FortiDeceptor decoys
FortiDeceptor creates a network of decoys to lure attackers and monitor their activities on the network. When a hacker attacks a decoy, an alert is generated and their malicious activities are captured and analyzed in real-time. This analysis generates a mitigation and remediation response that protects the network.
The current FortiDeceptor decoy OS are:
Windows |
Windows 7, Windows 10, Windows 2016 and Windows 2019 |
Linux |
Ubuntu Desktop, CentOS |
IoT/OT |
SCADA version 3, Medical OS, and IoT OS. |
VPN |
Fortinet SSL-VPN (FG-60E, FG-100F, FG-1500D, FG-2000E, FG-3700D) |
Customized Windows |
Windows 10, Windows Server 2016, Windows Sever 2019 |
The current FortiDeceptor application decoys PACS are:
IoT/OT |
POS OS, ERP OS PACS and SAP |
The current FortiDeceptor lure services are:
Windows |
RDP, SMB, TCPListener and NBNSSpoofSpotter and ICMP |
Linux | |
IoT/OT |
HTTP, FTP, TFTP, SNMP, MODBUS, S7COMM, BACNET, IPMI, TRICONEX, ENIP, Kamstrup, DNP3, Telnet, PACS-WEB, PACS, DICOM server, Infusion Pump (TELNET), Infusion Pump (FTP), POS-WEB, ERP-WEP, GUARDIAN-AST, IEC104, Jetdirect, Printer-WEB, IP Camera-WEB, UPnP, RTSP, CDP, TP-link WEB, CWMP, SAP DISPATCHER and SAP WEB |
SSL VPN |
HTTPS |
Customized Windows |
RDP, SMB, NBNSSpoofSpotter, MSSQL IIS (HTTP/HTTPS) and ICMP |
The current FortiDeceptor IP address capacity are:
- A single FDCIKF can host up to 16 deception VMs.
- A single FDCIKG can host up to 20 deception VMs.
- A single FDCVMS can host up to 20 deception VMs.
- A single deception VM supports up to 24 IP addresses or decoys. Each IP represents a decoy.
- A single FortiDeceptor appliance (HW/VM) can support up to 480 IP addresses.
- A single FortiDeceptor appliance (HW/VM) can support up to 128 segments (VLANS).
VPN only supports 8 IPs. Cisco Decoy only supports 1VLAN. |
Decoy services details
IoT OS
Brother MFC Printer Decoy
Service |
Description |
---|---|
SNMP |
|
Jetdirect |
Enable this service to open port 9100 on the decoy VM and respond to PJL (Printer Job Language) requests. |
Printer-WEB |
A web GUI that simulates the administration GUI of Brother NC-340h printer. |
Cisco router decoy
Service |
Description |
---|---|
Models |
4 Cisco images (models) are supported: 2691, 3660, 3725 and 3745. An error is displayed if you upload an image that is not supported. |
Router Running-Config (optional) |
Allows you to upload a customized Cisco config file to predefine the Cisco router setting |
Telnet service |
A login-required service that enables attackers to utilize all Cisco router functions. |
HTTP service |
A login-required GUI service similar to the telnet service but with less functionality. |
SNMP service |
|
CDP service |
Enable this service to allow the decoy VM to send CDP traffic within the network. |
HP printer decoy
Service |
Description |
---|---|
SNMP service |
|
Jetdirect |
|
Printer-WEB |
|
IP camera decoy
Service |
Description |
---|---|
IP Camera-WEB |
|
SNMP service |
|
UPnP service |
|
RTSP service |
Example: To infinitely loop a video: From the attacker perspective, the live camera stream is available at |
Lexmark Printer decoy
Service |
Description |
|
---|---|---|
SNMP |
|
|
Jetdirect |
|
|
Printer-WEB |
A web GUI that simulates the administration GUI of Lexmark MX410de printer. |
TP-LINK decoy
Service |
Description |
---|---|
TP-LINK WEB |
Enable this service to allow attackers to login to a fake TP-link setting site. |
CWMP |
Enable this service to send data using CWMP protocol to {ip}:{port}/cpe. |
Medical
Service |
Description |
---|---|
Infusion Pump (Telnet) service |
|
Infusion Pump (FTP) |
|
PACS service |
|
PACS-WEB service |
|
DICOM Server service |
|
POS
Service |
Description |
---|---|
POS-WEB service |
|
CRM(ERP)
Service |
Description |
---|---|
ERP-WEB service |
|
SAP
Service |
Description |
---|---|
SAP ROUTER |
|
SAP DISPATCHER |
|
SAP WEB |
A fake SAP HTTP and HTTPS GUI for SAP Fiori Launchpad or Legacy WebGUI. |
SCADA (version3) OS
Ascent Compass MNG decoy
Service |
Description |
---|---|
HTTP service |
|
FTP service |
|
SNMP service |
|
BACNET service |
|
Guardian-AST decoy
Service |
Description |
---|---|
Guardian-AST service |
IPMI Device decoy
Service |
Description |
---|---|
HTTP service |
|
SNMP service |
|
FTP service |
|
IPMI service |
|
KAMSTRUP 382 decoy
Service |
Description |
---|---|
KAMSTRUP service |
|
Liebert Spruce UPS decoy
Service |
Description |
---|---|
TFTP |
Enable this to service capture attacks through TFTP on default TFTP port |
SNMP |
|
HTTP |
Enable this service to capture attacks through HTTP on default HTTP port. |
Niagara4 Station decoy
Service |
Description |
---|---|
SNMP |
|
HTTP |
Enable this service to capture attacks through HTTP on default HTTP port. |
BACNET |
Enable this service capture attack through BACNET on default BACNET port. |
NiagaraAX Station decoy
Service |
Description |
---|---|
SNMP |
|
HTTP |
Enable this service to capture attacks through HTTP on the default HTTP port. |
BACNET |
Enable this service capture attacks through BACNET on the default BACNET port. |
PowerLogic ION7650 decoy
Service |
Description |
---|---|
SNMP |
|
MODBUS |
Enable this service capture attacks through MODBUS on the default MODBUS port. |
DNP3 |
Enable this service capture attacks through DNP3 on the default DNP3 port. |
HTTP |
Enable this service to capture attacks through HTTP on the default HTTP port. |
Rockwell 1769-L16ER/BLOGIX5316ER decoy
Service |
Description |
---|---|
SNMP |
|
ENIP |
Enable this service to capture attacks through ENIP on the default ENIP port. |
HTTP |
Enable this service to capture attacks through HTTP on the default HTTP port. |
Rockwell 1769-L35E Ethernet Port decoy
Service |
Description |
---|---|
SNMP |
|
ENIP |
Enable this service to capture attacks through ENIP on the default ENIP port. |
HTTP |
Enable this service to capture attacks through HTTP on the default HTTP port. |
Rockwell PLC decoy
Service |
Description |
---|---|
HTTP service |
|
TFTP service |
|
SNMP service |
|
ENIP service |
|
Schneider EcoStruxure BMS server decoy
Service |
Description |
---|---|
SNMP service |
|
BACNET service |
|
HTTP service |
|
TRICONEX service |
|
Schneider Power Meter - PM5560 decoy
Service |
Description |
---|---|
SNMP service |
|
BACNET service |
|
HTTP service |
|
DNP3 service |
|
ENIP service |
|
Schneider SCADAPack 333E decoy
Service |
Description |
---|---|
SNMP service |
|
DNP3 service |
|
Telnet service |
|
Siemens S7-200 PLC decoy
Service |
Description |
---|---|
HTTP service |
|
TFTP service |
|
SNMP service |
|
MODBUS service |
|
S7COMM service |
|
Siemens S7-300 PLC decoy
TFTP service |
|
SNMP service |
|
IEC104 service |
|
VAV-DD BACNET controller decoy
Service |
Description |
---|---|
SNMP service |
|
BACNET service |
|