We'll pick the best region based on the attack surface you want to monitor.
Select Instance Size
Small
~$0.006/hr
2 GB RAM · 1 vCPU
Up to 10 decoys
Medium
~$0.012/hr
4 GB RAM · 2 vCPU
Up to 25 decoys + NetWatch
RECOMMENDED
Large
~$0.024/hr
8 GB RAM · 4 vCPU
Up to 50 decoys + full stack
Configure Options
Deploy Zeek + Suricata alongside honeypots for network monitoring.
Provision a dedicated-CPU instance (CCX13 on Hetzner) with /dev/kvm so Firecracker microVMs can boot here. Post-setup installs the Firecracker toolchain + builds the Cowrie rootfs image. Additive to the standard collector stack — container decoys keep working.
hours
Review Deployment
Provisioning Collector
●
Creating VPS instance
●
Installing Docker
●
Deploying Collector
●
Pairing with Control Plane
●
Online
IP Address
Corporate Collectors
Deploy on public VPSs to attract internet-facing attacks. Good for threat intelligence gathering and demonstrating the platform.
Client Collectors
Clients deploy inside their own networks. All data is scoped to their tenant — they only see their own detections and incidents.
Live Cloud Servers
All machines running in your cloud provider accounts, cross-referenced with ADE tracking
Click Refresh to load live inventory from Hetzner
Pre-configured collector hardware with Nythrix ADE software pre-installed. Ships ready to deploy — plug in, pair, and start collecting.