Capabilities

Deception telemetry designed for security operations.

GCSA HoneyTrace combines SSH and Telnet emulation, session replay, payload capture, indicator extraction, LLM-assisted triage, and SIEM routing in one maintainable deployment surface.

GCSA HoneyTrace telemetry flowA network diagram showing attacker traffic flowing into a HoneyTrace node, then into analysis, malware collection, SIEM output, and alliance intelligence.scanbruteGCSAhoneypotsessionsreplaymalwaresamplesSIEMeventsioc feedpayload capturealert lane: active

Core modules

Everything the SOC expects from a honeypot layer

Deception

SSH & Telnet Honeypot

Expose believable services that capture brute force attempts, shell activity, uploaded files, and attacker tooling without touching production systems.

Forensics

Session Recording

Preserve commands, keystrokes, filesystem activity, timing, and replayable terminal sessions for investigation and response workflows.

Collection

Malware Capture

Collect samples and URLs delivered by intruders, enrich them with context, and route artifacts into your analysis pipeline.

Operations

SIEM-Ready Telemetry

Forward normalized events to Splunk, Elastic, Sentinel, syslog, webhooks, or data lakes for alerting and threat intelligence correlation.

Federation

Alliance-Wide Sensing

Deploy nodes across exposed surfaces and compare attacker behavior across regions, sectors, and infrastructure tiers.

Detection

Early Warning Signals

Convert low-noise adversary interaction into timely indicators for credential attacks, botnet campaigns, and post-exploitation behavior.

AI Analysis

LLM-Assisted Threat Triage

Package sessions, commands, samples, IOCs, and context into LLM-readable summaries so the SOC can judge intent, priority, and response options faster.

Pipeline

A clean path from interaction to evidence

01

Expose controlled services

Place GCSA honeypot nodes in DMZ, cloud, branch, or lab networks where scanning and credential attacks naturally arrive.

02

Capture attacker behavior

Record authentication attempts, interactive shells, downloads, uploaded payloads, and command sequences with full session context.

03

Enrich and route telemetry

Transform raw interaction into indicators, replay artifacts, and structured events for SOC tooling and alliance intelligence sharing.