Deception
SSH & Telnet Honeypot
Expose believable services that capture brute force attempts, shell activity, uploaded files, and attacker tooling without touching production systems.
Capabilities
GCSA HoneyTrace combines SSH and Telnet emulation, session replay, payload capture, indicator extraction, LLM-assisted triage, and SIEM routing in one maintainable deployment surface.
Core modules
Deception
Expose believable services that capture brute force attempts, shell activity, uploaded files, and attacker tooling without touching production systems.
Forensics
Preserve commands, keystrokes, filesystem activity, timing, and replayable terminal sessions for investigation and response workflows.
Collection
Collect samples and URLs delivered by intruders, enrich them with context, and route artifacts into your analysis pipeline.
Operations
Forward normalized events to Splunk, Elastic, Sentinel, syslog, webhooks, or data lakes for alerting and threat intelligence correlation.
Federation
Deploy nodes across exposed surfaces and compare attacker behavior across regions, sectors, and infrastructure tiers.
Detection
Convert low-noise adversary interaction into timely indicators for credential attacks, botnet campaigns, and post-exploitation behavior.
AI Analysis
Package sessions, commands, samples, IOCs, and context into LLM-readable summaries so the SOC can judge intent, priority, and response options faster.
Pipeline
Place GCSA honeypot nodes in DMZ, cloud, branch, or lab networks where scanning and credential attacks naturally arrive.
Record authentication attempts, interactive shells, downloads, uploaded payloads, and command sequences with full session context.
Transform raw interaction into indicators, replay artifacts, and structured events for SOC tooling and alliance intelligence sharing.