// high-interaction honeypot · real services · zero emulation
AmberCell is a high-interaction honeypot: it runs full, real services — actual postfix, OpenLDAP, xrdp, kamailio — not emulated look-alikes. Attackers interact with genuine daemons on a genuine network stack, and every packet, credential, and payload is preserved, sealed in amber.
AmberCell is a decoy computer that looks like a real office network: mail servers, file shares, databases, even a remote-desktop login.
The difference from a movie prop: everything on it actually works. Attackers who break in get real software to interact with — and every move is recorded, like insects preserved in amber.
Nothing of yours is ever exposed, and the evidence leaves through a one-way letterbox.
FOR SECURITY PROFESSIONALS
High-interaction by architecture: real OSS daemons in per-protocol cells — no fake shells, no scripted responses
ATT&CK/Engage enrichment; bounded AI manager off the packet path with a deterministic critic
Kill bars G1–G14 gate production exposure
One-way dead drop — SIEM and analysts pull, they never touch the pot
meanwhile, in the web — an attacker who touches a cell is stuck in it:no real data, no next hop, no way out. Every struggle is another frame of evidence, preserved.
______ _____ ___ _
| ___ \ ___|/ _ \ | |
| |_/ / |__ / /_\ \| |
| /| __|| _ || |
| |\ \| |___| | | || |____
\_| \_\____/\_| |_/\_____/
02 / WHY HIGH-INTERACTION MATTERS
Honeypots are classed by how much of the service is real. AmberCell sits at the deep end — deliberately.
LOW-INTERACTION
Emulated protocol banners and handshakes only (honeyd-style). Cheap and safe, but an attacker fingerprinting the fake walks away in seconds — you learn almost nothing about what they intended to do.
MEDIUM-INTERACTION
Scripted emulation: fake shells and canned responses (cowrie-style). Better lures, still detectable — behaviour never quite matches a real system, and sophisticated tooling notices the seams.
HIGH-INTERACTION AMBERCELL
Full, real services. Attackers exploit, authenticate, upload and interact with genuine daemons on a real network stack — the deepest, most truthful evidence you can collect. AmberCell makes that safe to operate: every real daemon is sealed in its own cell with tight caps, seccomp and egress allowlists.
______________ __ _____
/ ____/ ____/ / / / / ___/
/ / / __/ / / / / \__ \
/ /___/ /___/ /___/ /______/ /
\____/_____/_____/_____/____/
03 / 28 high-interaction protocol decoys
protocol
port
proto
software
status
ftp
21
tcp
vsftpd
real
ssh
22
tcp
openssh
real
telnet
23
tcp
busybox
real
smtp
25
tcp
postfix
real
dns
53
udp+tcp
coredns
real
tftp
69
udp
dnsmasq
real
http
80/443
tcp
nginx
real
pop3
110
tcp
dovecot
real
ntp
123
udp
chrony
beta
netbios
137
udp
nmbd
real
imap
143
tcp
dovecot
real
snmp
161
udp+tcp
net-snmp
real
ldap
389
tcp
openldap
beta
smb
445
tcp
samba
real
protocol
port
proto
software
status
syslog
514
tcp+udp
rsyslog
beta
mqtt
1883
tcp
mosquitto
real
dockerapi
2375
tcp
mocked api
trap
mysql
3306
tcp
mariadb
real
rdp
3389
tcp
xrdp
real
sip
5060
tcp
kamailio
real
postgres
5432
tcp
postgresql
real
vnc
5900
tcp
tigervnc
real
redis
6379
tcp
redis
real
elastic
9200
tcp
elasticsearch
real
kubelet
10250
tcp
mocked api
trap
memcached
11211
tcp
memcached
real
ollama
11434
tcp
llm lure
mock
mongo
27017
tcp
mongodb
real
/ FLOWS — packets per second, live
** ** ******* ** ** ******* ** ** ** ** **
//** ** **/////** /** /**/**////** /** /** **** //** **
//**** ** //**/** /**/** /** /** * /** **//** //****
//** /** /**/** /**/******* /** *** /** ** //** //**
/** /** /**/** /**/**///** /** **/**/** ********** /**
/** //** ** /** /**/** //** /**** //****/**//////** /**
/** //******* //******* /** //** /**/ ///**/** /** /**
// /////// /////// // // // // // // //
04 / YOUR DECOY, YOUR WAY — READY OR HOMEMADE
whatever you plug in — curated, homemade, or remote — the evidence pipeline stays identical
Every protocol cell speaks the same contract. Run a curated real daemon, bring your own, or tunnel to the servers you already operate — the collectors and evidence never change.
WAY 1
CURATED REAL DAEMONS
70+ digest-pinned open-source servers ship as one-env-var swaps: AMBER_FTP_PROVIDER=proftpd, AMBER_SMTP_PROVIDER=exim, AMBER_LDAP_PROVIDER=glauth… Each keeps the same evidence schema, so switching never breaks your pipeline.
→ tutorial 02
WAY 2
BRING YOUR OWN DOCKER
Already built the perfect lure? Point a cell at your image: AMBER_FTP_HI_IMAGE=registry…@sha256:… (prebuilt) or AMBER_FTP_PROVIDER_CONTEXT=/path/to/your/Dockerfile. Containment and capture wrap around whatever you bring.
→ tutorial 02
WAY 3
TUNNEL TO YOUR OWN SERVER
Have real services already? Relay a cell to them at any address: AMBER_LDAP_PROVIDER=remote + AMBER_LDAP_REMOTE_ADDR=ldap.corp:389. It's an L4 relay — bytes untouched, evidence still captured at the cell front.
→ tutorial 03
__ __ ______ __ __
/\ \_\ \ /\ __ \ /\ \ _ \ \
\ \ __ \ \ \ \/\ \ \ \ \/ ".\ \
\ \_\ \_\ \ \_____\ \ \__/".~\_\
\/_/\/_/ \/_____/ \/_/ \/_/
05 / HOW IT WORKS
STEP 1
DECOY
Real OSS daemons run in sealed cells behind nftables DNAT — a convincing, high-interaction network.
STEP 2
RECORD
Per-cell collectors own the netns: rotating pcap, raw flows, credentials, uploads — append-only.
STEP 3
EXAMINE
ATT&CK/Engage enrichment + bounded AI decisions; intelligence leaves via a one-way dead drop.
┌─────────────────────────── the sealed case ───────────────────────────┐
internet ───▶│ nftables DNAT ──▶ ambernet (icc off) ──▶ 28 real-service cells │
│ │ │ │ │
│ ▼ ▼ ▼ │
│ egress allowlist dns sinkhole *-collector ──▶ /var/ambercell │
│ (tcp 80/443 only, (all lookups │ pcap · flows · JSONL │
│ tcp/25 dropped) logged) ▼ │
│ dead drop ◀ one-way letterbox │
└──────────────────────────────────────────────────────────────────────────┘
SIEM / analysts pull — never touch the pot
/ BEACON — the dead-drop publish cycle
dP 88888888b .d888888 888888ba 888888ba
88 88 d8' 88 88 `8b 88 `8b
88 a88aaaa 88aaaaa88a a88aaaa8P' 88 88
88 88 88 88 88 `8b. 88 88
88 88 88 88 88 88 88 88
88888888P 88888888P 88 88 dP dP dP dP
06 / TUTORIALS — interactive, copy-ready, real
Every command is verified against the repo. Sessions run in an animated terminal — lines type themselves in, and every $ line copies on click. ▶ start guided tour
~3 min beginner
TUT·01
First flight — your first real honeypot
Clone, build amberctl, boot a real vsftpd cell, probe it, and watch your first evidence land. No public IP needed.
open_session_
~2 min beginner
TUT·02
Swap the decoy — providers & your own Docker
Switch vsftpd→proftpd with one variable, then bring a custom image. Evidence schema never changes; digests stay pinned.
open_session_
~2 min intermediate
TUT·03
Point a cell at YOUR server
Relay attackers into your existing LDAP/SNMP/SIP server at any address — the cell keeps capturing at the front.
open_session_
~2 min analyst
TUT·04
Take the intel — the dead drop
Publish an evidence bundle, verify it hash-by-hash, and pull it exactly like your SIEM would.
open_session_
~4 min operator
TUT·05
Deploy sensors — a remote fleet
Headless provisioning, systemd watchdog + publish timer, and a central launcher for many sensors.
open_session_
▄████▄ ▒█████ ███▄ █ ▄▄▄█████▓ ▄▄▄ ██▓ ███▄ █ ▓█████ ▓█████▄
▒██▀ ▀█ ▒██▒ ██▒ ██ ▀█ █ ▓ ██▒ ▓▒▒████▄ ▓██▒ ██ ▀█ █ ▓█ ▀ ▒██▀ ██▌
▒▓█ ▄ ▒██░ ██▒▓██ ▀█ ██▒▒ ▓██░ ▒░▒██ ▀█▄ ▒██▒▓██ ▀█ ██▒▒███ ░██ █▌
▒▓▓▄ ▄██▒▒██ ██░▓██▒ ▐▌██▒░ ▓██▓ ░ ░██▄▄▄▄██ ░██░▓██▒ ▐▌██▒▒▓█ ▄ ░▓█▄ ▌
▒ ▓███▀ ░░ ████▓▒░▒██░ ▓██░ ▒██▒ ░ ▓█ ▓██▒░██░▒██░ ▓██░░▒████▒░▒████▓
░ ░▒ ▒ ░░ ▒░▒░▒░ ░ ▒░ ▒ ▒ ▒ ░░ ▒▒ ▓▒█░░▓ ░ ▒░ ▒ ▒ ░░ ▒░ ░ ▒▒▓ ▒
░ ▒ ░ ▒ ▒░ ░ ░░ ░ ▒░ ░ ▒ ▒▒ ░ ▒ ░░ ░░ ▒▒░ ░ ░ ░ ░ ▒ ▒
░ ░ ░ ░ ▒ ░ ░ ░ ░ ░ ▒ ▒ ░ ░ ░ ░ ░ ░ ░ ░
░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░
░ ░
07 / SAFETY — real services, hard limits
High-interaction means real risk if done naively. AmberCell's answer is layered containment — production exposure is gated by kill bars, and if any trips, you don't ship.
[✓] lab profile is the default[✓] no host orchestration, ever[✓] egress allowlist + dns sinkhole[✓] append-only evidence[✓] one-way dead drop
[✓] G1 no unexplained egress
[✓] G2 no lateral container reach
[✓] G3 no host/metadata access
[✓] G4 no docker.sock anywhere
[✓] G5 unknown traffic never dropped
[✓] G6 AI never mutates evidence
[✓] G8 traps can't orchestrate
[✓] G10 no outbound tcp/25
[✓] G13 no dns/memcached amplification
[✓] G14 relays can't widen egress
● AMBERCELL × CHN — you found one piece of the network
AmberCell runs perfectly as a standalone box — but it's part of Cyber Halluci Net (CHN), our security-research collective. The perfect complete free deception suite.