Skip to content

OpenCanary (UHBS multi-protocol proof)

Status: Informative · evaluation proof
Upstream: https://github.com/thinkst/opencanary · commit bc231423aa40242cbd0bf34801f8788e23420dee
Official capability: multi-protocol network canary (OpenCanary README).
Graded here: HTTP, FTP, SSH, Telnet, Redis, MySQL, RDP, SIP, SNMP, NTP, TFTP, VNC, Git, SMB (Samba sidecar).

Protocol Class / port Quick Full
HTTP Web-API · HTTP :80 52.34 / D 66.02 / D
FTP Low-Interaction · FTP :21 50.47 / D 61.5 / D
SSH Low-Interaction · SSH :2222 31.94 / F 35.64 / F
TELNET Low-Interaction · Telnet :23 52.83 / D 64.9 / D
REDIS Low-Interaction · Redis :6379 45.07 / F 53.72 / D
MYSQL Low-Interaction · MySQL :3306 51.48 / D 62.96 / D
RDP Low-Interaction · RDP :3389 50.13 / D 61.01 / D
SIP Low-Interaction · SIP :5060 40.01 / F 46.44 / F
SNMP Low-Interaction · SNMP :161 40.69 / F 47.42 / F
NTP Low-Interaction · NTP :123 40.69 / F 47.42 / F
TFTP Low-Interaction · TFTP :69 40.69 / F 47.42 / F
VNC Low-Interaction · VNC :5900 50.81 / D 61.99 / D
GIT Low-Interaction · Git :9418 51.48 / D 62.96 / D
SMB Low-Interaction · SMB :445 50.13 / D 57.72 / D

Named product is evaluation proof only — not a UHBS endorsement.

What this decoy is

Multi-service canary/honeypot framework (many protocols); UHBS publishes per-protocol grades.

For CTI analysts

  • Per-protocol canaries yield precise “someone touched this fake service” intel for lateral-movement detection.
  • Use protocol-specific hubs — OpenCanary is not a single UHQS number.

Primary signals: Per-service connection/auth events as configured.

For blue teams / detection engineering

  • Deploy canaries on sensitive VLANs; any connection is high-signal for blue teams.
  • Integrate OpenCanary alerts into SOAR with asset/context tags to avoid alert fatigue.

Trust & limitations

  • Evaluation proof under UHBS 4.2.2 — not a certification or endorsement.
  • Prefer full/ over quick/ for decisions.
  • Reading guide: READING-UHQS.md.