Detection and monitoring EU-developed

T-Pot

Combines multiple honeypots and a local analysis stack to collect, search and visualize attempted attacks against decoy network services.

By Deutsche Telekom Security · Germany

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Detection and monitoring
Developer or maintainer
Deutsche Telekom Security
Recorded country
Germany
Product model
Open source
Deployment
Self-hosted
Software license
Mixed: GPL-3.0 for T-Pot code; integrated components retain separate licenses
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

The upstream project is maintained by Deutsche Telekom Security GmbH, whose official GitHub organization identifies Bonn, Germany as its location.

Reported capabilities

  • Multiple integrated honeypots
  • Attack event search and visualization
  • Standalone or distributed deployment

Scope and limits

T-Pot packages third-party honeypots and an Elastic-based analysis stack under their own licenses, so the project GPL does not apply to every component. Honeypots are decoys and require deliberate network isolation and deployment planning.

Inspect the research evidence 5 source observations
  1. identity / capabilities / deployment

    README calls T-Pot an all-in-one multi-honeypot platform with more than 20 decoys and attack visualization; installation documents self-hosted standalone and distributed setups.

    Read source
  2. origin / country

    Official upstream organization identifies Deutsche Telekom Security GmbH and its Bonn, Germany location; this establishes the project organization's country, not every contributor's location.

    Read source
  3. license

    Root LICENSE contains GNU GPL version 3 text.

    Read source
  4. license

    README licenses section names different terms for bundled components, including Elastic-licensed software.

    Read source
  5. maintenance

    Upstream default-branch Atom feed records a commit on 2026-10-06; branch activity is not a support guarantee.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

Elastic Integration

Bundles an Elastic Stack pipeline for collecting and visualizing honeypot events. This documents the supplied T-Pot stack; compatibility with an independently managed Elastic deployment is not established here.

Suricata Integration

Provides a Suricata container alongside honeypots for network security monitoring. Availability depends on the selected deployment configuration.

Put the tool in context.

Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.

From Sigma rule to a tested detection