Skip to main content
The trap command deploys lightweight honeypot services that mimic real network services (SSH, HTTP, SMB, and more). When an attacker interacts with a trap, Panguard captures their tactics, generates threat intelligence, and alerts you immediately.

Usage

Subcommands

Options

--services
string
Comma-separated list of honeypot service types to deploy. Options include ssh, http, smb, ftp, mysql, redis, rdp.
--data-dir
string
Override the default directory for trap logs and intelligence data. Defaults to ~/.panguard/trap/.
--no-cloud
flag
Keep all captured intelligence local — do not upload to the Panguard Threat Cloud.

Examples

Supported Honeypot Services

Honeypot ports are intentionally offset from standard ports to avoid conflicts with real services. You can customize port mappings in the trap configuration.

Honeypots Guide

Step-by-step guide for deploying and managing honeypots.

Trap Product Overview

Architecture and design of the Trap deception system.

Attacker Profiling

How Panguard builds attacker profiles from trap data.

panguard threat

Run a local Threat Cloud server for intelligence aggregation.