
PhantomFS v1.2.20
Windows honeypot using ProjFS to project decoy files that trigger Event Log and desktop alerts when accessed, with SMB remote session logging for lateral movement detection.
Fake Files. Real Security.
Virtual honeypot file system for Windows — lure attackers into a directory that looks real, then catch them in the act.
What Is PhantomFS?
PhantomFS uses the Windows Projected File System (ProjFS) to surface a virtual directory full of convincing decoy files — financial reports, SSH keys, API credentials, HR spreadsheets, NDAs — that exist only in memory. No data is ever written to disk until an attacker (or insider threat) opens one.
The moment a file is touched, PhantomFS:
- Writes a Windows Event Log entry (Application log, source
PhantomFS) - Fires a Toast notification to the active desktop session
- Logs the exact filename, timestamp, and process context
- When accessed over a network share — captures the SMB username and source address
Because legitimate users have no reason to open files they didn't put there, every alert is high-confidence. No tuning, no ML, no cloud dependencies — just a native Windows driver and a single executable.
Features
| Feature | Details |
|---|---|
| Zero-footprint decoys | Files are projected on demand — nothing is written to disk unless an attacker reads a file |
| Windows Event Log | Event ID 1001 (file read), 1002 (placeholder created), 1003 (started), 1004 (stopped) |
| Toast alerts | Immediate desktop notification via Windows PowerShell — works even over RDP |
| Remote session logging | SMB username and source address captured via NetSessionEnum when PID 4 triggers access |
| Auto-cleanup | Hydrated synthetic files deleted after a configurable delay; reverts to virtual on next access |
| Configurable templates | PDF, XLSX, DOCX, JSON, CSV, PEM, plain text — all served from XML templates in the config |
| Per-file cooldown | Configurable throttle (default 15 s) prevents alert floods when a tool reads multiple chunks |
| Synthetic file list | Drop-in XML list of convincing filenames with realistic byte sizes |
| Single executable | PhantomFS.exe + PhantomFS.exe.config — no installer required |
Requirements
- Windows 10 version 1809 (Build 17763) or later — Windows 11 recommended
- .NET Framework 4.8
- Windows Projected File System optional feature enabled (
Enable-WindowsOptionalFeature -Online -FeatureName Client-ProjFS -NoRestart) - Administrator privileges to start the virtual root
Quick Start
Simple Commands (recommended)
- Download
PhantomFS-v1.1.0-x64.zipfrom Releases and extract it - Run as Administrator — enable ProjFS,
Enable-WindowsOptionalFeature -Online -FeatureName Client-ProjFS -NoRestart - Execute
.\PhantomFS.exe --virtroot C:\PhantomFS\Virtual\Documents --syntheticonly - Browse to
C:\PhantomFS\Virtual\Documentsin Explorer — you will see the decoy files - Open one — watch the Toast fire and check Event Viewer → Windows Logs → Application
Configuration
All settings live in PhantomFS.exe.config. All keys are optional — omitting a key uses the default shown in the table.
Use the PhantomFS Profile Builder to generate different config profiles for your deployment scenarios:
<settings> Section
<settings>
<enableEventLog>true</enableEventLog>
<enableToast>true</enableToast>
<alertOnOpen>true</alertOnOpen>
<alertOnRead>true</alertOnRead>
<toastCooldownSeconds>15</toastCooldownSeconds>
<verbose>false</verbose>
<virtRoot></virtRoot>
<sourceRoot></sourceRoot>
<syntheticOnly>true</syntheticOnly>
<!-- v1.1.0 — auto-cleanup -->
<autoCleanupEnabled>true</autoCleanupEnabled>
<autoCleanupDelaySeconds>300</autoCleanupDelaySeconds>
<!-- v1.1.0 — remote session logging -->
<resolveRemoteIPs>true</resolveRemoteIPs>
</settings>
| Key | Default | Since | Description |
|---|---|---|---|
enableEventLog | true | 1.0.0 | Write to Windows Application event log |
enableToast | true | 1.0.0 | Send desktop Toast notification |
alertOnOpen | true | 1.0.0 | Alert when a placeholder is first created (directory browse) |
alertOnRead | true | 1.0.0 | Alert when file data is actually read |
toastCooldownSeconds | 15 | 1.0.0 | Minimum seconds between Toasts for the same file path |
verbose | false | 1.0.0 | Extra console output for diagnostics |
virtRoot | (arg 1) | 1.0.0 | Override virtual root path from config rather than command line |
sourceRoot | (empty) | 1.0.0 | Optional real backing directory — leave empty for synthetic-only mode |
syntheticOnly | true | 1.0.0 | Serve only the files listed in <syntheticFileList> |
autoCleanupEnabled | true | 1.1.0 | Delete materialized synthetic files after the delay and revert to virtual |
autoCleanupDelaySeconds | 300 | 1.1.0 | Seconds after hydration before the file is deleted (cleanup timer runs every 30 s) |
resolveRemoteIPs | true | 1.1.0 | DNS-resolve the SMB client hostname to an IP address; set to false if lookup latency is unacceptable |
Remote Session Logging
When a file is accessed over an SMB share, PhantomFS detects PID 4 (the Windows System process / kernel SMB driver) as the caller and automatically calls NetSessionEnum to identify the remote user. The Event Log entry and Toast notification will include:
PhantomFS — Honeypot File Content Read
File : Documents\Q4_Financial_Report_2024.pdf
Process : System (PID 4)
Remote : CORP\jsmith @ DESKTOP-A1B2C3D [192.168.1.45]
Requirements for remote logging:
- The Server service must be running (it starts automatically whenever a share is active)
- PhantomFS must be running on the machine hosting the share
resolveRemoteIPsrequires the client machine to be resolvable via DNS
Auto-Cleanup Behaviour
After a synthetic file is opened and hydrated (content written to disk), a background timer checks every 30 seconds and deletes files whose hydration time exceeds autoCleanupDelaySeconds. The deleted file reverts to a virtual ProjFS placeholder — the next access re-triggers the ProjFS callback as if the file had never been opened.
Files that are still open when the cleanup timer fires are skipped without error and retried on the next 30-second cycle.
Adding Decoy Files
Add entries under <syntheticFileList> in the config:
\Documents,true,0,1744586986
\Documents\Q4_Financial_Report_2024.pdf,false,8192,1744586986
\Documents\Employee_Salaries_2024.xlsx,false,4096,1743942586
\IT\Keys,true,0,1744586986
\IT\Keys\deploy_key.pem,false,3247,1742354986
Adding Content Templates
<syntheticTemplates>
<template name="my_custom_file.txt"><![CDATA[
... your file content here ...
]]></template>
</syntheticTemplates>