Skip to main content

Overview

The honeypot access point alert triggers when WIDS detects a honeypot (also known as an evil twin) access point. A honeypot AP mimics a legitimate network to trick users into connecting, potentially exposing their traffic to attackers.

Prerequisites

Configuring the alert

Honeypot AP alert configuration

Configuration fields

FieldRequiredDescription
EnabledYesToggle to activate or deactivate the alert (default: on)
LabelNoCustom name for this alert instance
DescriptionNoAdditional notes about this alert
Alert typeYesSelect “Honeypot AP”
ReceiverYesSelect from configured receivers
Company wideYesApply to all networks or select specific networks
Excluded networksNoNetworks to exclude when Company wide is enabled

Webhook event

This alert corresponds to the ALERT_HONEYPOT_AP_DETECTED webhook event. See Honeypot access point webhook payload for integration details.

What to do when you receive this alert

  1. Review the alert details to identify the suspected honeypot AP
  2. Determine if this is a legitimate device (e.g., a personal hotspot)
  3. If unauthorized, attempt to locate and remove the device
  4. Contact Meter Support for assistance with investigation

Need help?

If you run into any issues or have questions, please reach out to our Support Engineering team by opening a ticket via the Dashboard: https://dashboard.meter.com/support
Last updated by Meter Support Engineering on 01/23/2026