Tech riderRev. 4 Oct 2026
- 1Runs onLinux, Mac, self-hosted, Windows
- 2CostsFree plan
- 3Deployment modelself-hosted
- 4Decoy scopemulti-layer
4 lines stated Written from the maker's own pages: github.com

Overview
T-Pot is ranked #5 of 18 in honeypot software on Specifiction. It runs on Linux, macOS, Self-hosted, Windows. There is a free plan.
T-Pot plans and pricing
All plansT-Pot Free open source · self-hosted · hardware and network requirements apply github.com · 4 Oct 2026
Compared on honeypot software
- Free plan
- Yesgithub.com
- Deployment model
- self-hostedgithub.com
- Decoy scope
- multi-layergithub.com
Facts
- Purpose
- T-Pot is an all-in-one, optionally distributed honeypot platform supporting multiple architectures and more than 20 honeypots.github.com · 4 Oct 2026
- Analysis stack
- It uses Elasticsearch to store events, Logstash to ingest and send them, and Kibana to display dashboards.github.com · 4 Oct 2026
- Network monitoring
- Included network security monitoring tools include Fatt, P0f, and Suricata.github.com · 4 Oct 2026
- Visualization and tools
- Included tools include an animated attack map, CyberChef, Elasticvue, and Spiderfoot.github.com · 4 Oct 2026
- Deployment
- T-Pot supports standalone and distributed deployments, including hive and sensor installation types.github.com · 4 Oct 2026
- Operating systems
- The project documents supported Linux distributions and says macOS and Windows use Docker Desktop with a limited feature set.github.com · 4 Oct 2026
- Hardware requirements
- The project recommends 16 GB RAM and a 256 GB SSD for a hive, or 8 GB RAM and a 128 GB SSD for a sensor.github.com · 4 Oct 2026
- Data sharing
- By default, data is submitted to Sicherheitstacho, and the project says this can be disabled by removing the ewsposter section from the configuration.github.com · 4 Oct 2026
- Security considerations
- The project warns that compromise cannot be ruled out and says honeypots should not contain sensitive data.github.com · 4 Oct 2026
- Vulnerability reporting
- The security policy asks reporters to identify the affected component, provide reproduction details, and check whether the issue is known upstream.github.com · 4 Oct 2026
- Support
- T-Pot is provided as-is without a support commitment; users can report issues and ask general questions through GitHub Issues and Discussions.github.com · 4 Oct 2026
- Retention
- Log persistence defaults to 30 cycles and the default Elasticsearch index policy keeps indices for 30 days; both can be adjusted.github.com · 4 Oct 2026
- LLM honeypots
- The Beelzebub and Galah honeypots require Ollama, while ChatGPT support is described as untested with T-Pot.github.com · 4 Oct 2026
Best T-Pot alternatives
See all 17 All accessCh 01 OpenCanary Free planLinuxMac Free to start7.3 All accessCh 02 Beelzebub Free planFree trialAPI Free to start7.2 All accessCh 03 Canarytokens Free planAndroidiOS Free to start7.2 All accessCh 04 Honeyd Free planLinuxself-hosted Free to start7.0 All accessCh 06 Cowrie Free planLinuxself-hosted Free to start6.9 All accessCh 07 Honeytrap Free planLinuxself-hosted Free to start6.9
Where it ranks on Specifiction
- Best Honeypot Software in 2026#5 of 18
Is T-Pot yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- github.com/telekom-security/tpotce· checked 4 Oct 2026
- github.com/telekom-security/tpotce/security/policy· checked 4 Oct 2026


