Sometimes you need to know, is there any malicious activity inside your local net, or not. You can add IDS and scan all traffic on LAN or simply deploy VM with honeypot.
Quiet simple with VM!
1) setup VM bith basic Linux installation inside your net
2) download honeypot form https://github.com/jurigurjanov/honeypot and open some ports inside honeypot.py upon your flavor
3) add some decoys, like IP in hosts with IP from VM on some LAN machines
4) wait for e-mail
phone +372 5507447 mail me