Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
Headscale serves as an open-source, self-managed version of the control server utilized by the Tailscale network, allowing users to maintain complete ownership of their private tailnets while employing Tailscale clients. It offers capabilities for registering users and nodes, generating pre-authentication keys, advertising subnet routes and exit nodes, enforcing access controls, and integrating with identity providers like OIDC/SAML for user authentication. The server can be deployed using Debian/Ubuntu packages or as standalone binaries and is configurable through a YAML file, with management options available via its command-line interface or REST API. Headscale maintains a comprehensive database that tracks each node, route, and user, supports workflows for route approvals, and offers features such as subnet routing, the designation of exit nodes, and direct node-to-node connections within the tailnet. By being self-hosted, it empowers organizations and enthusiasts to retain complete control over their private network endpoints, encryption keys, and traffic flows, eliminating reliance on a commercial control plane. This level of control not only enhances security but also provides flexibility for users to customize their networking solutions according to their specific needs.
Description
Engineered entirely in Go, HoneyWire delivers a self-hosted, open-source deception engine that identifies post-exploitation and lateral movement without the heavy footprint of commercial enterprise software. Using an intuitive Terminal UI (TUI) wizard, security teams and sysadmins can rapidly distribute distroless, lightweight canary tripwires across any Linux environment in a matter of seconds.
Our detection model guarantees an absolute zero false-positive rate. Because every HoneyWire sensor operates as a strictly synthetic decoy, they possess no actual business utility. Consequently, any network interaction with these endpoints is a guaranteed indicator of compromise whether from a rogue internal script, a breached CI/CD pipeline, or a live adversary.
The platform ships with a growing arsenal of ready-to-deploy traps:
- TCP Canary Tarpits: Occupy attractive network ports to capture malicious payloads and bog down automated enumeration tools.
- Fake Web Routers: Mimic administrative dashboards to snare HTTP-focused reconnaissance.
- Honeytoken File Canaries: Covert file integrity monitors that trigger the instant an attacker reads or scrapes sensitive decoy directories.
- Network & ICMP Sensors: Unmask stealthy subnet discovery and ping sweeps before hostile actors can map your production assets.
(Expect new trap types in upcoming releases!)
Fleet configuration and node telemetry are centrally orchestrated by the HoneyWire Hub a secure, fully private control server. To seamlessly integrate with your existing EDR or SIEM infrastructure, the Hub dispatches dynamic alerts through standard Syslog, alongside native push notification support for Slack, Discord, Gotify, and Ntfy.
API Access
Has API
Yes
API Access
Has API
No
Pricing Details
Free
Free Trial
No
Free Version
Yes
Pricing Details
Free
Free Trial
No
Free Version
Yes
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
Yes
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
Yes
Chromebook
No
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Vendor Details
Company Name
Juan Font
Country
Netherlands
Website
headscale.net/stable/
Vendor Details
Company Name
HoneyWire
Country
Italy
Website
honeywire.dev