DShield Sensor
SANS Internet Storm Center's honeypot sensor for contributing threat data, with an ELK dashboard
DShield Sensor has no official, structured tool listing we can auto-sync (unlike Kali, BlackArch, REMnux, and Tails). The tools below are maintained by hand and may be incomplete or outdated — check the official docs for the current tool set.
Last verified September 5, 2026
DShield Sensor is a lightweight honeypot built to contribute real attacker traffic to SANS ISC’s DShield threat-intelligence project, positioned differently from the full-scale, locally-analyzed platform T-Pot already covers in this catalog — smaller footprint, single honeypot (Cowrie), and centralized reporting to a third party by default.
Use it only on infrastructure you own or are explicitly authorized to expose — see the disclaimer.
Notable bundled toolsmanually maintained
Getting started
DShield Sensor installs via the official script onto a Raspberry Pi (running Raspberry Pi OS) or an Ubuntu 24.04/26.04 LTS host. It runs the Cowrie honeypot underneath to log attacker activity against the sensor and forwards that data to SANS ISC's DShield project for aggregate threat-intelligence research. The separate, community-run DShield-SIEM project adds a local Elastic Stack dashboard so you can review your own sensor's data directly instead of only contributing it upstream.