Trap the attacker
before it gets any further.
A honeypot VM deployed inside the LAN. 14 decoy services (SSH, RDP, SMB, fake Veeam, MSSQL…) that catch lateral movement immediately — often 14 days before the ransomware reaches the real servers.
Nobody has a legitimate reason to connect to a fake backup server or a fake SQL database. HoneyPot plants 14 credible decoys on the LAN — a Veeam banner, Samba shares for finance and HR, MSSQL with logs, RDP on the right hostname, a "BackupServer" dashboard with 200 simulated jobs. On first contact: a critical alert. The SOC sees the lateral movement in progress, isolates the source machine and fires a playbook — before the ransomware starts.
From threat to evidence, in real time.
The module captures the signal, SYLink AI correlates it and decides — you keep control.
The technology, in detail.
What the module actually does — functions, not promises.
14 services leurres
- SSH (Cowrie) + Telnet
- RDP (xrdp + recorder)
- SMB (Samba finance / HR / management)
- FTP + 193 canary files (UUID)
- MSSQL + MySQL + PostgreSQL + Redis + VNC
- Fake Veeam (HTTPS) plus an HTTP honeytrap (25 booby-trapped routes)
Detection
- Any SSH/RDP/SMB connection to the VM is suspicious
- Capture of the credentials attempted
- Commands executed (whoami, net user…)
- HASSH fingerprint of the SSH client
- Inotify on canary files (read / copy)
- Windows OS spoofing (TTL=128) to fool scanners
SYLink AI driven
- Automatic triage (critical / high / medium)
- Reconstruction of the attacker's path (source → decoy)
- DPI cross-correlation (who talked to the decoy?)
- EDR cross-correlation (which process on the source?)
- SOAR playbook generated automatically
VM licence & robustness
- Hardware fingerprint (UUID + machine-id + MAC)
- Lock mode when no licence is present
- HMAC-signed enrolment token
- QR activation with automatic tenant assignment
- Remote revocation means immediate lock
Local threat intel
- Attacking IPs propagated into unified_iocs
- If the attacker strikes elsewhere → tenant alert
- Scan, DDoS and SYN-flood detection
- Boot event analysis
- SOC watchdog: VM down → events replayed
SOAR loop
- Auto IP block → tenant firewall + DPI
- Rotation of the Cowrie user database
- Escalation to an analyst in high mode
- Decoy files regenerated
- TCP reset traceable back to the endpoint
What is it actually for?
Detect an attacker already inside the LAN
Ransomware takes 7 to 14 days to prepare, moving laterally. HoneyPot catches the first SMB attempt on the fake backup server → an alert 14 days before the encryption.
Fool the scanners
An attacker runs nmap: the VM answers as Windows Server, Veeam, MSSQL, RDP. They waste 30 minutes on a fake server — time enough for the SOC to react.
Capture lateral credentials
A script tries psexec with admin/admin1234. Cowrie captures the credentials → the SOC knows which account is compromised elsewhere.
Threat intel propagated
The attacking IP is added to the internal CTI feeds. If it reappears on the DPI sensor or the EDR, the alert is instant. One detection feeds the whole chain.
Driven by SYLink AI, hosted 100% in France (HDS v2), with no Cloud Act exposure. Every decision is logged and defensible under NIS2 and DORA.
One building block of the SOC — never on its own.
Each module feeds the others through SYLink AI.
Ready to see what is really
happening on your network?
First trial free, no credit card, no commitment. On your existing infrastructure.
