Responses
Answer with AI
Emulated shell/HTTP/VFS slots (shell.stdout,
http.index_body, …). Policy still validates every byte.
Fail-closed decoy sensor
The CyberHalluciNet Decoy Engine is an attacker-facing sensor fabric: multi-protocol surfaces that use constrained AI to stay believable, engage adversaries longer, and feed CTI, while fail-closed policy keeps models and attackers from gaining real authority.
What the A.I Honeypot can do with a constrained broker: and where to learn each skill.
Responses
Emulated shell/HTTP/VFS slots (shell.stdout,
http.index_body, …). Policy still validates every byte.
Data fills
Redis, SQL, Mongo, Elasticsearch bait via schema-bound seeds
(*-ai-seed=1) on Emulated Listen surfaces.
Camera
Optional Ollama scene JPEG pool for App-webs / ISAPI snapshots
(CYBERHALLUCINET_HTTP_HIKVISION_AI_IMAGE=1).
MODE=ai + broker UDS, then choose an adapter
(static_stub → ollama / hosted).
Full path:
A.I Honeypot tutorials.
Operator-selected, fail-closed, strictly additive.
Contained · default
Multi-service synthetic decoys. No real shell. No attacker egress. Fastest, safest default.
Emulated
Rich synthetic FS + schema-bound AI fills and replay. Still no real OS command authority.
Live · ack-gated
Sandboxed proxy to disposable guests (MicroVM / pool). Real execution only after signed ack.
Full sensor listen surface (opt-in, empty = off, fail-closed by default). Yes: mail, DHCP, Windows, cloud, and OT faces are included.
Listeners are enabled per address flag / YAML (for example
--listen-smtp, --listen-pop, --listen-dhcp).
Additional persona packages and lab faces can extend realism; OT listeners share a
unified device persona for coherent CTI correlation.
Choose AI posture, placement, and industry pack.
From package to Ops UI in about ten minutes. Compose-only path if you prefer containers first.
make ops-web build./bin/ops-gui -doctor127.0.0.1:3080make research-upmake research-self-testmake research-down when finishedA Helm chart scaffold for sensor deploy is included for Kubernetes trials. Live / MicroVM paths need extra ack and host prerequisites.
# From your CyberHalluciNet lab package root:
make ops-web build
./bin/ops-gui -doctor
CYBERHALLUCINET_REPO_ROOT="$PWD" ./bin/ops-gui -addr 127.0.0.1:3080
# open http://127.0.0.1:3080/ → Setup (Intel + Detection) → Launch → Investigate / Manage
Docs: Install lab · interactive tutorials · Back to platform overview
Learn by doing
Pick a learning path. Steps are ordered the same way as the in-repo Diátaxis tutorials. Progress is saved in this browser; open each tutorial here when you are ready.
Answers
The A.I. Decoy Engine is CyberHalluciNet’s attacker-facing sensor fabric. It exposes multi-protocol decoy surfaces that use constrained AI to stay believable, engage adversaries longer, and feed CTI, while fail-closed policy keeps models and attackers from gaining real authority over execution or egress.
Three tiers: Contained (low-interaction synthetic Listen), Emulated (medium-interaction with schema-bound AI fills and richer personas), and Live (high-interaction, acknowledgment-gated proxy into disposable guest backends). Contained and Emulated never execute real attacker OS commands on the host.
Start on loopback with the beginner lab or Make the A.I. Decoy Engine tutorial. Use Docker Compose or Helm for isolated staging. Do not Internet-bind research profiles by default. Live / MicroVM paths require signed acknowledgment and burnable, network-isolated guests before any higher-risk engagement.