OpenCanary is free, self-hosted software that acts as a network honeypot: it imitates services and alerts when someone interacts with them after entering a non-public network. It runs as a daemon and can report a source IP address and a possible breach location. Its service modules include SSH, FTP, Git, web services, databases, Telnet, SNMP, SIP, VNC, Redis, TFTP, NTP and TCP banners. Alerts can go to files, Syslog, email, HTTP webhooks, Slack, Microsoft Teams or HPFeeds-compatible daemons. Webhooks support GET, POST and PUT. The companion opencanary-correlator can combine related events, such as repeated login attempts, into one email or SMS alert. The project describes its resource requirements as very low, with use on a Raspberry Pi or a minimally resourced virtual machine. Documentation covers Ubuntu and macOS installation and Docker deployment on Linux hosts. Linux has the broadest options: SMB monitoring is unavailable on macOS, and portscan monitoring is Linux-only and disabled in Docker. The configuration file should be root-owned and writable only by root because it is read with root privileges.
Who it is for
It suits administrators who want a self-hosted way to detect interactions with decoy network services and route alerts to their chosen destinations. Linux deployments have the most module options.
What is good
- Imitates a broad range of network services.
- Supports email, Syslog, webhooks and chat alerts.
- Correlator groups related events into one alert.
- Can run on a Raspberry Pi.
- Free plan: 0.00 USD per free.
What to know first
- SMB monitoring is unavailable on macOS.
- Portscan monitoring is Linux-only.
- Portscan monitoring is disabled in Docker.
- Configuration must be writable only by root.
Verdict
OpenCanary offers a range of decoy services and alert routes for self-hosted network monitoring. Review platform and module limits, and secure its root-read configuration file.
OpenCanary plans and pricing
All plansCompared on honeypot software
- Free plan
- Yes
- Deployment model
- self-hosted
- Decoy scope
- network
- Credential lures
- Yes


