Deploy a hardened deception honeypot in minutes. OpenCanary by AdvanceCo provides early warning alerts for unauthorized network lateral movement and breach detection within your AWS VPC using low-interaction digital decoys.
Enterprise Deception Technology: Detect Intruders with Digital Decoys
Perimeter security is not enough. AdvanceCo Inc provides a production-hardened deployment of OpenCanary, a powerful open-source deception tool designed to catch hackers who have already bypassed your firewall.
OpenCanary acts as a silent sentry within your network. By mimicking common services like file servers, databases, or web portals, it creates a digital landmine. Because legitimate users have no reason to access these decoys, any interaction is a high-probability indicator of a security breach or malicious lateral movement.
Key Features:
Versatile Service Emulation: Configure your canary to look like a Linux server, a Windows workstation, or a network device to fit your environment.
Low Interaction Design: Provides maximum security with minimal risk, as the services are emulated rather than fully functional.
Streamlined Alerting: Logs are formatted for easy ingestion into AWS CloudWatch, S3, or third-party SIEM platforms.
Cloud-Native Optimization: Specifically tuned for the AWS Nitro System and optimized for Ubuntu 22.04 LTS for maximum uptime.
The AdvanceCo Advantage:
Our Raleigh-based engineering team removes the complexity of managing honeypots. By choosing our supported AMI, you receive:
Automated Maintenance: We handle the critical security updates and software patches.
Deployment Stability: Pre-configured defaults designed for enterprise VPC environments.
Professional Assistance: Access to technical support for configuration and alerting logic.
Ideal Use Cases:
Internal Threat Detection: Identify rogue employees or compromised accounts moving through your internal network.
Ransomware Early Warning: Catch automated scanners as they look for vulnerable network shares.
Post-Breach Analysis: Gain valuable intelligence on attacker techniques and intended targets.
Highlights
Multi-Service Deception: Mimic high-value targets including SSH, FTP, Telnet, HTTP, and SQL services to lure and identify attackers.
Instant Breach Detection: Receive real-time notifications the moment an unauthorized user interacts with a decoy service.
Lightweight and Hardened: Optimized for minimal resource consumption, allowing for cost-effective deployment across multiple subnets.
Compliance Support: Meets essential monitoring and logging requirements for SOC 2, PCI DSS 4.0, and HIPAA.
AdvanceCo Managed Support: Includes regular security patching for the Ubuntu kernel and OpenCanary binaries from our US-based team.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 5 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour based on the EC2 instance size you run this honeypot software on. Pricing scales with compute capacity. The smallest options are burstable general-purpose types like t2.nano, t3.nano, t2.micro, and t3.micro. Mid-range choices include the m5, m6i, m7a, m7i, and m7i-flex families. The m8i, m8id, and m8i-flex families offer larger sizes, up to 96xlarge and bare-metal metal-48xl and metal-96xl configurations. As you move to instances with more vCPUs and memory, the hourly rate rises. No upfront commitment applies.
Top-of-mind questions for buyers
What do I actually get with each hourly instance option?
Each option runs the OpenCanary honeypot software on an Ubuntu 22.04 EC2 instance of the size you pick. Larger instance names (more vCPUs and memory) run one virtual machine each. The metal-48xl and metal-96xl types run on dedicated bare-metal hardware rather than shared virtualized hosts.
Am I charged when the instance is stopped or powered off?
Hourly software charges apply only while the instance runs. A stopped instance stops accruing the hourly software rate. You may still pay underlying AWS storage fees for the attached volume, but the software meters running hours only. No upfront commitment applies.
How does the hourly billing differ from committing for a longer term?
The hourly option meters actual instance-hours with no upfront commitment. You pay only for the hours the instance runs, and the rate rises with instance size. This suits variable or short-lived deployments where you start and stop the honeypot as needed rather than running it continuously.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
AdvanceCo Inc provides professional support for this product.
Standard: Email support with a response within 24 hours.
Premium: Dedicated Slack channel and 4-hour SLA for critical issues.
Phone, email, and remote hands on available secproductsupport@advancecoinc.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Deploy a hardened deception honeypot in minutes. OpenCanary by AdvanceCo provides early warning alerts for unauthorized network lateral movement and breach detection within your AWS VPC using low-interaction digital decoys.
Deploy a hardened deception honeypot in minutes. OpenCanary by AdvanceCo provides early warning alerts for unauthorized network lateral movement and breach detection within your AWS VPC using low-interaction digital decoys.
Security Onion is a free and open platform built by defenders for defenders. It includes network visibility, host visibility, intrusion detection honeypots, log management, case management, and much more.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.