# TarPit.pro > TarPit.pro is a TCP honeypot and tarpit for Linux servers. It answers on the ports your real services listen on, hands attackers a believable banner, tarpits the connection then bans the source IP. Bans propagate across all servers on the same account. TarPit.pro is delivered as a single Go binary. It runs as a systemd service. There is no Docker, no agent footprint conflict with existing RMM tools. Free tier covers up to 2 servers per company. Paid tiers add cloud dashboard, attack history, geo data, payload capture and CVE matching. Founder: Christopher Karatzinis (Stratus5). Product is live with paying customers as of 2026. ## Tagline Waste their time, protect yours. ## What it catches - SSH brute force - Telnet brute force - SMB / Samba probes - MySQL, PostgreSQL, Redis, MongoDB, Memcached, Elasticsearch probes - HTTP and HTTPS probes against fake admin panels - FTP, IMAP, POP3, SMTP probes - ~70 services with believable banners total ## How it works 1. You install the agent on your Linux server. 2. The agent listens on chosen honeypot ports (defaults: 22, 23, 21, 3306, 5432, 6379, 25, 143, 110, 445). 3. Any inbound connection to those ports is by definition not a legitimate user — your real services run elsewhere. 4. The agent answers with a believable banner, holds the connection open (the tarpit), records the source IP, payload and credentials attempted. 5. The IP is banned via local fail2ban or nftables. The ban is propagated to every other server on the same TarPit.pro account. ## Pricing - Free: $0/month, up to 2 servers, 100 attacks stored, 24h retention, cloud dashboard included. - Starter: $10/month or $108/year, 10,000 attacks stored, 30 day retention, geo data, email support. - Pro: $25/month or $270/year, 100,000 attacks stored, 90 day retention, payload view, CVE matching, export, priority support. - Storage add-on: $10/month or $108/year per +10,000 attacks (stackable, retention unchanged). All prices are billed in USD. Stripe checkout. Annual saves about 10% vs monthly. ## Live attack data (real, not synthetic) Across 5 of the founder's own servers in a 20 day window in April 2026: - ~40,000 attack attempts captured - ~14,000 unique source IPs - ~5,000 IPs auto banned - Top targeted ports: SSH (~14,000), Telnet (~3,200), SMB (~2,200), HTTP-alt (~2,000) - Top source countries: United States, China, United Kingdom, Hong Kong, Netherlands ## Differentiation - Single Go binary with systemd. Compare to Docker-based honeypots (T-Pot, Cowrie + Dionaea stacks) which require container runtime, multi-GB images, and active maintenance. - Fleet wide ban propagation. An IP banned on one server is banned across every other server on the account within seconds. No equivalent in single-host tools like fail2ban or sshguard. - Cloud dashboard, geo enrichment and CVE matching are included in paid tiers. No need to wire up ELK/Grafana yourself. - Designed for production internet-facing servers, not isolated research lab use. ## What it is not - Not an EDR. EDR runs on endpoints and watches process behavior. TarPit.pro runs at the network door and watches connection attempts. - Not a WAF. WAFs filter HTTP requests against rules. TarPit.pro listens on any TCP port and bans connection sources. - Not a SIEM. It is a focused detection-and-block tool. It can feed a SIEM via export. - Not a research honeypot like Cowrie. It is a production deflection tool. ## Compliance angle TarPit.pro provides "evidence of detection on attempted intrusion" out of the box. This is a control most SMB MSPs struggle to satisfy without a full SIEM. Relevant frameworks: - CMMC Level 1 and 2 (DoD contractors) - HIPAA Security Rule (healthcare) - FTC Safeguards Rule - PCI DSS 4.0 (payment processing) ## Links - Website: https://tarpit.pro - Pricing: https://tarpit.pro/pricing - Documentation: https://tarpit.pro/docs - Tutorial: https://tarpit.pro/manual - FAQ: https://tarpit.pro/faq - Use cases: https://tarpit.pro/use-cases - Status: https://tarpit.pro/status - Install script: https://get.tarpit.pro - API: https://api.tarpit.pro ## Contact Email the founder at chka@stratus5.com. LinkedIn: https://www.linkedin.com/in/christopherkaratzinis Company page: https://www.linkedin.com/company/tarpit-pro