Object First Honeypot Demo with Geoff Burke
Senior Technology Advisor Geoff Burke showcases the integrated honeypot functionality built into the Object First appliance. Designed as a digital tripwire, the honeypot is physically hosted on the appliance but logically segmented to ensure security. It serves as an early warning system to detect lateral movement and reconnaissance efforts by attackers who typically probe the network to identify high-value targets. By mimicking juicy targets like a Veeam Windows Repository or SQL Server, the honeypot lures hackers into interacting with it, allowing the system to trigger immediate alerts before the actual backup data is compromised.
The setup process is intentionally simple, requiring only two clicks within the security settings to enable the honeypot with either a static or DHCP IP address. Once active, the system monitors for unauthorized access attempts and can be configured to send notifications via email or Syslog to a Security Information and Event Management (SIEM) platform or tools like Grafana. In a live demonstration, Burke uses the Zenmap utility to perform an “intense scan” against the honeypot’s IP. The Object First dashboard immediately lights up with events, capturing the attacker’s attempts to probe protocols such as RDP and specialized Veeam services.
The honeypot provides both reactive and preventative benefits for organizations. Reactively, it ensures that IT admins are alerted to an intrusion at any hour—specifically targeting the “Friday night at 2:00 AM” window when many ransomware attacks begin. Preventatively, the visibility of these juicy but fake services can act as a deterrent. A sophisticated hacker who recognizes a cluster of high-value services on a single IP may realize they have hit a honeypot and retreat to avoid further detection. By integrating this feature for free, Object First adds a layer of proactive defense to their absolute immutability strategy, ensuring customers have the tools to stop an attack in its early stages.
Presented by Geoff Burke, Senior Technology Advisor. Recorded live at Tech Field Day Extra at RSAC 2026 in San Francisco on March 23, 2026. Watch the entire presentation at https://techfieldday.com/appearance/object-first-presents-at-tech-field-day-extra-at-rsac-2026/ or visit https://techfieldday.com/event/rsac2026/ or https://ObjectFirst.com/ for more information.
Transcript
This is the honeypot demo. Now, first of all, I can ask questions. Everyone know what a honeypot is?
Okay. It's a security conference, I thought so. Okay.
So this is just our dashboard. This is live. This is a VPN.
I do have a video just in case. They warned me, Jeff, the VPN connection, but it looks like it's working. I love the honeypot.
This is free as well. It's included in the appliance. It is separated from the appliance.
So it's in the appliance, but it's segmented off. As you know, a honeypot is a tripwire. When attackers attack, one of the first things they need to do is find out what is where.
They need to know what to attack and where. The honeypot will warn you that you're being attacked. And again, remember I said two in the morning, Friday night, some hacker groups will look on Facebook, open page, "Oh, it's Jeff's birthday next weekend.
Ha ha. " So you need to know. To set this up, it's two clicks.
You go into Settings, and then you go to Security, obviously, and then to Honeypot. You click Enable Honeypot. You have a choice between a static or a DHCP IP address, and it's up and running.
And then you should see lower down here, let's use this, Healthy, and you can use that restart button. Now, you could just sit here and watch our events dashboard all day long, but of course, that wouldn't be much fun. So what you should also do is enable cluster notifications.
You've got the mail notifications. Of course, today's modern situation is RSAC. You probably want to send Syslog forwarding to a SIEM or some kind of monitoring section.
So we have that as well. So what I'm going to do, I'm going to attack our rupee. It's why I like this part of the show.
All right. So first of all, I'm going to go back and find out what my IP address is because I, of course, forgot it. It is, okay, 472.
So I'm going to go into my beloved Zenmap. Don't do this at home or in your production if you haven't warned your boss. 172.
What was that again? 16. 16, and then I guess 472, right?
Yeah, there you go. I wouldn't be a hacker. I couldn't even remember the IP address.
It's the pressure of a demo. Okay. But DNS is working.
Well, there you go. Exactly. So this is a great utility.
It's basically Nmap, but for people who just don't want to learn all those commands. I'm going to do an intense scan, but they're all little choices. So let's do a scan.
Okay, what's going to happen? Did I press a button? I did.
Let's go back now to our ObjectFirst appliance. One second. See that scan going.
Oops. Let's go. Wrong location.
That's what happens you go on a Mac. There we go. We should see this event start to light up.
So let's go there. Okay. Boom.
Look at that, and let's just view all events. So the beautiful thing about our honeypot, it's not just a regular honeypot, like advertising phony SSH or other services. This is a Veeam honeypot.
It's pretending to be a Veeam server. It's pretending to be a Veeam Windows repository, which is the juiciest for hackers. They love that.
And all sorts of other things. And it's going to warn you here. So I did an intense scan, so that Zenmap is attacking everything it can, and you are getting all of these warnings in your event view.
But if you went and set up... Let's go over and switch this on the Mac. Where are we?
Give me a second. I thought I had this up. Let's go to Grafana.
So I don't have a SIEMing on the laptop, well, in this little lab, because obviously it would cost a lot. So I create a little Grafana with InfluxDB, and those Syslog messages, raw ones, are coming in, and I'm just posting here. So this, let's pretend, is our scene.
These are the messages coming through. So in your scene, you could set up, for instance, forwarding, pager alert, Slack alert, whatever torture you enjoy. And as you can see here, different protocols.
RDP, SQL Server, Veeam, Veeam WR. What does that stand for? When they first showed me this, I had to think about that, and it's Veeam Windows Repository.
Right. So this is what you're going to get, and I would say this is not just warning you about them being there. But if I was a smart hacker and I saw all these juicy services light up on one IP address, I would think, "Uh-oh, it's a honeypot," and I would be out of there quick.
I don't want to get caught. So in a way, it's also a preventative measure.