysis; documentation and maintenance require further review.","organization":"mushorg","year":2015,"source_url":"https://github.com/mushorg/tanner","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-mycert-espot","slug":"gh-mycert-espot","kind":"software","name":"ESPot","summary_es":"Repositorio sobre observación de ataques a Elasticsearch; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about observation of Elasticsearch attacks; documentation and maintenance require further review.","organization":"mycert","year":2014,"source_url":"https://github.com/mycert/ESPot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-fygrave-honeyntp","slug":"gh-fygrave-honeyntp","kind":"software","name":"honeyntp","summary_es":"Repositorio sobre servicio señuelo NTP; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about decoy NTP service; documentation and maintenance require further review.","organization":"fygrave","year":2014,"source_url":"https://github.com/fygrave/honeyntp","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-schmalle-nodepot","slug":"gh-schmalle-nodepot","kind":"software","name":"Nodepot","summary_es":"Repositorio sobre simulación de aplicaciones Node.js; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about Node.js application simulation; documentation and maintenance require further review.","organization":"schmalle","year":2014,"source_url":"https://github.com/schmalle/Nodepot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-mushorg-conpot","slug":"gh-mushorg-conpot","kind":"software","name":"conpot","summary_es":"Repositorio sobre simulación de sistemas industriales; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about industrial-system simulation; documentation and maintenance require further review.","organization":"mushorg","year":2013,"source_url":"https://github.com/mushorg/conpot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["OT/ICS"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-mdp-honeypot-go","slug":"gh-mdp-honeypot-go","kind":"software","name":"honeypot.go","summary_es":"Repositorio sobre simulación de SSH en Go; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about SSH simulation in Go; documentation and maintenance require further review.","organization":"mdp","year":2013,"source_url":"https://github.com/mdp/honeypot.go","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"honeywords-2013","slug":"honeywords-2013","kind":"paper","name":"Honeywords: Making Password-Cracking Detectable","summary_es":"Propuesta de contraseñas falsas asociadas a cada cuenta y un honeychecker separado para detectar su uso.","summary_en":"Proposal for false passwords per account and a separate honeychecker that detects their use.","organization":"Juels & Rivest","year":2013,"source_url":"https://people.csail.mit.edu/rivest/pubs/JR13.pdf","evidence":"full-text-review","reviewed_at":"2026-09-16","techniques":["Honeytoken"],"environments":["Identity"],"doi":"10.1145/2508859.2516671","review_basis":"full-text","full_text_reviewed_at":"2026-09-16","design_es":"Diseño de honeywords por cuenta y un honeychecker separado; analiza generación, ataques y operación.","design_en":"Design of per-account honeywords and a separate honeychecker; analyzes generation, attacks and operation.","finding_es":"Convierte el uso de una credencial falsa en una señal de compromiso del archivo de hashes.","finding_en":"Turns use of a false credential into a signal that the password file was compromised.","evidence_limits_es":"La eficacia depende de honeywords indistinguibles, protección del honeychecker y gestión segura de falsas alarmas.","evidence_limits_en":"Effectiveness depends on indistinguishable honeywords, honeychecker protection and safe false-alarm handling.","organization_country":null,"deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-schmalle-mysqlpot","slug":"gh-schmalle-mysqlpot","kind":"software","name":"MysqlPot","summary_es":"Repositorio sobre servicio señuelo MySQL; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about decoy MySQL service; documentation and maintenance require further review.","organization":"schmalle","year":2012,"source_url":"https://github.com/schmalle/MysqlPot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-gfoss-phpmyadmin-honeypot","slug":"gh-gfoss-phpmyadmin-honeypot","kind":"software","name":"phpmyadmin_honeypot","summary_es":"Repositorio sobre simulación de phpMyAdmin; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about phpMyAdmin simulation; documentation and maintenance require further review.","organization":"gfoss","year":2012,"source_url":"https://github.com/gfoss/phpmyadmin_honeypot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"gh-dmpayton-django-admin-honeypot","slug":"gh-dmpayton-django-admin-honeypot","kind":"software","name":"django-admin-honeypot","summary_es":"Repositorio sobre login señuelo de administración Django; documentación y mantenimiento requieren revisión adicional.","summary_en":"Repository about decoy Django admin login; documentation and maintenance require further review.","organization":"dmpayton","year":2011,"source_url":"https://github.com/dmpayton/django-admin-honeypot","evidence":"repository-metadata","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"acalvio-cpg-reference","slug":"acalvio-cpg-reference","kind":"case-study","name":"Acalvio CPG Customer Reference","summary_es":"Relato de selección y piloto de ShadowPlex publicado por Acalvio para una empresa de bienes de consumo.","summary_en":"ShadowPlex selection and pilot story published by Acalvio for a consumer goods company.","organization":"Acalvio","year":null,"source_url":"https://www.acalvio.com/wp-content/uploads/acalvio-customer-reference-cpg.pdf","evidence":"vendor-published-case","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Cloud","Identity"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"acalvio-industrial-reference","slug":"acalvio-industrial-reference","kind":"case-study","name":"Acalvio Industrial Manufacturer Reference","summary_es":"Relato de un fabricante industrial publicado por Acalvio; se registra como experiencia del proveedor.","summary_en":"Industrial manufacturer story published by Acalvio; recorded as a vendor case.","organization":"Acalvio","year":null,"source_url":"https://www.acalvio.com/wp-content/uploads/acalvio-customer-reference-industrial-manufacturer.pdf","evidence":"vendor-published-case","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["OT/ICS"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"adbhoney","slug":"adbhoney","kind":"software","name":"ADBHoney","summary_es":"Honeypot de baja interacción que simula el servicio Android Debug Bridge.","summary_en":"Low-interaction honeypot simulating the Android Debug Bridge service.","organization":"huuck","year":null,"source_url":"https://github.com/huuck/ADBHoney","evidence":"repository-documentation","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["IoT"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"El repositorio describe una simulación de Android Debug Bridge de baja interacción.","critical_observation_en":"The repository describes low-interaction Android Debug Bridge simulation.","limitations_es":"La ficha no establece que reproduzca un dispositivo real ni que cubra ataques IoT distintos de ADB.","limitations_en":"This record does not establish real-device fidelity or coverage of IoT attacks beyond ADB.","question_es":"¿Qué comandos registra y cuáles revelan que el servicio es simulado?","question_en":"Which commands are recorded, and which reveal that the service is simulated?"},{"id":"akamai-guardicore-deception","slug":"akamai-guardicore-deception","kind":"product","name":"Akamai Guardicore Segmentation: Dynamic Deception","summary_es":"Producto principalmente de microsegmentación cuya documentación incluye redirección dinámica hacia un entorno de engaño; se registra esa capacidad relacionada.","summary_en":"Primarily a microsegmentation product whose documentation includes dynamic redirection into a deception environment; this related capability is recorded.","organization":"Akamai","year":null,"source_url":"https://www.akamai.com/products/akamai-guardicore-segmentation","evidence":"vendor-claim","reviewed_at":"2026-09-15","techniques":["Decoy","Moving target defense"],"environments":["Network","OT/ICS"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"Akamai documenta redirección dinámica a un entorno de engaño dentro de su oferta de segmentación.","critical_observation_en":"Akamai documents dynamic redirection to a deception environment within its segmentation offering.","limitations_es":"Es una capacidad relacionada; la ficha no describe un producto de deception autónomo.","limitations_en":"This is a related capability; the record does not describe a standalone deception product.","question_es":"¿Qué reglas de segmentación activan la redirección y qué tráfico se excluye?","question_en":"Which segmentation rules trigger redirection and which traffic is excluded?"},{"id":"awesome-honeypots","slug":"awesome-honeypots","kind":"community","name":"Awesome Honeypots","summary_es":"Lista comunitaria de proyectos y materiales sobre honeypots; cada enlace requiere verificación propia.","summary_en":"Community list of honeypot projects and materials; each link requires separate verification.","organization":"Community contributors","year":null,"source_url":"https://github.com/paralax/awesome-honeypots","evidence":"community-directory","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network","Application"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"canarytokens-open","slug":"canarytokens-open","kind":"software","name":"Canarytokens","summary_es":"Proyecto abierto para generar tokens señuelo que alertan cuando alguien los utiliza.","summary_en":"Open project for creating decoy tokens that alert when someone uses them.","organization":"Thinkst","year":null,"source_url":"https://github.com/thinkst/canarytokens","evidence":"repository-documentation","reviewed_at":"2026-09-15","techniques":["Honeytoken"],"environments":["Identity","Cloud"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"La documentación ofrece mecanismos para crear tokens que alertan ante su uso.","critical_observation_en":"Documentation offers mechanisms for creating tokens that alert when used.","limitations_es":"Una activación puede provenir de pruebas, indexadores o uso accidental; no equivale automáticamente a intrusión.","limitations_en":"A trigger may come from tests, indexers or accidental use; it is not automatically an intrusion.","question_es":"¿Cómo se evita uso legítimo y se contextualiza cada alerta?","question_en":"How is legitimate use excluded and each alert contextualized?"},{"id":"fidelis-childrens-hospital","slug":"fidelis-childrens-hospital","kind":"case-study","name":"Children’s Hospital / Fidelis Deception","summary_es":"Relato de uso de Fidelis Deception en un hospital infantil norteamericano publicado por el proveedor.","summary_en":"Vendor-published story of Fidelis Deception use at a North American children’s hospital.","organization":"Fidelis Security","year":null,"source_url":"https://fidelissecurity.com/resource/case-study/childrens-hospital/","evidence":"vendor-published-case","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Network","Identity"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"Fidelis publica una experiencia de despliegue en un hospital infantil.","critical_observation_en":"Fidelis publishes a deployment story at a children’s hospital.","limitations_es":"No se verificaron aquí resultados independientes ni restricciones clínicas del despliegue.","limitations_en":"Independent outcomes and clinical deployment constraints were not verified here.","question_es":"¿Qué controles aseguran que un señuelo no afecta sistemas asistenciales?","question_en":"Which controls ensure a decoy does not affect clinical systems?"},{"id":"cowrie","slug":"cowrie","kind":"software","name":"Cowrie","summary_es":"Honeypot SSH y Telnet que registra intentos de acceso y sesiones del atacante.","summary_en":"SSH and Telnet honeypot that records login attempts and attacker sessions.","organization":"Cowrie contributors","year":null,"source_url":"https://github.com/cowrie/cowrie","evidence":"repository-documentation","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"El repositorio documenta captura de accesos y sesiones SSH/Telnet.","critical_observation_en":"The repository documents SSH/Telnet login and session capture.","limitations_es":"Los comandos observados en un honeypot no representan por sí solos a todos los atacantes ni prueban eficacia de detección.","limitations_en":"Commands observed in a honeypot do not represent all attackers or prove detection effectiveness.","question_es":"¿Qué porcentaje de las sesiones genera una investigación útil y con qué costo operativo?","question_en":"What share of sessions leads to useful investigation, and at what operational cost?"},{"id":"maple-deception-service","slug":"maple-deception-service","kind":"service","name":"Deception as a Service","summary_es":"Oferta de honeypots operados como servicio publicada por Maple Networks.","summary_en":"Honeypot service offering published by Maple Networks.","organization":"Maple Networks","year":null,"source_url":"https://www.maple-networks.com/security/honeypots/","evidence":"provider-offering","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"daleo-deception-service","slug":"daleo-deception-service","kind":"service","name":"Deception as a Service","summary_es":"Oferta gestionada que DALEO publica junto a la plataforma de CounterCraft.","summary_en":"Managed offering DALEO publishes in conjunction with the CounterCraft platform.","organization":"DALEO Synergy","year":null,"source_url":"https://www.daleosynergy.eu/products","evidence":"provider-offering","reviewed_at":"2026-09-15","techniques":["Decoy","Adversary engagement"],"environments":["Network"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"ecca-deception-as-a-service","slug":"ecca-deception-as-a-service","kind":"service","name":"Deception as a Service","summary_es":"Oferta de ECCA en Egipto y GCC que enumera integración, servicios independientes, formación y gestión de deception.","summary_en":"ECCA offering in Egypt and GCC listing integration, independent services, training and managed deception.","organization":"ECCA Group","year":null,"source_url":"https://ecca-group.com/deception-as-a-service/","evidence":"provider-offering","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Network","Identity"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":"Egypt","deployment_regions":["Egypt","Africa","GCC"],"sectors":null,"source_language":"en","critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"ECCA enumera integración, formación y operación gestionada para clientes en Egipto y GCC.","critical_observation_en":"ECCA lists integration, training and managed operation for customers in Egypt and GCC.","limitations_es":"La página de oferta no publica métricas de resultados ni acuerdos operativos completos.","limitations_en":"The offering page does not publish outcome metrics or full operating agreements.","question_es":"¿Quién mantiene los señuelos y responde a las alertas en cada modalidad?","question_en":"Who maintains decoys and responds to alerts in each delivery mode?"},{"id":"acsg-deception-as-a-service","slug":"acsg-deception-as-a-service","kind":"service","name":"Deception as a Service","summary_es":"ACSG publica una oferta gestionada de señuelos y monitoreo continuo para IT, cloud e ICS.","summary_en":"ACSG publishes a managed decoy and continuous-monitoring offering for IT, cloud and ICS.","organization":"Advanced Computer Solutions Group","year":null,"source_url":"https://www.advancedcsg.net/deception-as-a-service/","evidence":"provider-offering","reviewed_at":"2026-09-15","techniques":["Decoy","Honeytoken"],"environments":["Network","Cloud","OT/ICS"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":"United States","deployment_regions":null,"sectors":null,"source_language":"en","critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"ACSG publica monitoreo gestionado con señuelos para IT, cloud e ICS.","critical_observation_en":"ACSG publishes managed monitoring with decoys for IT, cloud and ICS.","limitations_es":"La página no demuestra despliegues seguros en sistemas industriales concretos.","limitations_en":"The page does not establish safe deployment in a specific industrial system.","question_es":"¿Cómo se separan los señuelos de los procesos industriales reales?","question_en":"How are decoys separated from real industrial processes?"},{"id":"deception-pro-platform","slug":"deception-pro-platform","kind":"product","name":"Deception.Pro","summary_es":"Entornos persistentes e instrumentados para detonar malware y observar acciones de adversarios, según la descripción de la plataforma.","summary_en":"Persistent instrumented environments for malware detonation and adversary observation, according to the platform description.","organization":"Deception.Pro","year":null,"source_url":"https://deception.pro/","evidence":"vendor-claim","reviewed_at":"2026-09-15","techniques":["Decoy","Adversary engagement"],"environments":["Network","Endpoint"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"La plataforma anuncia entornos instrumentados para observar acciones posteriores a la intrusión.","critical_observation_en":"The platform advertises instrumented environments for observing post-compromise actions.","limitations_es":"La descripción no establece qué conductas se observarían fuera de esos escenarios preparados.","limitations_en":"The description does not establish what would be observed outside prepared scenarios.","question_es":"¿Qué límites de aislamiento y retención se aplican al entorno?","question_en":"What isolation and retention limits apply to the environment?"},{"id":"maindefense-deepsea","slug":"maindefense-deepsea","kind":"service","name":"DeepSea Managed OT Deception","summary_es":"Servicio gestionado de deception para IT y OT publicado por MainDefense.","summary_en":"Managed IT and OT deception service published by MainDefense.","organization":"MainDefense","year":null,"source_url":"https://maindefense.de/","evidence":"provider-offering","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["OT/ICS","Network"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"dionaea","slug":"dionaea","kind":"software","name":"Dionaea","summary_es":"Proyecto de honeypot para observar intentos de explotación de servicios de red.","summary_en":"Honeypot project for observing attacks against network services.","organization":"DinoTools","year":null,"source_url":"https://github.com/DinoTools/dionaea","evidence":"repository-documentation","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"El repositorio describe observación de intentos contra servicios de red simulados.","critical_observation_en":"The repository describes observation of attempts against simulated network services.","limitations_es":"No hay en esta ficha una prueba comparable de cobertura de protocolos o de carga de operación.","limitations_en":"This record has no comparable protocol coverage or operating-load test.","question_es":"¿Qué protocolos relevantes para la organización cubre la configuración actual?","question_en":"Which protocols relevant to the organization does the current setup cover?"},{"id":"proofpoint-energy-shadow","slug":"proofpoint-energy-shadow","kind":"case-study","name":"Energy Company / Proofpoint Shadow","summary_es":"Relato de adopción de Shadow en una empresa energética publicado por Proofpoint; la reducción de tiempo de investigación es una afirmación del cliente recogida por el proveedor.","summary_en":"Energy company Shadow adoption story published by Proofpoint; investigation-time reduction is a customer statement reported by the vendor.","organization":"Proofpoint","year":null,"source_url":"https://www.proofpoint.com/us/customer-stories/energy-company-powers-defenses-proofpoint","evidence":"vendor-published-case","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Endpoint","Identity"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"Proofpoint publica un relato de adopción en una empresa de energía.","critical_observation_en":"Proofpoint publishes an energy-company adoption story.","limitations_es":"No se verificó una evaluación independiente de resultados.","limitations_en":"No independent outcome evaluation was reviewed.","question_es":"¿Qué medición previa y posterior sustenta la reducción declarada?","question_en":"What before-and-after measurement supports the reported reduction?"},{"id":"fidelis-deception","slug":"fidelis-deception","kind":"product","name":"Fidelis Deception","summary_es":"Plataforma comercial de señuelos y breadcrumbs para redes, identidad y cloud, según la oferta de Fidelis.","summary_en":"Commercial decoy and breadcrumb platform for network, identity and cloud, according to Fidelis.","organization":"Fidelis Security","year":null,"source_url":"https://fidelissecurity.com/solutions/deception/","evidence":"vendor-claim","reviewed_at":"2026-09-15","techniques":["Decoy","Honeytoken"],"environments":["Network","Identity","Cloud"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"Fidelis publica una oferta de señuelos y breadcrumbs en varios entornos.","critical_observation_en":"Fidelis publishes a decoy and breadcrumb offering across environments.","limitations_es":"Esta ficha no comprueba integraciones, permisos ni resultados de detección.","limitations_en":"This record does not verify integrations, permissions or detection outcomes.","question_es":"¿Qué integración lleva la interacción con el señuelo al flujo del SOC?","question_en":"Which integration carries decoy interactions into the SOC workflow?"},{"id":"fortideceptor","slug":"fortideceptor","kind":"product","name":"FortiDeceptor","summary_es":"Plataforma de Fortinet para desplegar activos señuelo y alertar sobre su uso.","summary_en":"Fortinet platform for deploying decoy assets and alerting on their use.","organization":"Fortinet","year":null,"source_url":"https://www.fortinet.com/products/fortideceptor","evidence":"vendor-claim","reviewed_at":"2026-09-15","techniques":["Decoy","Honeypot"],"environments":["Network","OT/ICS"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"La página comercial declara señuelos para red y entornos industriales.","critical_observation_en":"The commercial page claims decoys for network and industrial environments.","limitations_es":"La presencia de una categoría OT/ICS no demuestra aislamiento seguro en una planta concreta.","limitations_en":"An OT/ICS category does not prove safe isolation in a specific plant.","question_es":"¿Cómo se valida seguridad de proceso antes de colocar señuelos industriales?","question_en":"How is process safety validated before placing industrial decoys?"},{"id":"galah","slug":"galah","kind":"software","name":"Galah","summary_es":"Honeypot web que utiliza un modelo de lenguaje para generar interacciones.","summary_en":"Web honeypot using a language model to generate interactions.","organization":"0x4D31","year":null,"source_url":"https://github.com/0x4D31/galah","evidence":"repository-documentation","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"La documentación presenta un honeypot web con respuestas generadas mediante un modelo de lenguaje.","critical_observation_en":"Documentation presents a web honeypot with language-model-generated responses.","limitations_es":"La plausibilidad y el costo de inferencia no se evaluaron de forma independiente en esta ficha.","limitations_en":"Response plausibility and inference cost were not independently evaluated in this record.","question_es":"¿Cuándo detecta el adversario respuestas inconsistentes o fuera de contexto?","question_en":"When does an adversary detect inconsistent or out-of-context responses?"},{"id":"glastopf","slug":"glastopf","kind":"software","name":"Glastopf","summary_es":"Honeypot para aplicaciones web que registra interacciones con superficies simuladas.","summary_en":"Web application honeypot recording interactions with simulated attack surfaces.","organization":"mushorg","year":null,"source_url":"https://github.com/mushorg/glastopf","evidence":"repository-documentation","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"La documentación ubica el proyecto en el engaño de aplicaciones web.","critical_observation_en":"Documentation places the project in web-application deception.","limitations_es":"Un proyecto de honeypot web puede necesitar adaptación para parecerse a aplicaciones modernas; aquí no se verificó ese ajuste.","limitations_en":"A web honeypot may need adaptation to resemble modern applications; that fit was not tested here.","question_es":"¿Qué señales distinguen tráfico automatizado masivo de interacción investigable?","question_en":"What signals distinguish bulk automated traffic from investigable interaction?"},{"id":"countercraft-global-bank-api","slug":"countercraft-global-bank-api","kind":"case-study","name":"Global Bank API Digital Twin","summary_es":"CounterCraft describe un gemelo digital de API bancaria que atrajo un ataque en menos de 30 días; resultado atribuido al proveedor.","summary_en":"CounterCraft describes a bank API digital twin that attracted an attack within 30 days; outcome attributed to the vendor.","organization":"CounterCraft","year":null,"source_url":"https://www.countercraftsec.com/blog/external-attack-surface-management-with-digital-twins-a-case-study/","evidence":"vendor-published-case","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Application","Cloud"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"CounterCraft informa una interacción en un gemelo digital de API bancaria en menos de 30 días.","critical_observation_en":"CounterCraft reports an interaction with a bank API digital twin within 30 days.","limitations_es":"El período hasta la primera interacción no representa por sí mismo eficacia de detección.","limitations_en":"Time to first interaction alone does not represent detection effectiveness.","question_es":"¿Qué acciones distinguieron la interacción investigable de un escaneo?","question_en":"Which actions distinguished an actionable interaction from a scan?"},{"id":"sprintit-honeypot-service","slug":"sprintit-honeypot-service","kind":"service","name":"Honeypot as a Service","summary_es":"Oferta SaaS de honeypots y señales de engaño publicada por Sprint IT Solutions; condiciones operativas pendientes de evaluación.","summary_en":"SaaS honeypot and deception-signal offering published by Sprint IT Solutions; operational terms await assessment.","organization":"Sprint IT Solutions","year":null,"source_url":"https://www.sitwll.com/honeypot","evidence":"provider-offering","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"Sprint IT Solutions anuncia honeypots ofrecidos como servicio.","critical_observation_en":"Sprint IT Solutions advertises honeypots as a service.","limitations_es":"Los términos de acceso, retención e integración siguen sin verificarse aquí.","limitations_en":"Access, retention and integration terms remain unverified here.","question_es":"¿Dónde residen los datos observados y quién puede consultarlos?","question_en":"Where does observed data reside and who can access it?"},{"id":"honeytrap","slug":"honeytrap","kind":"software","name":"Honeytrap","summary_es":"Framework abierto para crear y operar sensores honeypot.","summary_en":"Open framework for building and operating honeypot sensors.","organization":"Honeytrap contributors","year":null,"source_url":"https://github.com/honeytrap/honeytrap","evidence":"repository-documentation","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"El repositorio describe un framework para construir sensores honeypot.","critical_observation_en":"The repository describes a framework for building honeypot sensors.","limitations_es":"Un framework exige diseño, operación y pruebas adicionales; no aporta por sí mismo una detección medida.","limitations_en":"A framework requires design, operation and further testing; it does not itself provide measured detection.","question_es":"¿Qué módulos y protocolos están mantenidos y cuáles requieren desarrollo propio?","question_en":"Which modules and protocols are maintained, and which require custom work?"},{"id":"rapid7-insightidr-deception","slug":"rapid7-insightidr-deception","kind":"product","name":"InsightIDR Deception Technology","summary_es":"Capacidades de InsightIDR para crear honeypots, usuarios, archivos y credenciales señuelo; la documentación describe alertas ante interacción.","summary_en":"InsightIDR capabilities for honeypots, honey users, files and credentials; documentation describes interaction alerts.","organization":"Rapid7","year":null,"source_url":"https://docs.rapid7.com/insightidr/deception-technology/","evidence":"product-documentation","reviewed_at":"2026-09-15","techniques":["Honeypot","Honeytoken"],"environments":["Network","Identity"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"La documentación enumera honeypots, usuarios, archivos y credenciales señuelo.","critical_observation_en":"Documentation lists honeypots, honey users, files and credentials.","limitations_es":"La variedad de señuelos documentada no demuestra que todos sean útiles en cada instalación.","limitations_en":"The documented variety does not establish that every decoy is useful in every deployment.","question_es":"¿Qué señuelo genera la señal más investigable en la red propia?","question_en":"Which decoy yields the most actionable signal in the local network?"},{"id":"quirso-managed-response","slug":"quirso-managed-response","kind":"service","name":"Managed Deception and Response","summary_es":"Servicio de señuelos y respuesta publicado por QUIRSO para organizaciones en Alemania.","summary_en":"Decoy and response service published by QUIRSO for organizations in Germany.","organization":"QUIRSO","year":null,"source_url":"https://www.quirso.de/index-en.html","evidence":"provider-offering","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Network"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"cyber-fidelity-managed-deception","slug":"cyber-fidelity-managed-deception","kind":"service","name":"Managed Deception Service","summary_es":"Oferta gestionada de honeypots y señuelos publicada por Cyber Fidelity.","summary_en":"Managed honeypot and decoy offering published by Cyber Fidelity.","organization":"Cyber Fidelity","year":null,"source_url":"https://www.cyberfidelity.co/","evidence":"provider-offering","reviewed_at":"2026-09-15","techniques":["Honeypot","Decoy"],"environments":["Network"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"lastnode-managed-deception","slug":"lastnode-managed-deception","kind":"service","name":"Managed Deception Service","summary_es":"Servicio de deception operado por LastNode, según su página de oferta.","summary_en":"Deception operated by LastNode, according to its service page.","organization":"LastNode","year":null,"source_url":"https://lastnode.com/deception","evidence":"provider-offering","reviewed_at":"2026-09-15","techniques":["Honeypot","Decoy"],"environments":["Network"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"wipro-managed-deception","slug":"wipro-managed-deception","kind":"service","name":"Managed Deception Services","summary_es":"Servicio gestionado de deception que Wipro describe en colaboración con Acalvio.","summary_en":"Managed deception offering that Wipro describes in partnership with Acalvio.","organization":"Wipro","year":null,"source_url":"https://www.wipro.com/cybersecurity/managed-deception-services/","evidence":"provider-offering","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Network","Identity"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":false,"critical_reviewed_at":null,"critical_observation_es":null,"critical_observation_en":null,"limitations_es":null,"limitations_en":null,"question_es":null,"question_en":null},{"id":"acalvio-managed-targeted-intel","slug":"acalvio-managed-targeted-intel","kind":"service","name":"Managed Targeted Threat Intel","summary_es":"Ficha de Acalvio que describe alojar y gestionar señuelos externos en su cloud para compartir inteligencia mediante STIX.","summary_en":"Acalvio datasheet describing cloud-hosted and managed external decoys with STIX intelligence sharing.","organization":"Acalvio","year":null,"source_url":"https://www.acalvio.com/wp-content/uploads/acalvio-shadowplex-threat-intel-datasheet.pdf","evidence":"provider-datasheet","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Cloud"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"La ficha de producto describe señuelos externos alojados por el proveedor e intercambio STIX.","critical_observation_en":"The datasheet describes provider-hosted external decoys and STIX sharing.","limitations_es":"La existencia de un formato de intercambio no garantiza calidad o utilidad de la inteligencia.","limitations_en":"An exchange format does not guarantee intelligence quality or usefulness.","question_es":"¿Qué objetos STIX se entregan y con qué contexto de captura?","question_en":"Which STIX objects are delivered and with what capture context?"},{"id":"microsoft-defender-identity-honeytoken","slug":"microsoft-defender-identity-honeytoken","kind":"product","name":"Microsoft Defender for Identity Honeytoken Tags","summary_es":"Función documentada para etiquetar cuentas y dispositivos honeytoken; la actividad de acceso genera alertas en Defender for Identity.","summary_en":"Documented feature tagging honeytoken accounts and devices; sign-ins generate Defender for Identity alerts.","organization":"Microsoft","year":null,"source_url":"https://learn.microsoft.com/en-us/defender-for-identity/entity-tags","evidence":"product-documentation","reviewed_at":"2026-09-15","techniques":["Honeytoken"],"environments":["Identity"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"Microsoft documenta etiquetas honeytoken para cuentas y dispositivos.","critical_observation_en":"Microsoft documents honeytoken tags for accounts and devices.","limitations_es":"Una etiqueta exige gobernanza de cuentas; la documentación no mide eficacia en este sitio.","limitations_en":"A tag requires account governance; this site does not measure effectiveness.","question_es":"¿Qué actividad legítima puede tocar la cuenta y generar ruido?","question_en":"Which legitimate activity can touch the account and create noise?"},{"id":"mitre-d3fend","slug":"mitre-d3fend","kind":"framework","name":"MITRE D3FEND","summary_es":"Base de conocimiento de técnicas defensivas que ofrece vocabulario relacionado con señuelos.","summary_en":"Knowledge base of defensive techniques with terminology related to decoys.","organization":"MITRE","year":null,"source_url":"https://d3fend.mitre.org/","evidence":"framework-documentation","reviewed_at":"2026-09-15","techniques":["Decoy"],"environments":["Network"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"La base de conocimiento MITRE ofrece vocabulario para técnicas defensivas y señuelos.","critical_observation_en":"The MITRE knowledge base offers vocabulary for defensive techniques and decoys.","limitations_es":"La correspondencia taxonómica no implica que una implementación concreta funcione.","limitations_en":"A taxonomy mapping does not imply a specific implementation works.","question_es":"¿Qué técnica D3FEND describe mejor el comportamiento, no solo el nombre comercial?","question_en":"Which D3FEND technique best describes the behavior, beyond the commercial name?"},{"id":"mitre-engage","slug":"mitre-engage","kind":"framework","name":"MITRE Engage","summary_es":"Framework para planificar y comunicar actividades de denial, deception y adversary engagement.","summary_en":"Framework for planning and communicating denial, deception and adversary engagement.","organization":"MITRE","year":null,"source_url":"https://github.com/mitre/engage","evidence":"framework-documentation","reviewed_at":"2026-09-15","techniques":["Adversary engagement"],"environments":["Network","Cloud"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"La documentación de MITRE propone un proceso para planificar, operar y entender engagement.","critical_observation_en":"MITRE documentation proposes a process to prepare, operate and understand engagement.","limitations_es":"Es un marco de planificación, no una certificación de eficacia de productos o campañas.","limitations_en":"It is a planning framework, not a certification of product or campaign effectiveness.","question_es":"¿Qué hipótesis y límites de operación se documentan antes del despliegue?","question_en":"Which hypotheses and operating limits are documented before deployment?"},{"id":"opencanary","slug":"opencanary","kind":"software","name":"OpenCanary","summary_es":"Honeypot de red multiprotocolo para detectar interacciones sospechosas en redes internas.","summary_en":"Multi-protocol network honeypot for detecting suspicious interactions inside networks.","organization":"Thinkst","year":null,"source_url":"https://github.com/thinkst/opencanary","evidence":"repository-documentation","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"La documentación del repositorio describe un sensor multiprotocolo para redes internas.","critical_observation_en":"Repository documentation describes a multiprotocol sensor for internal networks.","limitations_es":"La ficha no mide tasas de alerta, falsos positivos ni esfuerzo de mantenimiento en una red real.","limitations_en":"This record does not measure alert rates, false positives or maintenance in a real network.","question_es":"¿Qué servicios simulados siguen siendo creíbles en el entorno que se quiere proteger?","question_en":"Which simulated services remain credible in the target environment?"},{"id":"proofpoint-shadow","slug":"proofpoint-shadow","kind":"product","name":"Proofpoint Shadow","summary_es":"Componente comercial de protección de identidad que distribuye señuelos en endpoints para alertar sobre movimiento lateral, según Proofpoint.","summary_en":"Commercial identity protection component deploying endpoint deceptions to alert on lateral movement, according to Proofpoint.","organization":"Proofpoint","year":null,"source_url":"https://www.proofpoint.com/us/products/identity-threat-detection-response/shadow","evidence":"vendor-claim","reviewed_at":"2026-09-15","techniques":["Decoy","Honeytoken"],"environments":["Endpoint","Identity"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"Proofpoint describe señuelos en endpoints para detectar movimiento lateral.","critical_observation_en":"Proofpoint describes endpoint decoys for lateral-movement detection.","limitations_es":"La fuente comercial no cuantifica cobertura ni falsas alertas en una organización comparable.","limitations_en":"The commercial source does not quantify coverage or false alerts in a comparable organization.","question_es":"¿Cómo se relaciona cada alerta con una identidad y un endpoint reales?","question_en":"How is each alert linked to a real identity and endpoint?"},{"id":"riot-games-tracebit","slug":"riot-games-tracebit","kind":"case-study","name":"Riot Games / Tracebit","summary_es":"Experiencia de adopción de deception en cloud publicada por el proveedor Tracebit.","summary_en":"Cloud deception adoption story published by the vendor Tracebit.","organization":"Tracebit","year":null,"source_url":"https://tracebit.com/customer/riot-games","evidence":"published-case","reviewed_at":"2026-09-15","techniques":["Honeytoken"],"environments":["Cloud"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"El proveedor publica una experiencia de adopción cloud atribuida a Riot Games.","critical_observation_en":"The vendor publishes a cloud adoption story attributed to Riot Games.","limitations_es":"El relato está publicado por el proveedor. Sus afirmaciones deben leerse en ese contexto.","limitations_en":"The story is published by the vendor. Its claims should be read in that context.","question_es":"¿Qué resultados medibles y costos de operación se pueden verificar fuera del relato?","question_en":"Which measurable results and operating costs can be verified beyond the story?"},{"id":"shadowplex","slug":"shadowplex","kind":"product","name":"ShadowPlex","summary_es":"Familia comercial de deception para identidad, cloud y redes, según la documentación de Acalvio.","summary_en":"Commercial deception portfolio for identity, cloud and networks, according to Acalvio documentation.","organization":"Acalvio","year":null,"source_url":"https://www.acalvio.com/products/","evidence":"vendor-claim","reviewed_at":"2026-09-15","techniques":["Decoy","Honeytoken"],"environments":["Identity","Cloud","Network"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"El portafolio comercial atribuye cobertura de identidad, cloud y redes a ShadowPlex.","critical_observation_en":"The commercial portfolio attributes identity, cloud and network coverage to ShadowPlex.","limitations_es":"La página de portafolio no ofrece una prueba independiente ni requisitos de cada módulo.","limitations_en":"The portfolio page provides neither an independent test nor requirements for each module.","question_es":"¿Qué integraciones y límites corresponden a la modalidad concreta que se compra?","question_en":"Which integrations and constraints apply to the specific offering being purchased?"},{"id":"acalvio-targeted-threat-intel","slug":"acalvio-targeted-threat-intel","kind":"product","name":"ShadowPlex Targeted Threat Intel","summary_es":"Oferta de inteligencia de amenazas basada en señuelos externos; Acalvio describe modalidades gestionada y como appliance.","summary_en":"Decoy-based targeted threat intelligence offering; Acalvio describes managed and appliance delivery.","organization":"Acalvio","year":null,"source_url":"https://www.acalvio.com/products/shadowplex-targeted-threat-intel/","evidence":"vendor-claim","reviewed_at":"2026-09-15","techniques":["Decoy","Honeytoken"],"environments":["Cloud","Network"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"Acalvio presenta señuelos externos con modalidades gestionada y appliance.","critical_observation_en":"Acalvio presents external decoys with managed and appliance options.","limitations_es":"El material comercial no permite estimar atribución ni calidad de inteligencia.","limitations_en":"Commercial material does not allow attribution or intelligence quality to be estimated.","question_es":"¿Qué artefactos observados pasan a decisiones defensivas comprobables?","question_en":"Which observed artifacts lead to verifiable defensive decisions?"},{"id":"snare","slug":"snare","kind":"software","name":"SNARE","summary_es":"Componente de honeypot web reactivo desarrollado por el equipo de mushorg.","summary_en":"Reactive web honeypot component developed by the mushorg team.","organization":"mushorg","year":null,"source_url":"https://github.com/mushorg/snare","evidence":"repository-documentation","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Application"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"El repositorio documenta un componente web reactivo del ecosistema mushorg.","critical_observation_en":"The repository documents a reactive web component from the mushorg ecosystem.","limitations_es":"La ficha no verifica compatibilidad actual, seguridad de despliegue ni resultados en producción.","limitations_en":"This record does not verify current compatibility, deployment safety or production results.","question_es":"¿Con qué componente de análisis se integra y qué datos conserva?","question_en":"Which analysis component does it integrate with, and what data is retained?"},{"id":"t-pot","slug":"t-pot","kind":"software","name":"T-Pot","summary_es":"Plataforma que reúne varios honeypots y herramientas de análisis en una instalación.","summary_en":"Platform combining multiple honeypots and analysis tools in one deployment.","organization":"Telekom Security","year":null,"source_url":"https://github.com/telekom-security/tpotce","evidence":"repository-documentation","reviewed_at":"2026-09-15","techniques":["Honeypot"],"environments":["Network","IoT"],"doi":null,"review_basis":"repository-metadata","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"La documentación presenta una instalación que reúne varios sensores y herramientas de análisis.","critical_observation_en":"Documentation presents a deployment combining several sensors and analysis tools.","limitations_es":"Integrar sensores no garantiza que todos estén bien ubicados, aislados o mantenidos.","limitations_en":"Combining sensors does not guarantee sound placement, isolation or maintenance.","question_es":"¿Qué sensores aportan señales únicas frente a una instalación más pequeña?","question_en":"Which sensors add unique signals compared with a smaller deployment?"},{"id":"countercraft-platform","slug":"countercraft-platform","kind":"product","name":"The Platform","summary_es":"Plataforma comercial que utiliza señuelos para detección e inteligencia de amenazas, según CounterCraft.","summary_en":"Commercial platform using decoys for detection and threat intelligence, according to CounterCraft.","organization":"CounterCraft","year":null,"source_url":"https://www.countercraftsec.com/products/","evidence":"vendor-claim","reviewed_at":"2026-09-15","techniques":["Decoy","Adversary engagement"],"environments":["Network","Cloud"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"El proveedor presenta señuelos orientados a detección e inteligencia de amenazas.","critical_observation_en":"The vendor presents decoys aimed at detection and threat intelligence.","limitations_es":"Una promesa de inteligencia requiere verificar qué observación es accionable y cómo se atribuye.","limitations_en":"An intelligence claim requires checking which observations are actionable and how they are attributed.","question_es":"¿Qué decisión defensiva cambia a partir de las observaciones del señuelo?","question_en":"Which defensive decision changes because of decoy observations?"},{"id":"thinkst-canary","slug":"thinkst-canary","kind":"product","name":"Thinkst Canary","summary_es":"Producto comercial de señuelos para detectar interacciones con sistemas que aparentan ser legítimos.","summary_en":"Commercial decoy product for detecting interactions with systems that appear legitimate.","organization":"Thinkst","year":null,"source_url":"https://canary.tools/","evidence":"vendor-claim","reviewed_at":"2026-09-15","techniques":["Honeypot","Honeytoken"],"environments":["Network","Identity"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"La página del proveedor presenta señuelos y tokens para generar alertas de interacción.","critical_observation_en":"The vendor page presents decoys and tokens that generate interaction alerts.","limitations_es":"La ficha registra capacidades declaradas; no prueba eficacia, tasa de ruido ni costo total.","limitations_en":"This record captures declared capabilities; it does not test effectiveness, noise rate or total cost.","question_es":"¿Qué alertas aporta frente a controles de detección ya existentes?","question_en":"Which alerts does it add beyond existing detection controls?"},{"id":"tracebit-platform","slug":"tracebit-platform","kind":"product","name":"Tracebit","summary_es":"Plataforma comercial de deception con casos publicados para entornos cloud.","summary_en":"Commercial deception platform with published cloud case studies.","organization":"Tracebit","year":null,"source_url":"https://tracebit.com/","evidence":"vendor-claim","reviewed_at":"2026-09-15","techniques":["Honeytoken","Decoy"],"environments":["Cloud"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"La documentación comercial presenta una plataforma de deception para cloud.","critical_observation_en":"Commercial documentation presents a cloud deception platform.","limitations_es":"Los relatos de clientes publicados por el proveedor requieren atribución y no son benchmarks independientes.","limitations_en":"Vendor-published customer stories need attribution and are not independent benchmarks.","question_es":"¿Qué permisos requiere cada señuelo y cómo se limita su exposición?","question_en":"What permissions does each decoy need, and how is its exposure limited?"},{"id":"zscaler-deception","slug":"zscaler-deception","kind":"product","name":"Zscaler Deception","summary_es":"Producto de Zscaler que distribuye señuelos y alertas por interacción, según su página comercial.","summary_en":"Zscaler product distributing decoys and interaction alerts, according to its product page.","organization":"Zscaler","year":null,"source_url":"https://www.zscaler.com/products-and-solutions/deception-technology","evidence":"vendor-claim","reviewed_at":"2026-09-15","techniques":["Decoy","Honeytoken"],"environments":["Network","Identity"],"doi":null,"review_basis":"source-page","full_text_reviewed_at":null,"design_es":null,"design_en":null,"finding_es":null,"finding_en":null,"evidence_limits_es":null,"evidence_limits_en":null,"organization_country":null,"deployment_regions":null,"sectors":null,"source_language":null,"critical_reading":true,"critical_reviewed_at":"2026-09-15","critical_observation_es":"La página del proveedor describe distribución de señuelos y alertas por interacción.","critical_observation_en":"The vendor page describes decoy distribution and interaction alerts.","limitations_es":"No se verificaron aquí cobertura efectiva, integración ni falsos positivos en una implantación real.","limitations_en":"Effective coverage, integration and false positives were not verified in a real deployment here.","question_es":"¿Qué evento desencadena una alerta y con qué contexto llega al analista?","question_en":"What event triggers an alert, and what context reaches the analyst?"}]}