CyberDefenders is an independently funded nonprofit project.. Donate
Cloud security deception environment
2026 Summer Cohort — Capstone Project

Ghost Cloud: LLM Honeypots in AWS

Sponsored by Lib13 Inc

Project Brief

Deception Environments for Attacker Telemetry

This track built isolated AWS deception environments using Beelzebub to emulate SSH servers without exposing real systems or secrets, then evaluated how LLM-generated interaction patterns affect attacker engagement and telemetry quality. Two interns worked this track in parallel, each standing up honeypot infrastructure, configuring services like Cowrie, and studying methodologies to make the deception layer more intelligent while maintaining safety guardrails.

Capstone Team

  • Sakshee Ujjwal Kumat — VIT Chennai · Completed
  • Shikhar Sahay — VIT Vellore · In Progress (final deliverables due shortly)

Project Workstreams

Cloud Deception Lab

Deployed a safely isolated SSH honeypot in AWS, collecting commands and credential attempts to evaluate how LLM-assisted responses affect attacker engagement and telemetry quality.

Honeypot or Hallucination?

Compared static and dynamic honeypot behavior (Cowrie vs. Beelzebub) and evaluated whether LLM-generated interactions are realistic, safe, and useful for defenders.

Track Scope: Expected Deliverables

  • Deployment guide for isolated AWS honeypot environments with logging, alerting, and cost controls.
  • Structured reports summarizing commands, payloads, indicators, scanner behavior, credential attempts, and session timelines.
  • Safety guardrails that prevent exposure of real systems, secrets, credentials, or operationally sensitive information.
  • Evaluation results comparing static and LLM-assisted honeypot behavior.
  • Defender-focused reports that turn observed attacker behavior into practical recommendations for small organizations.

Skills Demonstrated

Cloud Security (AWS) Honeypot Deception Threat Intelligence LLM Applications Attacker Telemetry Analysis Python