{"slug": "ambercell-is-a-high-interaction-honeypot-it-runs-full-real-services", "title": "AmberCell is a high-interaction honeypot: it runs full, real services", "summary": "AmberCell is a new high-interaction honeypot that runs 28 real protocol decoys — including postfix, OpenLDAP, xrdp and kamailio — rather than emulated look-alikes, according to its operators. The system seals each genuine daemon in a per-protocol cell with tight caps, seccomp and egress allowlists, and gates production exposure behind kill bars G1–G14. Evidence leaves through a one-way dead drop that SIEM and analysts pull from, so attackers interact with real software while no production data is exposed.", "body_md": "／／ high-interaction honeypot · real services · zero emulation\n\nAmberCell is a high-interaction honeypot: it runs full, real\nservices — actual postfix, OpenLDAP, xrdp, kamailio — not emulated look-alikes.\nAttackers interact with genuine daemons on a genuine network stack, and every packet,\ncredential, and payload is preserved, sealed in amber.\n\nAmberCell is a decoy computer that looks like a real\noffice network: mail servers, file shares, databases, even a remote-desktop login.\n\nThe difference from a movie prop: everything on it actually\nworks. Attackers who break in get real software to interact with — and every move is\nrecorded, like insects preserved in amber.\n\nNothing of yours is ever exposed, and the evidence\nleaves through a one-way letterbox.\n\nFOR SECURITY PROFESSIONALS\n\nHigh-interaction by architecture: real OSS daemons in per-protocol\ncells — no fake shells, no scripted responses\n\nATT&CK/Engage enrichment; bounded AI manager off the packet path with a deterministic critic\n\nKill bars G1–G14 gate production exposure\n\nOne-way dead drop — SIEM and analysts pull, they never touch the pot\n\nmeanwhile, in the web — an attacker who touches a cell is\nstuck in it:no real data, no next hop, no way out. Every struggle is\nanother frame of evidence, preserved.\n\n```\n______ _____  ___   _\n| ___ \\  ___|/ _ \\ | |\n| |_/ / |__ / /_\\ \\| |\n|    /|  __||  _  || |\n| |\\ \\| |___| | | || |____\n\\_| \\_\\____/\\_| |_/\\_____/\n```\n\n02 / WHY HIGH-INTERACTION MATTERS\n\nHoneypots are classed by how much of the service is real. AmberCell sits at the deep end —\ndeliberately.\n\nLOW-INTERACTION\n\nEmulated protocol banners and handshakes only (honeyd-style). Cheap and safe, but an\nattacker fingerprinting the fake walks away in seconds — you learn almost nothing about\nwhat they intended to do.\n\nMEDIUM-INTERACTION\n\nScripted emulation: fake shells and canned responses (cowrie-style). Better lures, still\ndetectable — behaviour never quite matches a real system, and sophisticated tooling\nnotices the seams.\n\nHIGH-INTERACTION AMBERCELL\n\nFull, real services. Attackers exploit, authenticate,\nupload and interact with genuine daemons on a real network stack — the deepest, most\ntruthful evidence you can collect. AmberCell makes that safe\nto operate: every real daemon is sealed in its own cell with tight caps, seccomp and\negress allowlists.\n\n```\n   ______________    __   _____\n  / ____/ ____/ /   / /  / ___/\n / /   / __/ / /   / /   \\__ \\\n/ /___/ /___/ /___/ /______/ /\n\\____/_____/_____/_____/____/\n```\n\n03 / 28 high-interaction protocol decoys\n\nprotocol\n\nport\n\nproto\n\nsoftware\n\nstatus\n\nftp\n\n21\n\ntcp\n\nvsftpd\n\nreal\n\nssh\n\n22\n\ntcp\n\nopenssh\n\nreal\n\ntelnet\n\n23\n\ntcp\n\nbusybox\n\nreal\n\nsmtp\n\n25\n\ntcp\n\npostfix\n\nreal\n\ndns\n\n53\n\nudp+tcp\n\ncoredns\n\nreal\n\ntftp\n\n69\n\nudp\n\ndnsmasq\n\nreal\n\nhttp\n\n80/443\n\ntcp\n\nnginx\n\nreal\n\npop3\n\n110\n\ntcp\n\ndovecot\n\nreal\n\nntp\n\n123\n\nudp\n\nchrony\n\nbeta\n\nnetbios\n\n137\n\nudp\n\nnmbd\n\nreal\n\nimap\n\n143\n\ntcp\n\ndovecot\n\nreal\n\nsnmp\n\n161\n\nudp+tcp\n\nnet-snmp\n\nreal\n\nldap\n\n389\n\ntcp\n\nopenldap\n\nbeta\n\nsmb\n\n445\n\ntcp\n\nsamba\n\nreal\n\nprotocol\n\nport\n\nproto\n\nsoftware\n\nstatus\n\nsyslog\n\n514\n\ntcp+udp\n\nrsyslog\n\nbeta\n\nmqtt\n\n1883\n\ntcp\n\nmosquitto\n\nreal\n\ndockerapi\n\n2375\n\ntcp\n\nmocked api\n\ntrap\n\nmysql\n\n3306\n\ntcp\n\nmariadb\n\nreal\n\nrdp\n\n3389\n\ntcp\n\nxrdp\n\nreal\n\nsip\n\n5060\n\ntcp\n\nkamailio\n\nreal\n\npostgres\n\n5432\n\ntcp\n\npostgresql\n\nreal\n\nvnc\n\n5900\n\ntcp\n\ntigervnc\n\nreal\n\nredis\n\n6379\n\ntcp\n\nredis\n\nreal\n\nelastic\n\n9200\n\ntcp\n\nelasticsearch\n\nreal\n\nkubelet\n\n10250\n\ntcp\n\nmocked api\n\ntrap\n\nmemcached\n\n11211\n\ntcp\n\nmemcached\n\nreal\n\nollama\n\n11434\n\ntcp\n\nllm lure\n\nmock\n\nmongo\n\n27017\n\ntcp\n\nmongodb\n\nreal\n\n／ FLOWS — packets per second, live\n\n```\n **    **   *******   **     ** *******     **       **     **     **    **\n//**  **   **/////** /**    /**/**////**   /**      /**    ****   //**  **\n //****   **     //**/**    /**/**   /**   /**   *  /**   **//**   //****\n  //**   /**      /**/**    /**/*******    /**  *** /**  **  //**   //**\n   /**   /**      /**/**    /**/**///**    /** **/**/** **********   /**\n   /**   //**     ** /**    /**/**  //**   /**** //****/**//////**   /**\n   /**    //*******  //******* /**   //**  /**/   ///**/**     /**   /**\n   //      ///////    ///////  //     //   //       // //      //    //\n```\n\n04 / YOUR DECOY, YOUR WAY — READY OR HOMEMADE\n\nwhatever you plug in — curated, homemade, or remote — the evidence pipeline stays identical\n\nEvery protocol cell speaks the same contract. Run a curated real daemon, bring your own,\nor tunnel to the servers you already operate — the collectors and evidence never change.\n\nWAY 1\n\nCURATED REAL DAEMONS\n\n70+ digest-pinned open-source servers ship as one-env-var swaps:\nAMBER_FTP_PROVIDER=proftpd, AMBER_SMTP_PROVIDER=exim,\nAMBER_LDAP_PROVIDER=glauth… Each keeps the same evidence schema, so\nswitching never breaks your pipeline.\n\n→ tutorial 02\n\nWAY 2\n\nBRING YOUR OWN DOCKER\n\nAlready built the perfect lure? Point a cell at your image:\nAMBER_FTP_HI_IMAGE=registry…@sha256:… (prebuilt) or\nAMBER_FTP_PROVIDER_CONTEXT=/path/to/your/Dockerfile. Containment and\ncapture wrap around whatever you bring.\n\n→ tutorial 02\n\nWAY 3\n\nTUNNEL TO YOUR OWN SERVER\n\nHave real services already? Relay a cell to them at any address:\nAMBER_LDAP_PROVIDER=remote +\nAMBER_LDAP_REMOTE_ADDR=ldap.corp:389. It's an L4 relay — bytes untouched,\nevidence still captured at the cell front.\n\n→ tutorial 03\n\n```\n __  __     ______     __     __\n/\\ \\_\\ \\   /\\  __ \\   /\\ \\  _ \\ \\\n\\ \\  __ \\  \\ \\ \\/\\ \\  \\ \\ \\/ \".\\ \\\n \\ \\_\\ \\_\\  \\ \\_____\\  \\ \\__/\".~\\_\\\n  \\/_/\\/_/   \\/_____/   \\/_/   \\/_/\n```\n\n05 / HOW IT WORKS\n\nSTEP 1\n\nDECOY\n\nReal OSS daemons run in sealed cells behind nftables DNAT — a convincing, high-interaction network.\n\nSTEP 2\n\nRECORD\n\nPer-cell collectors own the netns: rotating pcap, raw flows, credentials, uploads — append-only.\n\nSTEP 3\n\nEXAMINE\n\nATT&CK/Engage enrichment + bounded AI decisions; intelligence leaves via a one-way dead drop.\n\n```\n              ┌─────────────────────────── the sealed case ───────────────────────────┐\n internet ───▶│ nftables DNAT ──▶ ambernet (icc off) ──▶ 28 real-service cells           │\n              │      │                     │                    │                        │\n              │      ▼                     ▼                    ▼                        │\n              │ egress allowlist      dns sinkhole      *-collector ──▶ /var/ambercell │\n              │ (tcp 80/443 only,     (all lookups           │        pcap · flows · JSONL  │\n              │  tcp/25 dropped)       logged)                ▼                            │\n              │                                          dead drop ◀ one-way letterbox   │\n              └──────────────────────────────────────────────────────────────────────────┘\n                                                SIEM / analysts pull — never touch the pot\n```\n\n／ BEACON — the dead-drop publish cycle\n\n```\ndP         88888888b  .d888888   888888ba  888888ba\n88         88        d8'    88   88    `8b 88    `8b\n88        a88aaaa    88aaaaa88a a88aaaa8P' 88     88\n88         88        88     88   88   `8b. 88     88\n88         88        88     88   88     88 88     88\n88888888P  88888888P 88     88   dP     dP dP     dP\n```\n\n06 / TUTORIALS — interactive, copy-ready, real\n\nEvery command is verified against the repo. Sessions run in an animated terminal —\nlines type themselves in, and every $ line copies on click.\n▶ start guided tour\n\n~3 min beginner\n\nTUT·01\n\nFirst flight — your first real honeypot\n\nClone, build amberctl, boot a real vsftpd cell, probe it, and watch your first evidence land. No public IP needed.\n\n> open_session_\n\n~2 min beginner\n\nTUT·02\n\nSwap the decoy — providers & your own Docker\n\nSwitch vsftpd→proftpd with one variable, then bring a custom image. Evidence schema never changes; digests stay pinned.\n\n> open_session_\n\n~2 min intermediate\n\nTUT·03\n\nPoint a cell at YOUR server\n\nRelay attackers into your existing LDAP/SNMP/SIP server at any address — the cell keeps capturing at the front.\n\n> open_session_\n\n~2 min analyst\n\nTUT·04\n\nTake the intel — the dead drop\n\nPublish an evidence bundle, verify it hash-by-hash, and pull it exactly like your SIEM would.\n\n> open_session_\n\n~4 min operator\n\nTUT·05\n\nDeploy sensors — a remote fleet\n\nHeadless provisioning, systemd watchdog + publish timer, and a central launcher for many sensors.\n\n> open_session_\n\n```\n ▄████▄   ▒█████   ███▄    █ ▄▄▄█████▓ ▄▄▄       ██▓ ███▄    █ ▓█████ ▓█████▄\n▒██▀ ▀█  ▒██▒  ██▒ ██ ▀█   █ ▓  ██▒ ▓▒▒████▄    ▓██▒ ██ ▀█   █ ▓█   ▀ ▒██▀ ██▌\n▒▓█    ▄ ▒██░  ██▒▓██  ▀█ ██▒▒ ▓██░ ▒░▒██  ▀█▄  ▒██▒▓██  ▀█ ██▒▒███   ░██   █▌\n▒▓▓▄ ▄██▒▒██   ██░▓██▒  ▐▌██▒░ ▓██▓ ░ ░██▄▄▄▄██ ░██░▓██▒  ▐▌██▒▒▓█  ▄ ░▓█▄   ▌\n▒ ▓███▀ ░░ ████▓▒░▒██░   ▓██░  ▒██▒ ░  ▓█   ▓██▒░██░▒██░   ▓██░░▒████▒░▒████▓\n░ ░▒ ▒  ░░ ▒░▒░▒░ ░ ▒░   ▒ ▒   ▒ ░░    ▒▒   ▓▒█░░▓  ░ ▒░   ▒ ▒ ░░ ▒░ ░ ▒▒▓  ▒\n  ░  ▒     ░ ▒ ▒░ ░ ░░   ░ ▒░    ░      ▒   ▒▒ ░ ▒ ░░ ░░   ▒▒░ ░ ░  ░ ░ ▒  ▒\n░        ░ ░ ░ ▒     ░   ░ ░   ░        ░   ▒    ▒ ░   ░   ░ ░    ░    ░ ░  ░\n░ ░          ░ ░           ░                ░  ░ ░           ░    ░  ░   ░\n░                                                                      ░\n```\n\n07 / SAFETY — real services, hard limits\n\nHigh-interaction means real risk if done naively. AmberCell's answer is layered containment —\nproduction exposure is gated by kill bars, and if any trips, you don't ship.\n\n[✓] lab profile is the default[✓] no host orchestration, ever[✓] egress allowlist + dns sinkhole[✓] append-only evidence[✓] one-way dead drop\n\n[✓] G1 no unexplained egress\n\n[✓] G2 no lateral container reach\n\n[✓] G3 no host/metadata access\n\n[✓] G4 no docker.sock anywhere\n\n[✓] G5 unknown traffic never dropped\n\n[✓] G6 AI never mutates evidence\n\n[✓] G8 traps can't orchestrate\n\n[✓] G10 no outbound tcp/25\n\n[✓] G13 no dns/memcached amplification\n\n[✓] G14 relays can't widen egress\n\n● AMBERCELL × CHN — you found one piece of the network\n\nAmberCell runs perfectly as a standalone box — but it's part of\nCyber Halluci Net (CHN), our security-research collective.\nThe perfect complete free deception suite.", "url": "https://wpnews.pro/news/ambercell-is-a-high-interaction-honeypot-it-runs-full-real-services", "canonical_source": "https://cyberhallucinet.github.io/AmberCell/", "published_at": "2026-10-09 09:38:44+00:00", "updated_at": "2026-10-09 09:52:05.820493+00:00", "lang": "en", "topics": ["ai-safety"], "entities": ["AmberCell", "postfix", "OpenLDAP", "xrdp", "kamailio", "cowrie", "honeyd", "SIEM"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/ambercell-is-a-high-interaction-honeypot-it-runs-full-real-services", "markdown": "https://wpnews.pro/news/ambercell-is-a-high-interaction-honeypot-it-runs-full-real-services.md", "text": "https://wpnews.pro/news/ambercell-is-a-high-interaction-honeypot-it-runs-full-real-services.txt", "jsonld": "https://wpnews.pro/news/ambercell-is-a-high-interaction-honeypot-it-runs-full-real-services.jsonld"}}