logo

How To Use Portspoof (Cyber Deception)

ID: 95c5c429-5d1b-5bc5-bdfc-34efb9bb1d8b

STIX ID: report--95c5c429-5d1b-5bc5-bdfc-34efb9bb1d8b

Feed Name: Black Hills Infosec Blog

Date Published: 2020-04-08

Date Updated: 2026-04-27

Author: BHIS

...
...

This document is a tutorial on using Portspoof within the Active Defense Harbinger Distribution (ADHD) to implement cyber deception by redirecting all TCP ports to a local listener and returning randomized service banners, thereby making every port appear open and extending the time and effort required for Nmap scans. It covers configuring iptables to forward connections to Portspoof on port 4444, demonstrates basic and version-detection scans, and shows how a user-defined signature file generates misleading service responses to frustrate reconnaissance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.