Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

DShield Sensor

SANS Internet Storm Center's honeypot sensor for contributing threat data, with an ELK dashboard

specializedbased on Raspberry Pi OS or UbuntuBlue Team

DShield Sensor has no official, structured tool listing we can auto-sync (unlike Kali, BlackArch, REMnux, and Tails). The tools below are maintained by hand and may be incomplete or outdated — check the official docs for the current tool set.

Official docs ↗Download ↗Source repo ↗

Last verified September 5, 2026

DShield Sensor is a lightweight honeypot built to contribute real attacker traffic to SANS ISC’s DShield threat-intelligence project, positioned differently from the full-scale, locally-analyzed platform T-Pot already covers in this catalog — smaller footprint, single honeypot (Cowrie), and centralized reporting to a third party by default.

Use it only on infrastructure you own or are explicitly authorized to expose — see the disclaimer.

Notable bundled toolsmanually maintained

cowrie

cowrie honeypot, bundled with T-Pot's multi-honeypot platform.

Getting started

DShield Sensor installs via the official script onto a Raspberry Pi (running Raspberry Pi OS) or an Ubuntu 24.04/26.04 LTS host. It runs the Cowrie honeypot underneath to log attacker activity against the sensor and forwards that data to SANS ISC's DShield project for aggregate threat-intelligence research. The separate, community-run DShield-SIEM project adds a local Elastic Stack dashboard so you can review your own sensor's data directly instead of only contributing it upstream.