A cybersecurity system designed to attract and study attackers is called a honeypot.
A honeypot is deliberately made to appear useful or vulnerable, even though it contains no ordinary production workload. Security teams monitor interactions with it to learn about scanning, exploitation attempts, malware, and attacker behavior. Because legitimate users should not normally access the decoy, activity there can be a valuable warning signal.
Honeypots can be low-interaction, offering only limited simulated services, or high-interaction, providing a more realistic environment for observation. They may imitate servers, databases, industrial systems, or other network resources. A collection of related decoys is sometimes called a honeynet.
A honeypot is not the same as a firewall. A firewall controls traffic according to rules, while a honeypot is primarily an observation and deception tool. Poorly isolated honeypots can create risk, so administrators separate them carefully from real systems.