HoneyDrop is a powerful appliance designed to enhance your network's security by setting up decoy services that attract and distract attackers. When deployed within your internal network, it tricks cybercriminals into targeting these fake services instead of your real assets, giving you a crucial edge in detecting and understanding potential threats.
HoneyDrop logs every interaction with its decoys to AWS CloudWatch, delivering real-time visibility into suspicious activity. Alerts can be sent via Discord, Microsoft Teams, or Slack, enabling rapid response to threats. You can also configure CloudWatch alarms to trigger Lambda functions for automated incident handling.
Highlights
Lure attackers away from high value systems long enough to be identified
Instant notifications of honeypot interactions via Slack, Discord and Microsoft Teams
Enable automated incident response actions to isolate and quarantine compromised hosts
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 5 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay HoneyDrop by the hour, and the rate depends on the EC2 instance type you choose to run the honeypot appliance. The 15 options map to general-purpose instance sizes across the t2, t3, and t3a families, ranging from nano up to xlarge. Larger sizes carry more compute capacity, so hourly software cost scales with the instance you pick. You select one instance type per deployment. This software fee is separate from the underlying AWS EC2 and CloudWatch charges, which you pay at standard AWS rates.
Top-of-mind questions for buyers
Am I charged the hourly software fee when the honeypot instance is stopped?
The software fee meters running instance time. A fully stopped instance does not accrue the hourly software charge. Stopped instances may still incur standard AWS storage fees for the attached disk volume, which are separate from the HoneyDrop software fee.
What does the hourly rate cover, and what other charges apply?
The hourly rate is the HoneyDrop software fee for one running EC2 instance. You also pay standard AWS rates for the underlying EC2 compute and for CloudWatch usage. These AWS charges are billed separately from the software fee and appear alongside it.
If I deploy HoneyDrop across several subnets or regions, how does billing scale?
HoneyDrop runs as a single EC2 instance per deployment. You can launch as many instances as you need across any VPC or region. Each running instance bills its own hourly software fee based on its chosen instance type, so total cost scales with instance count.
salientengineering.com
Helpful?
Vendor refund policy
Refunds considered on a case-by-case basis.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Quick and Simple HoneyDrop Configuration and Deployment
This AWS CloudFormation template deploys HoneyDrop, a configurable honeypot appliance designed to attract and monitor unauthorized access attempts across multiple network protocols. It provisions an EC2 instance with integrated AWS Secrets Manager for managing alerting (Slack, Discord, Microsoft Teams) and service configuration, and uses IAM roles to securely grant access to required resources.
Key features:
Deploys in your VPC and subnet of choice
Supports over a dozen honeypot services including SSH, FTP, HTTP, MySQL, Redis, RDP, Telnet, and more
Centralized configuration via CloudFormation parameters and Secrets Manager
Auto-updating appliance with structured alerting
Includes security group configuration for all enabled protocols
Management access via port 2222 with configurable CIDR restrictions
Ideal for security research, deception environments, or threat intelligence collection in cloud-based networks.
CloudFormation Template (CFT)
AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."
Version release notes
Production-Ready Honeypot Appliance Release
Streamlined Deployment: All configuration is now handled during the initial CloudFormation deployment, no post-deployment setup required.
Centralized Alert Management: Alert settings for Slack, Microsoft Teams, and Discord, as well as service enablement/disablement, are now managed through AWS Secrets Manager.
Improved Alerting: Alerts are now consistently formatted for better readability.
Auto-Updating Enabled: The appliance now supports automatic updates to ensure you're always running the latest version.
Additional details
Usage instructions
Template components
CloudFormation template
Usage instructions
Enter the required parameters in the CloudFormation stack
Slack, Discord, and Teams alerting is optional
Set the desired honeypot services to true
Once deployed, edit services and configure alerts as desired by modifying the HoneyDrop secret in Secrets Manager
We offer responsive and friendly support available to all HoneyDrop customers. Just reach out to us via email at: support@salientengineering.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.