DEV Community

Dewayne Cox
Dewayne Cox

Posted on

Building a Lightweight Honeypot on Fedora: What I Learned Creating BayouCanary

Absolutely. Here's a DEV.to-ready article. I kept it technical rather than sales-heavy and avoided claiming BayouCanary does anything we haven't validated.
Title:

Building a Lightweight Honeypot on Fedora: Why I Created BayouCanary
Tags:
linux security fedora cybersecurity
Article:
If someone is probing your network, how quickly would you know?
That question was part of what led me to build BayouCanary, a lightweight honeypot and security-monitoring project designed to run on Fedora Linux.
The concept isn't to replace a firewall, EDR platform, SIEM, IDS/IPS, or other enterprise security product.
It's much simpler:
Put a tripwire on the network and pay attention when something touches it.

What Is a Honeypot?
A honeypot is a system or service intentionally exposed in a controlled way so that unexpected interaction with it can be observed.
Consider a machine on your internal network that nobody should normally be connecting to.
If another system suddenly begins attempting connections to services on that machine, that's interesting.
It doesn't automatically mean you've discovered an attacker.
But it gives you something worth investigating.
That's the philosophy behind BayouCanary.
Why Fedora?
I wanted BayouCanary to be something that could run on a relatively simple Linux installation without requiring someone to build an entire security operations platform.
Fedora provides a solid environment for experimenting with Linux networking, services, automation, virtualization, and security tooling.
More importantly, you don't necessarily need dedicated hardware.
A BayouCanary system can be deployed in a Fedora virtual machine, which makes it practical for a homelab or testing environment where spinning up another physical server doesn't make sense.
That also makes experimentation much easier:

  1. Create a Fedora VM.
  2. Deploy the monitoring environment.
  3. Place it appropriately on your test network.
  4. Generate controlled test activity.
  5. Observe what BayouCanary reports. For development, being able to destroy and rebuild that VM is extremely useful. A Honeypot Isn't a Security Camera One misconception I wanted to avoid is presenting a honeypot as something that "protects your network." That's not really its job. I think of it more like a tripwire. A firewall asks: Should this traffic be allowed?

A monitoring platform might ask:
What is happening across my infrastructure?

A honeypot asks something slightly different:
Why is someone interacting with this system at all?

That distinction matters.
BayouCanary is intended to provide another source of visibility—not magically make a network secure.
Keeping the Project Small
Security projects have a habit of becoming enormous.
You start with:
"I'd like to monitor some network activity."

Three hours later you're designing a SOC.
I deliberately wanted to avoid that.
BayouCanary isn't intended to compete with enterprise security platforms.
The goal is closer to:
Deploy → Monitor → Observe → Investigate
That makes it potentially useful for:

  • Linux enthusiasts
  • Homelab users
  • Small networks
  • Security students
  • System administrators
  • People learning defensive security
  • Anyone experimenting with honeypots It also makes the project much easier to understand. Why a Dashboard Matters Collecting information is only half the problem. You also need to make the information understandable. One of the design goals for BayouCanary has therefore been providing a dashboard that makes it easier to see what the monitoring system is observing. I don't want someone to need five terminal windows open just to determine whether something interesting happened. This reflects a larger philosophy I'm using with the tools I build: The underlying technology can remain technical without requiring the interface to be difficult.

That's especially important with security tooling.
Complexity can hide important information.
Virtual Machines Make Great Security Labs
One of my favorite parts of this project is that you can experiment without needing an expensive lab.
A Fedora VM can become a disposable security target.
That means you can generate controlled traffic against it, observe the results, make changes, break things, restore a snapshot, and try again.
For someone learning Linux or defensive security, that's valuable.
You aren't just reading about network activity.
You're generating it and observing what happens.
What BayouCanary Is Not
It's equally important to define what a security tool doesn't do.
BayouCanary is not intended to replace:

  • Endpoint protection
  • Firewalls
  • Network segmentation
  • Vulnerability management
  • IDS/IPS platforms
  • Centralized logging
  • SIEM platforms
  • Good patch management It's another signal. And in security, sometimes one additional signal is exactly what starts an investigation. Early Access Means Early Access BayouCanary is currently at version 0.1.3 Early Access. I use that terminology deliberately. This is still an evolving project. I'd rather have Linux administrators, homelab users, and security-minded people experiment with it and tell me what's missing than pretend a young project is already a mature enterprise security product. Some of the questions I'm particularly interested in are:
  • What information should a lightweight honeypot dashboard surface first?
  • Which network services would be most useful to monitor?
  • What alerts would actually be useful rather than noisy?
  • What reporting would administrators want?
  • Would you deploy something like this in a VM?
  • What would make you trust—or distrust—a tool like this? Those answers can influence where the project goes next. Building Tools Around Real Problems BayouCanary is part of a larger project I'm building called BayouFinds. My background is in systems and infrastructure work, so I'm particularly interested in small tools that remove repetitive work or make technical information easier to understand. I'm increasingly convinced that useful software doesn't always need to reinvent the underlying technology. Sometimes the opportunity is simply: Take something powerful, remove unnecessary friction, add sensible guardrails, and make the information easier to use. That's the direction I'm exploring with BayouCanary and the other BayouFinds projects. Want to Try It? BayouCanary 0.1.3 Early Access is available here: BayouCanary 0.1.3 Early Access — Fedora Honeypot Security Monitor https://bayoufinds.com/b/oOg3f If you work with Linux, networking, cybersecurity, homelabs, or system administration, I'm particularly interested in your technical feedback. What would you want a lightweight honeypot to tell you the moment you opened its dashboard?

Top comments (1)