HoneyShark places imitation industrial equipment on your control network and records everything that touches it. The equipment has no production role, so contact with it is worth investigating.
Every decoy is reproduced from packet captures of real industrial equipment, so it responds the way genuine devices do. Built and supported by EEHA Automation's IT/OT and PCS team.
An attacker who reaches the plant network will look for controllers and operator stations, map what is there, then attach engineering software. That traffic looks normal and usually passes unnoticed.
Most control networks carry no security monitoring, so scanning goes unnoticed.
Industrial equipment cannot run security software, and production traffic must not be disturbed.
IT security tools report protocol errors, not what somebody tried to do to a controller.
The main capabilities of a HoneyShark appliance.
Each decoy is reproduced from packet captures of the real equipment collected from over a decade of control systems engineering.
Industrial protocols and device services answer as the genuine unit does with support for a variety of OT protocols.
Detects device enumeration and engineering sessions from crafted scripts and commercial engineering software.
Honeyshark is not just a packet scanner. It scans for patterns in bursts of packets to report a single event to operators.
Every event carries the source address, the hardware address and the vendor behind it.
A non-invasive standalone device on your network. Runs passively without connection to the internet.
One dashboard showing who touched the decoys, what they attempted and how serious it is.
Adds detection to a network that has no security tools of its own.
One appliance runs several decoys, and more can be added as the network grows.
Scanning and browsing happen long before anything is changed on real equipment.
Decoys use their own addresses and do not interact with real equipment.
Each event names the source, the software used and what it attempted to do.
Every packet a decoy receives is recorded. Packets that belong to one action are grouped together, given a plain description and a severity, then shown on the dashboard.
Give the appliance one address on the control network you want to watch.
Choose which devices to imitate, their addresses and their identities, from the dashboard.
Decoys appear on the network with vendor hardware addresses and answer like the real equipment.
Any contact is captured, classified and raised on the dashboard, with an email alert if you want one.
Tell us about your site and what you need to protect.
See how a honeypot exposes reconnaissance on a live control network.
1800 433 422
sales@eehaa.com.au
Level 4, 451 St Pauls Terrace, Fortitude Valley, QLD 4006
Unit 14, 49 Shore St West, Cleveland, QLD 4163
Unit 2, 100 Terrace Road, East Perth, WA 6004
PO Box 1854,Emerald, QLD 4720