| Category | Function | Share | Rank | Negative rate | Labels | Quadrant | Since September 2026 |
|---|---|---|---|---|---|---|---|
| Deception technology | Security operations | 2% | 9 of 94 | 9% | 11 | accepted challenger |
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 0 | 0 | 0 | 0 | 0 |
| GPT-5.4 mini | 0 | 1 | 0 | 0 | 1 |
| Gemini 3.5 Flash | 0 | 1 | 0 | 0 | 1 |
| Perplexity Sonar | 0 | 0 | 0 | 0 | 0 |
| Grok 4.1 Fast | 0 | 0 | 0 | 1 | 1 |
| Mistral Small | 0 | 0 | 0 | 0 | 0 |
| DeepSeek V4 Flash | 0 | 0 | 2 | 0 | 2 |
| Llama 4 Maverick | 0 | 1 | 0 | 0 | 1 |
| Qwen 3.7 Flash | 1 | 0 | 0 | 0 | 1 |
| Kimi K2 | 0 | 0 | 0 | 0 | 0 |
| GLM 4.7 FlashX | 0 | 2 | 0 | 0 | 2 |
| MiniMax M2.5 | 0 | 0 | 0 | 0 | 0 |
| GPT-6 Luna | 0 | 1 | 0 | 0 | 1 |
| Muse Glimmer 30B | 0 | 1 | 0 | 0 | 1 |
Verbatim evidence the judge attached to positive labels.
“Pick `T-Pot` if you have ≥1 person who knows Linux, Docker, and log analysis, and you want maximum detection surface for $0.” Qwen 3.7 Flash · Deception · budget prompt · first choice
“2. T-Pot - an open-source honeypot platform that combines multiple protocol-specific honeypots and analytics tools.” Llama 4 Maverick · Deception · paraphrase prompt · alternative
“T-Pot is a strong option... but it has higher operational overhead and infrastructure requirements” GPT-5.4 mini · Deception · paraphrase prompt · alternative
“Open-source / engineer-led alternative: T-Pot ... you own the upkeep, tuning and SIEM integration” Muse Glimmer 30B · Deception · paraphrase prompt · alternative
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
“High maintenance (Docker-heavy); better for labs than production.” Grok 4.1 Fast · Deception · paraphrase prompt · soft negative
Citations exist only for the models that return a source list, five of the fourteen in this edition, so these counts come from 28 of the 31 answers that named T-Pot and are not a share of its labels.
No domain is on file for T-Pot, so its own site is not marked.
Pages are listed as the models cited them.
Search figures are US estimates from DataForSEO, read October 5, 2026; AI search demand is its modeled, directional estimate, not a count of queries to any assistant. The answers are this edition's. Two measurements side by side: neither is read as the cause of the other.
An email the morning each edition publishes: where this product moved, where it held, and by how much against the noise floor. One address, confirmed by a click; a stop link in every email.
Already following? Everything you follow, with a stop for each.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when T-Pot's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as T-Pot, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
A new claim receives the current edition's vendor brief for T-Pot by email, built from the raw record of the edition. It shows: