> For the complete documentation index, see [llms.txt](https://mazeshark.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mazeshark.gitbook.io/docs/getting-started/create-honeypot.md).

# Create and test a honeypot

This page will guide you through the process of creating a honeypot with Mazeshark.

### Step 1: **Navigate to the sidebar and select Honeypots**

<figure><img src="https://2173595363-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQDdMrhsPnBXJ1LUZUVjd%2Fuploads%2F2ce7dKt7pMiQZz5OeToc%2FCreate%20Honeypot%20step%201.png?alt=media&amp;token=2f033170-42c9-4f7a-9f85-672f2d0fcf65" alt=""><figcaption></figcaption></figure>

### Step 2: Click "**+ Set up a new honeypot"** in the top right corner

### Step 3: Configure your honeypot

To ensure your honeypots are difficult to detect, select a type that matches your existing resources and assign a name in a similar format. By clicking the "Set up honeypot" button, the app will redirect you to the honeypot's page.

<figure><img src="https://2173595363-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQDdMrhsPnBXJ1LUZUVjd%2Fuploads%2FX1nLoj6yGHeaDbGzFksH%2FCreate%20Honeypot%20step%203.png?alt=media&amp;token=e11a2d23-073e-46e9-8f87-a6f253be9802" alt=""><figcaption></figcaption></figure>

### Step 4: Click "+Create CloudFormation stack"

<figure><img src="https://2173595363-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQDdMrhsPnBXJ1LUZUVjd%2Fuploads%2Ff7v4i7Ax6w9bI41IhRGJ%2FCreate%20Honeypot%20step%204.png?alt=media&amp;token=ff9d8dc9-a868-4976-b4a4-525488f72c77" alt=""><figcaption></figcaption></figure>

Clicking this will open your AWS account in a new tab. You may need to sign in first if you're not logged in.

### Step 5: On the CloudFormation page scroll down and click "Create stack"

This will create a CloudFormation stack for your honeypot. Pro tip: name your stack to something unique that blends in your environment.

<figure><img src="https://2173595363-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQDdMrhsPnBXJ1LUZUVjd%2Fuploads%2Fj9azIsQacw10nI4GDxXJ%2FCreate%20Honeypot%20step%205.png?alt=media&amp;token=dc0539fc-458c-4270-a109-651b84bc6af1" alt=""><figcaption></figcaption></figure>

### Step 6: Monitor the status of your stack

It may take a minute or two for the honeypot to become active. Seeing CREATE\_COMPLETE? Great job! Your honeypot is ready! Time to test your honeypot!

<figure><img src="https://2173595363-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQDdMrhsPnBXJ1LUZUVjd%2Fuploads%2FvbdP3yZBIjqxp0WXGnAF%2FCreate%20Honeypot%20step%206.png?alt=media&amp;token=d01bfabe-8d69-4ecb-81bd-c84d8744e21b" alt=""><figcaption></figcaption></figure>

### Step 7:  Click "Open your AWS Lambda function" on the honeypot's page

Make sure that your function's ARN is the same as configured for your honeypot.

<figure><img src="https://2173595363-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQDdMrhsPnBXJ1LUZUVjd%2Fuploads%2FOBAIjPf1uM5ypn76ioR5%2FCreate%20Honeypot%20step%207.png?alt=media&amp;token=1682d24b-3206-4720-a3b5-e5e36389932f" alt=""><figcaption></figcaption></figure>

### Step 8: Scroll down and click "Test"

No need to change or save the payload. Once you Invoked the function via the Test button, you should see the following message returned: "Forwarding event to server..."

<figure><img src="https://2173595363-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQDdMrhsPnBXJ1LUZUVjd%2Fuploads%2Fh2qLF3HnPxXQgz9ivSWi%2FCreate%20Honeypot%20step%208.png?alt=media&amp;token=5bc1668e-f514-4dba-a7d1-b6a26ab0b93d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2173595363-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQDdMrhsPnBXJ1LUZUVjd%2Fuploads%2FlyaJmA9Ys8AUJCT5I0jB%2FScreenshot%202025-01-17%20at%2014.10.38.png?alt=media&amp;token=402db45b-7206-49ff-baf9-d253298144e1" alt=""><figcaption></figcaption></figure>

Now, simply wait a few minutes for AWS to send the CloudTrail events and for MazeShark to detect the alert. You can also click "Re-check" on the honeypot's page.

<figure><img src="https://2173595363-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQDdMrhsPnBXJ1LUZUVjd%2Fuploads%2F5lsPrFzwJqXJuSx5OH1l%2FCreate%20Honeypot%20step%209.png?alt=media&amp;token=1f0b92b5-82d0-4fec-ad4f-8ba8c1624c67" alt=""><figcaption></figcaption></figure>

### Step 9: Investigate test alert

You should see the test alert in the Alerts section:

<figure><img src="https://2173595363-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQDdMrhsPnBXJ1LUZUVjd%2Fuploads%2FGSvEvjaI8YmzWugRJa3Q%2FScreenshot%202025-01-17%20at%2014.17.11.png?alt=media&amp;token=17c7f5aa-2eed-4eeb-92b8-4c161edd8856" alt=""><figcaption></figcaption></figure>

Click on the alert to see the details.

<figure><img src="https://2173595363-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQDdMrhsPnBXJ1LUZUVjd%2Fuploads%2FSqbxhEtxobfDUfWI69eZ%2FScreenshot%202025-01-17%20at%2014.18.54.png?alt=media&amp;token=0bc08b5c-c747-4645-b808-5a625d4deedf" alt=""><figcaption></figcaption></figure>

Now, it's time to set up automation!
