👻 Deception Intelligence · Real Honeypot

PHANTOM CORE™
A Real Honeypot That
Logs Real Attackers

Runs a real honeypot service on your server. Logs every genuine connection attempt from real attackers — their IP, method, path, and user agent. See exactly who is probing your infrastructure and what they are looking for.

See Live Attacker Log →
RealAttacker Data
LiveConnection Log
AutoAlways Running
AUYour Server
What PHANTOM CORE™ Actually Does Right Now

Honest Breakdown — A Real Honeypot,
Real Attacker Intelligence

✅ Working Right Now
  • Runs a real HTTP honeypot service on port 3066 of your server — always on, always listening
  • Logs every real connection attempt with IP address, HTTP method, requested path, and user agent
  • Presents a convincing fake login page to keep attackers engaged and gather intelligence
  • Sends all attacker activity to the real-time operations dashboard instantly via WebSocket
  • Stores all honeypot hits with timestamps — downloadable as JSON via API
  • Works autonomously — no management required once deployed
◦ Being Built — Not Yet Available
  • Full phantom infrastructure replication (phantom servers, databases, file shares)
  • Multi-port honeypot deployment across 247+ asset types
  • Automated attacker profiling and TTP classification
  • Phantom credential sets that trigger alerts when used
🪤
Real HTTP Honeypot
A genuine web service that attracts and logs attackers. Presents fake login pages to maximise attacker engagement and intelligence gathering.
✓ Live Now
📋
Attacker IP Logging
Every connection attempt logged with real IP address, timestamp, HTTP method, path requested, and full user agent string.
✓ Live Now
Real-Time Dashboard
Every honeypot hit appears on the operations dashboard instantly via live WebSocket connection. No polling, no delay.
✓ Live Now
🔗
AEGIS CORTEX Integration
Honeypot IPs can be immediately blocked via the AEGIS CORTEX auto-respond feature directly from the dashboard.
✓ Live Now
👻
Phantom Infrastructure
Full replica of your real infrastructure — phantom servers, databases, file shares — making your real assets invisible.
◦ Coming Soon
🔬
TTP Classification
Automated classification of attacker techniques, tactics, and procedures mapped to the MITRE ATT&CK framework.
◦ Coming Soon
How It Works

Your Server Is Already Being Probed.
Now You Can See Who.

Every server on the internet receives automated probing within minutes of going online. PHANTOM CORE™ turns that into actionable intelligence.

🌐
Attacker Scans
Automated bots and real attackers probe your server looking for open services and vulnerabilities
🪤
Honeypot Intercepts
PHANTOM CORE™ answers on port 3066 with a convincing fake service instead of your real applications
📋
Intelligence Logged
IP, method, path, user agent, and timestamp captured for every connection — building attacker profiles
🛡️
You Act
Block the IP via AEGIS CORTEX, report it to threat feeds, or simply monitor the intelligence data
Pricing

Honest Pricing for What
Actually Works Today.

All prices AUD excl. GST. Priced for current honeypot functionality.

Basic
Single honeypot + dashboard
A$39/mo
excl. GST · cancel anytime
  • 1 honeypot service
  • Full attacker logging
  • Real-time dashboard
  • JSON export via API
  • Email support
Enterprise
Custom deployment
A$249/mo
excl. GST · 12-month term
  • Unlimited honeypot services
  • Everything in Professional
  • Custom port configuration
  • Dedicated instance
  • Onboarding support
  • All future features included