// high-interaction honeypot · real services · zero emulation

AmberCell is a high-interaction honeypot: it runs full, real services — actual postfix, OpenLDAP, xrdp, kamailio — not emulated look-alikes. Attackers interact with genuine daemons on a genuine network stack, and every packet, credential, and payload is preserved, sealed in amber.

/ CELL BOOT SEQUENCE /
utc —
the cells never sleep
high-interaction means the services are real — why that matters ↓

01 / WHAT IS A HONEYPOT — IN TWO DIALECTS

IN PLAIN TERMS

AmberCell is a decoy computer that looks like a real office network: mail servers, file shares, databases, even a remote-desktop login.

The difference from a movie prop: everything on it actually works. Attackers who break in get real software to interact with — and every move is recorded, like insects preserved in amber.

Nothing of yours is ever exposed, and the evidence leaves through a one-way letterbox.

FOR SECURITY PROFESSIONALS

  • High-interaction by architecture: real OSS daemons in per-protocol cells — no fake shells, no scripted responses
  • Single-host Docker Compose (Ubuntu 22.04 / Debian 12), host nftables ingress/egress
  • Collector-owned netns capture: pcap + raw flows + JSONL events, append-only
  • ATT&CK/Engage enrichment; bounded AI manager off the packet path with a deterministic critic
  • Kill bars G1–G14 gate production exposure
  • One-way dead drop — SIEM and analysts pull, they never touch the pot
meanwhile, in the web — an attacker who touches a cell is stuck in it: no real data, no next hop, no way out. Every struggle is another frame of evidence, preserved.

02 / WHY HIGH-INTERACTION MATTERS

Honeypots are classed by how much of the service is real. AmberCell sits at the deep end — deliberately.

LOW-INTERACTION

Emulated protocol banners and handshakes only (honeyd-style). Cheap and safe, but an attacker fingerprinting the fake walks away in seconds — you learn almost nothing about what they intended to do.

MEDIUM-INTERACTION

Scripted emulation: fake shells and canned responses (cowrie-style). Better lures, still detectable — behaviour never quite matches a real system, and sophisticated tooling notices the seams.

HIGH-INTERACTION AMBERCELL

Full, real services. Attackers exploit, authenticate, upload and interact with genuine daemons on a real network stack — the deepest, most truthful evidence you can collect. AmberCell makes that safe to operate: every real daemon is sealed in its own cell with tight caps, seccomp and egress allowlists.

03 / 28 high-interaction protocol decoys

protocolportprotosoftwarestatus
ftp21tcpvsftpdreal
ssh22tcpopensshreal
telnet23tcpbusyboxreal
smtp25tcppostfixreal
dns53udp+tcpcorednsreal
tftp69udpdnsmasqreal
http80/443tcpnginxreal
pop3110tcpdovecotreal
ntp123udpchronybeta
netbios137udpnmbdreal
imap143tcpdovecotreal
snmp161udp+tcpnet-snmpreal
ldap389tcpopenldapbeta
smb445tcpsambareal
protocolportprotosoftwarestatus
syslog514tcp+udprsyslogbeta
mqtt1883tcpmosquittoreal
dockerapi2375tcpmocked apitrap
mysql3306tcpmariadbreal
rdp3389tcpxrdpreal
sip5060tcpkamailioreal
postgres5432tcppostgresqlreal
vnc5900tcptigervncreal
redis6379tcpredisreal
elastic9200tcpelasticsearchreal
kubelet10250tcpmocked apitrap
memcached11211tcpmemcachedreal
ollama11434tcpllm luremock
mongo27017tcpmongodbreal
/ FLOWS — packets per second, live

04 / YOUR DECOY, YOUR WAY — READY OR HOMEMADE

whatever you plug in — curated, homemade, or remote — the evidence pipeline stays identical

Every protocol cell speaks the same contract. Run a curated real daemon, bring your own, or tunnel to the servers you already operate — the collectors and evidence never change.

WAY 1

CURATED REAL DAEMONS

70+ digest-pinned open-source servers ship as one-env-var swaps: AMBER_FTP_PROVIDER=proftpd, AMBER_SMTP_PROVIDER=exim, AMBER_LDAP_PROVIDER=glauth… Each keeps the same evidence schema, so switching never breaks your pipeline.

WAY 2

BRING YOUR OWN DOCKER

Already built the perfect lure? Point a cell at your image: AMBER_FTP_HI_IMAGE=registry…@sha256:… (prebuilt) or AMBER_FTP_PROVIDER_CONTEXT=/path/to/your/Dockerfile. Containment and capture wrap around whatever you bring.

WAY 3

TUNNEL TO YOUR OWN SERVER

Have real services already? Relay a cell to them at any address: AMBER_LDAP_PROVIDER=remote + AMBER_LDAP_REMOTE_ADDR=ldap.corp:389. It's an L4 relay — bytes untouched, evidence still captured at the cell front.

05 / HOW IT WORKS

STEP 1

DECOY

Real OSS daemons run in sealed cells behind nftables DNAT — a convincing, high-interaction network.

STEP 2

RECORD

Per-cell collectors own the netns: rotating pcap, raw flows, credentials, uploads — append-only.

STEP 3

EXAMINE

ATT&CK/Engage enrichment + bounded AI decisions; intelligence leaves via a one-way dead drop.

              ┌─────────────────────────── the sealed case ───────────────────────────┐
 internet ───▶│ nftables DNAT ──▶ ambernet (icc off) ──▶ 28 real-service cells           │
              │      │                     │                    │                        │
              │      ▼                     ▼                    ▼                        │
              │ egress allowlist      dns sinkhole      *-collector ──▶ /var/ambercell │
              │ (tcp 80/443 only,     (all lookups           │        pcap · flows · JSONL  │
              │  tcp/25 dropped)       logged)                ▼                            │
              │                                          dead drop ◀ one-way letterbox   │
              └──────────────────────────────────────────────────────────────────────────┘
                                                SIEM / analysts pull — never touch the pot
/ BEACON — the dead-drop publish cycle

06 / TUTORIALS — interactive, copy-ready, real

Every command is verified against the repo. Sessions run in an animated terminal — lines type themselves in, and every $ line copies on click.

~3 min
beginner
TUT·01

First flight — your first real honeypot

Clone, build amberctl, boot a real vsftpd cell, probe it, and watch your first evidence land. No public IP needed.

> open_session_
~2 min
beginner
TUT·02

Swap the decoy — providers & your own Docker

Switch vsftpd→proftpd with one variable, then bring a custom image. Evidence schema never changes; digests stay pinned.

> open_session_
~2 min
intermediate
TUT·03

Point a cell at YOUR server

Relay attackers into your existing LDAP/SNMP/SIP server at any address — the cell keeps capturing at the front.

> open_session_
~2 min
analyst
TUT·04

Take the intel — the dead drop

Publish an evidence bundle, verify it hash-by-hash, and pull it exactly like your SIEM would.

> open_session_
~4 min
operator
TUT·05

Deploy sensors — a remote fleet

Headless provisioning, systemd watchdog + publish timer, and a central launcher for many sensors.

> open_session_

07 / SAFETY — real services, hard limits

High-interaction means real risk if done naively. AmberCell's answer is layered containment — production exposure is gated by kill bars, and if any trips, you don't ship.

[✓] lab profile is the default [✓] no host orchestration, ever [✓] egress allowlist + dns sinkhole [✓] append-only evidence [✓] one-way dead drop
[✓] G1 no unexplained egress
[✓] G2 no lateral container reach
[✓] G3 no host/metadata access
[✓] G4 no docker.sock anywhere
[✓] G5 unknown traffic never dropped
[✓] G6 AI never mutates evidence
[✓] G8 traps can't orchestrate
[✓] G10 no outbound tcp/25
[✓] G13 no dns/memcached amplification
[✓] G14 relays can't widen egress

● AMBERCELL × CHN — you found one piece of the network

AmberCell runs perfectly as a standalone box — but it's part of Cyber Halluci Net (CHN), our security-research collective. The perfect complete free deception suite.

> try CHN at cyberhallucinet.org_

ready in ~30 seconds on a laptop — no public IP required for the lab.