Listing Thumbnail

    OpenCanary Honeypot on Ubuntu (Hourly) by AdvanceCo

     Info
    Deployed on AWS
    Free Trial
    AWS Free Tier
    OpenCanary honeypot on a hardened Ubuntu 24.04 LTS AMI. Run low-interaction decoy services such as SSH, FTP, HTTP, RDP and MySQL inside your VPC and get alerted when anything connects to them. Maintained by AdvanceCo with US-based email support.

    Overview

    OpenCanary is an open-source, low-interaction honeypot from Thinkst Applied Research. It runs decoy network services that look real to an attacker but serve no legitimate purpose, so any connection to them is a strong signal of reconnaissance or lateral movement. This AMI from AdvanceCo packages OpenCanary on Ubuntu 24.04 LTS so you can place decoys in your AWS environment in minutes.

    What is included

    • OpenCanary installed and ready to configure
    • A default configuration file at /etc/opencanaryd/opencanary.conf
    • A systemd service that starts OpenCanary at boot
    • A hardened image with no SSH keys or shell history carried over from the build

    Decoy services you can enable SSH, FTP, Telnet, HTTP and HTTPS, MySQL, Microsoft SQL Server, RDP, VNC, SIP, TFTP, NTP, Redis, Git and port-scan detection. Choose which services to emulate and how they identify themselves so each decoy blends into your network.

    Alerting OpenCanary writes a structured JSON event for every interaction. Send events to syslog or to a log file shipped to Amazon CloudWatch Logs or your SIEM, or configure OpenCanary's built-in email and webhook handlers.

    Common uses

    • Detect lateral movement and internal reconnaissance after an initial compromise
    • Spot compromised credentials or misused accounts probing internal services
    • Add a low-cost, low-noise detection layer alongside network monitoring and endpoint tools

    Maintenance and support AdvanceCo publishes updated versions of this AMI with current Ubuntu security patches and OpenCanary releases. Included support is by email during US business hours from our US-based team. Paid support with Slack, phone and response-time commitments is available on request.

    Getting started Launch the AMI in the subnet you want to monitor and connect over SSH as the ubuntu user. Edit /etc/opencanaryd/opencanary.conf to enable decoy services and an alert destination, then restart the opencanary service. Open only the decoy service ports in the instance security group.

    Highlights

    • Low-interaction decoys: emulate SSH, FTP, HTTP, MySQL, RDP and more without exposing real services or data.
    • High-signal alerting: legitimate users have no reason to touch a decoy, so alerts are rare and actionable. JSON events work with syslog, CloudWatch Logs or your SIEM.
    • Maintained by AdvanceCo: hardened Ubuntu 24.04 LTS image with OpenCanary running as a systemd service, plus US-based email support.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Ubuntu 24.04

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free for 5 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.

    OpenCanary Honeypot on Ubuntu (Hourly) by AdvanceCo

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.
    If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier  for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier  for more details.

    Usage costs (50)

     Info
    Dimension
    Cost/hour
    t3.small
    Recommended
    $0.03
    t3.micro
    $0.03
    t2.micro
    $0.03
    m8i.48xlarge
    $0.03
    m5.large
    $0.03
    m8i.24xlarge
    $0.03
    m8i-flex.8xlarge
    $0.03
    m8i-flex.large
    $0.03
    m7i-flex.large
    $0.03
    m8i.12xlarge
    $0.03

    AI Insights

     Info

    Dimensions summary

    You pay by the hour for the EC2 instance size you run OpenCanary on. Each dimension maps to one AWS instance type, so pricing scales with the compute you select. Smaller burstable types (t2, t3) suit light testing. General-purpose families (m5, m6i, m7i, m7a, m8i, m8id) span from large up to very large multi-core and bare-metal (metal) options. The m8i-flex and m7i-flex types offer flexible general-purpose compute. The software rate is identical in function across all sizes; only the hourly charge changes with instance capacity. No commitment is required.

    Top-of-mind questions for buyers

    Each dimension bills one running EC2 instance of that size, charged per hour. The rate covers the OpenCanary software plus the underlying compute capacity of that instance type. Larger instance types carry more vCPUs and memory, so their hourly charge is higher. You pick the size that fits your workload.
    Hourly software charges apply only while the instance runs. A fully stopped instance stops accruing the software rate. Note that stopped instances may still incur underlying AWS storage fees for attached volumes, which are separate from this listing's software charge.
    The hourly option meters actual running time with no upfront commitment. You pay only for the hours each instance runs. This suits testing or short-term honeypot deployments. Continuous, always-on deployments may fit the vendor's annual or monthly pricing instead, which this hourly listing does not include.
    www.advancecoinc.com
    Helpful?

    Vendor refund policy

    No Refunds. Software supplied as is

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    OpenCanary 0.9.10 on Ubuntu 24.04 LTS, with all Ubuntu security updates available on 2026-10-05 applied. Built by AdvanceCo's automated image pipeline: the image is hardened (root password locked, no SSH keys, shell history or cloud-init state from the build) and tested before release, including a check that the service starts at boot, runs as an unprivileged user and logs decoy interactions as JSON.

    Additional details

    Usage instructions

    Connect over SSH as the ubuntu user. OpenCanary runs as the opencanary service with only the FTP decoy (TCP 21) enabled. Edit /etc/opencanaryd/opencanary.conf to enable decoys and an alert destination, then run 'sudo systemctl restart opencanary'. Events are logged as JSON to /var/tmp/opencanary.log and the systemd journal. The recommended security group allows SSH and FTP only from 10.0.0.0/8; open the ports of any decoys you enable. Support: secproductsupport@advancecoinc.com 

    Resources

    Support

    Vendor support

    Included support: email support from AdvanceCo's US-based engineering team during US business hours at secproductsupport@advancecoinc.com . Paid support options, including Slack, phone and response-time commitments, are available on request. More information:

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.