AmberCell is a high-interaction honeypot: it runs full, real services AmberCell is a new high-interaction honeypot that runs 28 real protocol decoys — including postfix, OpenLDAP, xrdp and kamailio — rather than emulated look-alikes, according to its operators. The system seals each genuine daemon in a per-protocol cell with tight caps, seccomp and egress allowlists, and gates production exposure behind kill bars G1–G14. Evidence leaves through a one-way dead drop that SIEM and analysts pull from, so attackers interact with real software while no production data is exposed. // high-interaction honeypot · real services · zero emulation AmberCell is a high-interaction honeypot: it runs full, real services — actual postfix, OpenLDAP, xrdp, kamailio — not emulated look-alikes. Attackers interact with genuine daemons on a genuine network stack, and every packet, credential, and payload is preserved, sealed in amber. AmberCell is a decoy computer that looks like a real office network: mail servers, file shares, databases, even a remote-desktop login. The difference from a movie prop: everything on it actually works. Attackers who break in get real software to interact with — and every move is recorded, like insects preserved in amber. Nothing of yours is ever exposed, and the evidence leaves through a one-way letterbox. FOR SECURITY PROFESSIONALS High-interaction by architecture: real OSS daemons in per-protocol cells — no fake shells, no scripted responses ATT&CK/Engage enrichment; bounded AI manager off the packet path with a deterministic critic Kill bars G1–G14 gate production exposure One-way dead drop — SIEM and analysts pull, they never touch the pot meanwhile, in the web — an attacker who touches a cell is stuck in it:no real data, no next hop, no way out. Every struggle is another frame of evidence, preserved. | \ |/ \ | | | | / / | / / \ \| | | /| || || | | |\ \| | | | | || | \ | \ \ /\ | | /\ / 02 / WHY HIGH-INTERACTION MATTERS Honeypots are classed by how much of the service is real. AmberCell sits at the deep end — deliberately. LOW-INTERACTION Emulated protocol banners and handshakes only honeyd-style . Cheap and safe, but an attacker fingerprinting the fake walks away in seconds — you learn almost nothing about what they intended to do. MEDIUM-INTERACTION Scripted emulation: fake shells and canned responses cowrie-style . Better lures, still detectable — behaviour never quite matches a real system, and sophisticated tooling notices the seams. HIGH-INTERACTION AMBERCELL Full, real services. Attackers exploit, authenticate, upload and interact with genuine daemons on a real network stack — the deepest, most truthful evidence you can collect. AmberCell makes that safe to operate: every real daemon is sealed in its own cell with tight caps, seccomp and egress allowlists. / / / / / / / / / / / / / / / / \ \ / / / / / / / / / / \ / / / / / 03 / 28 high-interaction protocol decoys protocol port proto software status ftp 21 tcp vsftpd real ssh 22 tcp openssh real telnet 23 tcp busybox real smtp 25 tcp postfix real dns 53 udp+tcp coredns real tftp 69 udp dnsmasq real http 80/443 tcp nginx real pop3 110 tcp dovecot real ntp 123 udp chrony beta netbios 137 udp nmbd real imap 143 tcp dovecot real snmp 161 udp+tcp net-snmp real ldap 389 tcp openldap beta smb 445 tcp samba real protocol port proto software status syslog 514 tcp+udp rsyslog beta mqtt 1883 tcp mosquitto real dockerapi 2375 tcp mocked api trap mysql 3306 tcp mariadb real rdp 3389 tcp xrdp real sip 5060 tcp kamailio real postgres 5432 tcp postgresql real vnc 5900 tcp tigervnc real redis 6379 tcp redis real elastic 9200 tcp elasticsearch real kubelet 10250 tcp mocked api trap memcached 11211 tcp memcached real ollama 11434 tcp llm lure mock mongo 27017 tcp mongodb real / FLOWS — packets per second, live // ///// / / / //// / / // // // / / / / / / // // // / / / / / / / // // / / / / / / /// / / / / / // / / / // / // / ////// / / // // / // / / /// / / / // /////// /////// // // // // // // // 04 / YOUR DECOY, YOUR WAY — READY OR HOMEMADE whatever you plug in — curated, homemade, or remote — the evidence pipeline stays identical Every protocol cell speaks the same contract. Run a curated real daemon, bring your own, or tunnel to the servers you already operate — the collectors and evidence never change. WAY 1 CURATED REAL DAEMONS 70+ digest-pinned open-source servers ship as one-env-var swaps: AMBER FTP PROVIDER=proftpd, AMBER SMTP PROVIDER=exim, AMBER LDAP PROVIDER=glauth… Each keeps the same evidence schema, so switching never breaks your pipeline. → tutorial 02 WAY 2 BRING YOUR OWN DOCKER Already built the perfect lure? Point a cell at your image: AMBER FTP HI IMAGE=registry…@sha256:… prebuilt or AMBER FTP PROVIDER CONTEXT=/path/to/your/Dockerfile. Containment and capture wrap around whatever you bring. → tutorial 02 WAY 3 TUNNEL TO YOUR OWN SERVER Have real services already? Relay a cell to them at any address: AMBER LDAP PROVIDER=remote + AMBER LDAP REMOTE ADDR=ldap.corp:389. It's an L4 relay — bytes untouched, evidence still captured at the cell front. → tutorial 03 /\ \ \ \ /\ \ /\ \ \ \ \ \ \ \ \ \/\ \ \ \ \/ ".\ \ \ \ \ \ \ \ \ \ \ \ /".~\ \ \/ /\/ / \/ / \/ / \/ / 05 / HOW IT WORKS STEP 1 DECOY Real OSS daemons run in sealed cells behind nftables DNAT — a convincing, high-interaction network. STEP 2 RECORD Per-cell collectors own the netns: rotating pcap, raw flows, credentials, uploads — append-only. STEP 3 EXAMINE ATT&CK/Engage enrichment + bounded AI decisions; intelligence leaves via a one-way dead drop. ┌─────────────────────────── the sealed case ───────────────────────────┐ internet ───▶│ nftables DNAT ──▶ ambernet icc off ──▶ 28 real-service cells │ │ │ │ │ │ │ ▼ ▼ ▼ │ │ egress allowlist dns sinkhole -collector ──▶ /var/ambercell │ │ tcp 80/443 only, all lookups │ pcap · flows · JSONL │ │ tcp/25 dropped logged ▼ │ │ dead drop ◀ one-way letterbox │ └──────────────────────────────────────────────────────────────────────────┘ SIEM / analysts pull — never touch the pot / BEACON — the dead-drop publish cycle dP 88888888b .d888888 888888ba 888888ba 88 88 d8' 88 88 8b 88 8b 88 a88aaaa 88aaaaa88a a88aaaa8P' 88 88 88 88 88 88 88 8b. 88 88 88 88 88 88 88 88 88 88 88888888P 88888888P 88 88 dP dP dP dP 06 / TUTORIALS — interactive, copy-ready, real Every command is verified against the repo. Sessions run in an animated terminal — lines type themselves in, and every $ line copies on click. ▶ start guided tour ~3 min beginner TUT·01 First flight — your first real honeypot Clone, build amberctl, boot a real vsftpd cell, probe it, and watch your first evidence land. No public IP needed. open session ~2 min beginner TUT·02 Swap the decoy — providers & your own Docker Switch vsftpd→proftpd with one variable, then bring a custom image. Evidence schema never changes; digests stay pinned. open session ~2 min intermediate TUT·03 Point a cell at YOUR server Relay attackers into your existing LDAP/SNMP/SIP server at any address — the cell keeps capturing at the front. open session ~2 min analyst TUT·04 Take the intel — the dead drop Publish an evidence bundle, verify it hash-by-hash, and pull it exactly like your SIEM would. open session ~4 min operator TUT·05 Deploy sensors — a remote fleet Headless provisioning, systemd watchdog + publish timer, and a central launcher for many sensors. open session ▄████▄ ▒█████ ███▄ █ ▄▄▄█████▓ ▄▄▄ ██▓ ███▄ █ ▓█████ ▓█████▄ ▒██▀ ▀█ ▒██▒ ██▒ ██ ▀█ █ ▓ ██▒ ▓▒▒████▄ ▓██▒ ██ ▀█ █ ▓█ ▀ ▒██▀ ██▌ ▒▓█ ▄ ▒██░ ██▒▓██ ▀█ ██▒▒ ▓██░ ▒░▒██ ▀█▄ ▒██▒▓██ ▀█ ██▒▒███ ░██ █▌ ▒▓▓▄ ▄██▒▒██ ██░▓██▒ ▐▌██▒░ ▓██▓ ░ ░██▄▄▄▄██ ░██░▓██▒ ▐▌██▒▒▓█ ▄ ░▓█▄ ▌ ▒ ▓███▀ ░░ ████▓▒░▒██░ ▓██░ ▒██▒ ░ ▓█ ▓██▒░██░▒██░ ▓██░░▒████▒░▒████▓ ░ ░▒ ▒ ░░ ▒░▒░▒░ ░ ▒░ ▒ ▒ ▒ ░░ ▒▒ ▓▒█░░▓ ░ ▒░ ▒ ▒ ░░ ▒░ ░ ▒▒▓ ▒ ░ ▒ ░ ▒ ▒░ ░ ░░ ░ ▒░ ░ ▒ ▒▒ ░ ▒ ░░ ░░ ▒▒░ ░ ░ ░ ░ ▒ ▒ ░ ░ ░ ░ ▒ ░ ░ ░ ░ ░ ▒ ▒ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ 07 / SAFETY — real services, hard limits High-interaction means real risk if done naively. AmberCell's answer is layered containment — production exposure is gated by kill bars, and if any trips, you don't ship. ✓ lab profile is the default ✓ no host orchestration, ever ✓ egress allowlist + dns sinkhole ✓ append-only evidence ✓ one-way dead drop ✓ G1 no unexplained egress ✓ G2 no lateral container reach ✓ G3 no host/metadata access ✓ G4 no docker.sock anywhere ✓ G5 unknown traffic never dropped ✓ G6 AI never mutates evidence ✓ G8 traps can't orchestrate ✓ G10 no outbound tcp/25 ✓ G13 no dns/memcached amplification ✓ G14 relays can't widen egress ● AMBERCELL × CHN — you found one piece of the network AmberCell runs perfectly as a standalone box — but it's part of Cyber Halluci Net CHN , our security-research collective. The perfect complete free deception suite.