Track Awesome Honeypots Updates Weekly
an awesome list of honeypot resources
🏠 Home · 🔍 Search · 🔥 Feed · 📮 Subscribe · ❤️ Sponsor · 😺 paralax/awesome-honeypots · ⭐ 9K · 🏷️ Security
Apr 07 - Apr 13, 2025
Honeypots
Web honeypots
- Cloud Active Defense (⭐89) - Cloud active defense lets you deploy decoys right into your cloud applications, putting adversaries into a dilemma: to hack or not to hack?
- Express honeypot (⭐19) - RFI & LFI honeypot using nodeJS and express.
- EoHoneypotBundle (⭐36) - Honeypot type for Symfony2 forms.
- Glastopf (⭐572) - Web Application Honeypot.
- Google Hack Honeypot - Designed to provide reconnaissance against attackers that use search engines as a hacking tool against your resources.
- HellPot (⭐960) - Honeypot that tries to crash the bots and clients that visit it's location.
- Laravel Application Honeypot (⭐432) - Simple spam prevention package for Laravel applications.
- Lophiid (⭐11) - Distributed web application honeypot to interact with large scale exploitation attempts.
- Nodepot (⭐46) - NodeJS web application honeypot.
- PasitheaHoneypot (⭐2) - RestAPI honeypot.
- Servletpot (⭐14) - Web application Honeypot.
- Shadow Daemon - Modular Web Application Firewall / High-Interaction Honeypot for PHP, Perl, and Python apps.
- StrutsHoneypot (⭐71) - Struts Apache 2 based honeypot as well as a detection module for Apache 2 servers.
- WebTrap (⭐65) - Designed to create deceptive webpages to deceive and redirect attackers away from real websites.
- basic-auth-pot (bap) (⭐48) - HTTP Basic Authentication honeypot.
- bwpot (⭐27) - Breakable Web applications honeyPot.
- django-admin-honeypot (⭐1k) - Fake Django admin login screen to notify admins of attempted unauthorized access.
- drupo (⭐57) - Drupal Honeypot.
- galah (⭐520) - an LLM-powered web honeypot using the OpenAI API.
- honeyhttpd (⭐47) - Python-based web server honeypot builder.
- honeyup (⭐27) - An uploader honeypot designed to look like poor website security.
- modpot (⭐57) - Modpot is a modular web application honeypot framework and management application written in Golang and making use of gin framework.
- owa-honeypot (⭐65) - A basic flask based Outlook Web Honey pot.
- phpmyadmin_honeypot (⭐65) - Simple and effective phpMyAdmin honeypot.
- shockpot - WebApp Honeypot for detecting Shell Shock exploit attempts.
- smart-honeypot (⭐17) - PHP Script demonstrating a smart honey pot.
- Snare/Tanner - successors to Glastopf
- Snare (⭐461) - Super Next generation Advanced Reactive honeypot.
- Tanner (⭐225) - Evaluating SNARE events.
- stack-honeypot (⭐23) - Inserts a trap for spam bots into responses.
- tomcat-manager-honeypot (⭐11) - Honeypot that mimics Tomcat manager endpoints. Logs requests and saves attacker's WAR file for later study.
- WordPress honeypots
- HonnyPotter (⭐32) - WordPress login honeypot for collection and analysis of failed login attempts.
- HoneyPress (⭐7) - Python based WordPress honeypot in a Docker container.
- wp-smart-honeypot (⭐28) - WordPress plugin to reduce comment spam with a smarter honeypot.
- wordpot (⭐182) - WordPress Honeypot.
- Python-Honeypot (⭐458) - OWASP Honeypot, Automated Deception Framework.
Dec 25 - Dec 31, 2023
Honeypots
Anti-honeypot stuff
- canarytokendetector (⭐20) - Tool for detection and nullification of Thinkst CanaryTokens
- honeydet (⭐89) - Signature based honeypot detector tool written in Golang
- kippo_detect (⭐57) - Offensive component that detects the presence of the kippo honeypot.
Honeypot deployment
- honeyfs (⭐7) - Tool to create artificial file systems for medium/high interaction honeypots.
- Modern Honeynet Network - Streamlines deployment and management of secure honeypots.
Aug 22 - Aug 28, 2022
Honeypots
Database Honeypots
- Delilah (⭐23) - Elasticsearch Honeypot written in Python (originally from Novetta).
- ESPot (⭐27) - Elasticsearch honeypot written in NodeJS, to capture every attempts to exploit CVE-2014-3120.
- ElasticPot - An Elasticsearch Honeypot.
- Elastic honey (⭐185) - Simple Elasticsearch Honeypot.
- MongoDB-HoneyProxy (⭐92) - MongoDB honeypot proxy.
- NoSQLpot (⭐102) - Honeypot framework built on a NoSQL-style database.
- mysql-honeypotd (⭐32) - Low interaction MySQL honeypot written in C.
- MysqlPot (⭐21) - MySQL honeypot, still very early stage.
- pghoney (⭐19) - Low-interaction Postgres Honeypot.
- sticky_elephant (⭐11) - Medium interaction postgresql honeypot.
- RedisHoneyPot (⭐24) - High Interaction Honeypot Solution for Redis protocol.
SIP
- SentryPeer (⭐190) - Protect your SIP Servers from bad actors.
Aug 08 - Aug 14, 2022
Honeypots
Low interaction honeypot
- Honeyperl - Honeypot software based in Perl with plugins developed for many functions like : wingates, telnet, squid, smtp, etc.
- T-Pot (⭐7.7k) - All in one honeypot appliance from telecom provider T-Mobile
- beelzebub (⭐879) - A secure honeypot framework, extremely easy to configure by yaml 🚀
Jan 10 - Jan 16, 2022
Honeypots
- Service Honeypots
- ADBHoney (⭐165) - Low interaction honeypot that simulates an Android device running Android Debug Bridge (ADB) server process.
- AMTHoneypot (⭐18) - Honeypot for Intel's AMT Firmware Vulnerability CVE-2017-5689.
- ddospot (⭐55) - NTP, DNS, SSDP, Chargen and generic UDP-based amplification DDoS honeypot.
- dionaea (⭐739) - Home of the dionaea honeypot.
- dhp (⭐30) - Simple Docker Honeypot server emulating small snippets of the Docker HTTP API.
- DolosHoneypot (⭐2) - SDN (software defined networking) honeypot.
- Ensnare (⭐66) - Easy to deploy Ruby honeypot.
- GenAIPot (⭐16) - The first A.I based open source honeypot. supports POP3 and SMTP protocols and generates content using A.I based on user description.
- Helix (⭐40) - K8s API Honeypot with Active Defense Capabilities.
- honeycomb_plugins (⭐26) - Plugin repository for Honeycomb, the honeypot framework by Cymmetria.
- [honeydb] (https://honeydb.io/downloads) - Multi-service honeypot that is easy to deploy and configure. Can be configured to send interaction data to to HoneyDB's centralized collectors for access via REST API.
- honeyntp (⭐53) - NTP logger/honeypot.
- honeypot-camera (⭐50) - Observation camera honeypot.
- honeypot-ftp (⭐31) - FTP Honeypot.
- honeypots (⭐767) - 25 different honeypots in a single pypi package! (dns, ftp, httpproxy, http, https, imap, mysql, pop3, postgres, redis, smb, smtp, socks5, ssh, telnet, vnc, mssql, elastic, ldap, ntp, memcache, snmp, oracle, sip and irc).
- honeytrap (⭐1.2k) - Advanced Honeypot framework written in Go that can be connected with other honeypot software.
- HoneyPy (⭐466) - Low interaction honeypot.
- Honeygrove (⭐20) - Multi-purpose modular honeypot based on Twisted.
- Honeyport (⭐44) - Simple honeyport written in Bash and Python.
- Honeyprint (⭐19) - Printer honeypot.
- Lyrebird - Modern high-interaction honeypot framework.
- MICROS honeypot (⭐16) - Low interaction honeypot to detect CVE-2018-2636 in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (MICROS).
- node-ftp-honeypot (⭐5) - FTP server honeypot in JS.
- pyrdp (⭐1.6k) - RDP man-in-the-middle and library for Python 3 with the ability to watch connections live or after the fact.
- rdppot (⭐65) - RDP honeypot
- RDPy (⭐1.7k) - Microsoft Remote Desktop Protocol (RDP) honeypot implemented in Python.
- SMB Honeypot (⭐48) - High interaction SMB service honeypot capable of capturing wannacry-like Malware.
- Tom's Honeypot (⭐26) - Low interaction Python honeypot.
- Trapster Commmunity (⭐116) - Modural and easy to install Python Honeypot, with comprehensive alerting
- troje (⭐45) - Honeypot that runs each connection with the service within a separate LXC container.
- WebLogic honeypot (⭐32) - Low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware.
- WhiteFace Honeypot (⭐5) - Twisted based honeypot for WhiteFace.
Distributed Honeypots
- DemonHunter (⭐61) - Low interaction honeypot server.
ICS/SCADA honeypots
- Conpot (⭐1.3k) - ICS/SCADA honeypot.
- GasPot (⭐139) - Veeder Root Gaurdian AST, common in the oil and gas industry.
- SCADA honeynet - Building Honeypots for Industrial Networks.
- gridpot (⭐55) - Open source tools for realistic-behaving electric grid honeynets.
- scada-honeynet - Mimics many of the services from a popular PLC and better helps SCADA researchers understand potential risks of exposed control system devices.
Other/random
- CitrixHoneypot (⭐114) - Detect and log CVE-2019-19781 scan and exploitation attempts.
- Damn Simple Honeypot (DSHP) (⭐17) - Honeypot framework with pluggable handlers.
- dicompot (⭐24) - DICOM Honeypot.
- IPP Honey - A honeypot for the Internet Printing Protocol.
- Log4Pot (⭐92) - A honeypot for the Log4Shell vulnerability (CVE-2021-44228).
- Masscanned (⭐119) - Let's be scanned. A low-interaction honeypot focused on network scanners and bots. It integrates very well with IVRE to build a self-hosted alternative to GreyNoise.
- medpot (⭐25) - HL7 / FHIR honeypot.
- NOVA (⭐75) - Uses honeypots as detectors, looks like a complete system.
- OpenFlow Honeypot (OFPot) (⭐23) - Redirects traffic for unused IPs to a honeypot, built on POX.
- OpenCanary (⭐2.4k) - Modular and decentralised honeypot daemon that runs several canary versions of services that alerts when a service is (ab)used.
- ciscoasa_honeypot (⭐51) A low interaction honeypot for the Cisco ASA component capable of detecting CVE-2018-0101, a DoS and remote code execution vulnerability.
- miniprint (⭐202) - A medium interaction printer honeypot.
Botnet C2 tools
- Hale (⭐191) - Botnet command and control monitor.
- dnsMole - Analyses DNS traffic and potentionaly detect botnet command and control server activity, along with infected hosts.
IPv6 attack detection tool
- ipv6-attack-detector (⭐39) - Google Summer of Code 2012 project, supported by The Honeynet Project organization.
Dynamic code instrumentation toolkit
- Frida - Inject JavaScript to explore native apps on Windows, Mac, Linux, iOS and Android.
Tool to convert website to server honeypots
- HIHAT - Transform arbitrary PHP applications into web-based high-interaction Honeypots.
Malware collector
- Kippo-Malware - Python script that will download all malicious files stored as URLs in a Kippo SSH honeypot database.
Distributed sensor deployment
- Community Honey Network - CHN aims to make deployments honeypots and honeypot management tools easy and flexible. The default deployment method uses Docker Compose and Docker to deploy with a few simple commands.
- Modern Honey Network - Multi-snort and honeypot sensor management, uses a network of VMs, small footprint SNORT installations, stealthy dionaeas, and a centralized server for management.
Network Analysis Tool
- Tracexploit - Replay network packets.
Log anonymizer
- LogAnon - Log anonymization library that helps having anonymous logs consistent between logs and network captures.
Low interaction honeypot (router back door)
- Honeypot-32764 (⭐18) - Honeypot for router backdoor (TCP 32764).
- WAPot (⭐19) - Honeypot that can be used to observe traffic directed at home routers.
honeynet farm traffic redirector
- Honeymole - Deploy multiple sensors that redirect traffic to a centralized collection of honeypots.
HTTPS Proxy
- mitmproxy - Allows traffic flows to be intercepted, inspected, modified, and replayed.
System instrumentation
- Sysdig - Open source, system-level exploration allows one to capture system state and activity from a running GNU/Linux instance, then save, filter, and analyze the results.
- Fibratus (⭐2.3k) - Tool for exploration and tracing of the Windows kernel.
Honeypot for USB-spreading malware
- Ghost-usb (⭐97) - Honeypot for malware that propagates via USB storage devices.
Data Collection
- Kippo2MySQL - Extracts some very basic stats from Kippo’s text-based log files and inserts them in a MySQL database.
- Kippo2ElasticSearch - Python script to transfer data from a Kippo SSH honeypot MySQL database to an ElasticSearch instance (server or cluster).
Passive network audit framework parser
- Passive Network Audit Framework (pnaf) (⭐32) - Framework that combines multiple passive and automated analysis techniques in order to provide a security assessment of network platforms.
VM monitoring and tools
- Antivmdetect (⭐736) - Script to create templates to use with VirtualBox to make VM detection harder.
- VMCloak (⭐496) - Automated Virtual Machine Generation and Cloaking for Cuckoo Sandbox.
- vmitools - C library with Python bindings that makes it easy to monitor the low-level details of a running virtual machine.
Binary debugger
- Hexgolems - Pint Debugger Backend (⭐32) - Debugger backend and LUA wrapper for PIN.
- Hexgolems - Schem Debugger Frontend (⭐142) - Debugger frontend.
Mobile Analysis Tool
- Androguard (⭐5.5k) - Reverse engineering, Malware and goodware analysis of Android applications and more.
- APKinspector (⭐838) - Powerful GUI tool for analysts to analyze the Android applications.
Honeynet data fusion
- HFlow2 - Data coalesing tool for honeynet/network analysis.
Server
- Amun - Vulnerability emulation honeypot.
- Artillery (⭐330) - Open-source blue team tool designed to protect Linux and Windows operating systems through multiple methods.
- Bait and Switch - Redirects all hostile traffic to a honeypot that is partially mirroring your production system.
- Bifrozt (⭐5) - Automatic deploy bifrozt with ansible.
- Conpot - Low interactive server side Industrial Control Systems honeypot.
- Heralding (⭐378) - Credentials catching honeypot.
- HoneyWRT (⭐21) - Low interaction Python honeypot designed to mimic services or ports that might get targeted by attackers.
- Honeyd (⭐11) - See honeyd tools.
- Honeysink - Open source network sinkhole that provides a mechanism for detection and prevention of malicious traffic on a given network.
- Hontel (⭐160) - Telnet Honeypot.
- KFSensor - Windows based honeypot Intrusion Detection System (IDS).
- LaBrea - Takes over unused IP addresses, and creates virtual servers that are attractive to worms, hackers, and other denizens of the Internet.
- MTPot (⭐104) - Open Source Telnet Honeypot, focused on Mirai malware.
- SIREN (⭐13) - Semi-Intelligent HoneyPot Network - HoneyNet Intelligent Virtual Environment.
- TelnetHoney (⭐1) - Simple telnet honeypot.
- UDPot Honeypot (⭐48) - Simple UDP/DNS honeypot scripts.
- Yet Another Fake Honeypot (YAFH) (⭐9) - Simple honeypot written in Go.
- arctic-swallow (⭐2) - Low interaction honeypot.
- fapro (⭐1.6k) - Fake Protocol Server.
- glutton (⭐271) - All eating honeypot.
- go-HoneyPot (⭐43) - Honeypot server written in Go.
- go-emulators (⭐10) - Honeypot Golang emulators.
- honeymail (⭐29) - SMTP honeypot written in Golang.
- honeytrap (⭐94) - Low-interaction honeypot and network security tool written to catch attacks against TCP and UDP services.
- imap-honey (⭐25) - IMAP honeypot written in Golang.
- mwcollectd - Versatile malware collection daemon, uniting the best features of nepenthes and honeytrap.
- potd (⭐30) - Highly scalable low- to medium-interaction SSH/TCP honeypot designed for OpenWrt/IoT devices leveraging several Linux kernel features, such as namespaces, seccomp and thread capabilities.
- portlurker (⭐33) - Port listener in Rust with protocol guessing and safe string display.
- slipm-honeypot (⭐17) - Simple low-interaction port monitoring honeypot.
- telnet-iot-honeypot (⭐304) - Python telnet honeypot for catching botnet binaries.
- telnetlogger (⭐240) - Telnet honeypot designed to track the Mirai botnet.
- vnclowpot (⭐22) - Low interaction VNC honeypot.
IDS signature generation
- Honeycomb - Automated signature creation using honeypots.
Lookup service for AS-numbers and prefixes
- CC2ASN - Simple lookup service for AS-numbers and prefixes belonging to any given country in the world.
Data Collection / Data Sharing
- HPfriends - Honeypot data-sharing platform.
- hpfriends - real-time social data-sharing - Presentation about HPFriends feed system
- HPFeeds (⭐214) - Lightweight authenticated publish-subscribe protocol.
- HPfriends - Honeypot data-sharing platform.
Central management tool
- PHARM - Manage, report, and analyze your distributed Nepenthes instances.
Network connection analyzer
- Impost - Network security auditing tool designed to analyze the forensics behind compromised and/or vulnerable daemons.
Honeypot extensions to Wireshark
- Wireshark Extensions - Apply Snort IDS rules and signatures against packet capture files using Wireshark.
Client
- CWSandbox / GFI Sandbox
- Capture-HPC-Linux
- Capture-HPC-NG (⭐11)
- Capture-HPC - High interaction client honeypot (also called honeyclient).
- HoneyBOT
- HoneyC
- HoneySpider Network (⭐29) - Highly-scalable system integrating multiple client honeypots to detect malicious websites.
- HoneyWeb - Web interface created to manage and remotely share Honeyclients resources.
- Jsunpack-n (⭐164)
- MonkeySpider
- PhoneyC (⭐26) - Python honeyclient (later replaced by Thug).
- Pwnypot - High Interaction Client Honeypot.
- Rumal - Thug's Rumāl: a Thug's dress and weapon.
- Shelia - Client-side honeypot for attack detection.
- Thug - Python-based low-interaction honeyclient.
- Thug Distributed Task Queuing
- Trigona
- URLQuery
- YALIH (Yet Another Low Interaction Honeyclient) (⭐68) - Low-interaction client honeypot designed to detect malicious websites through signature, anomaly, and pattern matching techniques.
Honeypot
PDF document inspector
- peepdf (⭐1.4k) - Powerful Python tool to analyze PDF documents.
Hybrid low/high interaction honeypot
SSH Honeypots
- Blacknet (⭐20) - Multi-head SSH honeypot system.
- Cowrie (⭐5.5k) - Cowrie SSH Honeypot (based on kippo).
- DShield docker (⭐15) - Docker container running cowrie with DShield output enabled.
- endlessh (⭐7.6k) - SSH tarpit that slowly sends an endless banner. (docker image)
- HonSSH (⭐374) - Logs all SSH communications between a client and server.
- HUDINX (⭐5) - Tiny interaction SSH honeypot engineered in Python to log brute force attacks and, most importantly, the entire shell interaction performed by the attacker.
- Kippo (⭐1.7k) - Medium interaction SSH honeypot.
- Kippo_JunOS (⭐10) - Kippo configured to be a backdoored netscreen.
- Kojoney2 (⭐37) - Low interaction SSH honeypot written in Python and based on Kojoney by Jose Antonio Coret.
- Kojoney - Python-based Low interaction honeypot that emulates an SSH server implemented with Twisted Conch.
- Longitudinal Analysis of SSH Cowrie Honeypot Logs (⭐18) - Python based command line tool to analyze cowrie logs over time.
- LongTail Log Analysis @ Marist College - Analyzed SSH honeypot logs.
- Malbait (⭐8) - Simple TCP/UDP honeypot implemented in Perl.
- MockSSH (⭐126) - Mock an SSH server and define all commands it supports (Python, Twisted).
- cowrie2neo (⭐7) - Parse cowrie honeypot logs into a neo4j database.
- go-sshoney (⭐31) - SSH Honeypot.
- go0r (⭐35) - Simple ssh honeypot in Golang.
- gohoney (⭐11) - SSH honeypot written in Go.
- hived (⭐3) - Golang-based honeypot.
- hnypots-agent) (⭐37) - SSH Server in Go that logs username and password combinations.
- honeypot.go (⭐28) - SSH Honeypot written in Go.
- honeyssh (⭐12) - Credential dumping SSH honeypot with statistics.
- hornet (⭐22) - Medium interaction SSH honeypot that supports multiple virtual hosts.
- ssh-auth-logger (⭐21) - Low/zero interaction SSH authentication logging honeypot.
- ssh-honeypot (⭐646) - Fake sshd that logs IP addresses, usernames, and passwords.
- ssh-honeypot (⭐26) - Modified version of the OpenSSH deamon that forwards commands to Cowrie where all commands are interpreted and returned.
- ssh-honeypotd (⭐17) - Low-interaction SSH honeypot written in C.
- sshForShits (⭐39) - Framework for a high interaction SSH honeypot.
- sshesame (⭐1.6k) - Fake SSH server that lets everyone in and logs their activity.
- sshhipot (⭐167) - High-interaction MitM SSH honeypot.
- sshlowpot (⭐14) - Yet another no-frills low-interaction SSH honeypot in Go.
- sshsyrup (⭐97) - Simple SSH Honeypot with features to capture terminal activity and upload to asciinema.org.
- twisted-honeypots (⭐86) - SSH, FTP and Telnet honeypots based on Twisted.
Distributed sensor project
A pcap analyzer
Network traffic redirector
Honeypot Distribution with mixed content
Honeypot sensor
- Honeeepi - Honeypot sensor on a Raspberry Pi based on a customized Raspbian OS.
File carving
Behavioral analysis tool for win32
Live CD
- DAVIX - The DAVIX Live CD.
Spamtrap
- Mail::SMTP::Honeypot - Perl module that appears to provide the functionality of a standard SMTP server.
- Mailoney (⭐264) - SMTP honeypot written in python.
- SendMeSpamIDS.py (⭐12) - Simple SMTP fetch all IDS and analyzer.
- Shiva (⭐136) - Spam Honeypot with Intelligent Virtual Analyzer.
- SMTPLLMPot (⭐6) - A super simple SMTP Honeypot built using GPT3.5
- SpamHAT (⭐26) - Spam Honeypot Tool.
- Spamhole
- honeypot (⭐2) - The Project Honey Pot un-official PHP SDK.
- spamd
Commercial honeynet
- Cymmetria Mazerunner - Leads attackers away from real targets and creates a footprint of the attack.
Server (Bluetooth)
Dynamic analysis of Android apps
Dockerized Low Interaction packaging
- Docker honeynet (⭐22) - Several Honeynet tools set up for Docker containers.
- Dockerized Thug - Dockerized Thug (⭐1k) to analyze malicious web content.
- Dockerpot (⭐148) - Docker based honeypot.
- Manuka (⭐24) - Docker based honeypot (Dionaea and Kippo).
- honey_ports (⭐7) - Very simple but effective docker deployed honeypot to detect port scanning in your environment.
- mhn-core-docker (⭐34) - Core elements of the Modern Honey Network implemented in Docker.
Network analysis
SIP Server
IOT Honeypot
- HoneyThing (⭐123) - TR-069 Honeypot.
- Kako (⭐27) - Honeypots for a number of well known and deployed embedded device vulnerabilities.
- Honeytokens
- CanaryTokens (⭐1.8k) - Self-hostable honeytoken generator and reporting dashboard; demo version available at CanaryTokens.org.
- Honeybits (⭐272) - Simple tool designed to enhance the effectiveness of your traps by spreading breadcrumbs and honeytokens across your production servers and workstations to lure the attacker toward your honeypots.
- Honeyλ (HoneyLambda) (⭐516) - Simple, serverless application designed to create and monitor URL honeytokens, on top of AWS Lambda and Amazon API Gateway.
- dcept (⭐505) - Tool for deploying and detecting use of Active Directory honeytokens.
- honeyku (⭐63) - Heroku-based web honeypot that can be used to create and monitor fake HTTP endpoints (i.e. honeytokens).
Honeyd Tools
Honeyd plugin
Honeyd viewer
Honeyd to MySQL connector
A script to visualize statistics from honeyd
- Honeyd stats
Network and Artifact Analysis
Sandbox
- Argos - Emulator for capturing zero-day attacks.
- COMODO automated sandbox
- Cuckoo - Leading open source automated malware analysis system.
- Pylibemu (⭐126) - Libemu Cython wrapper.
- RFISandbox - PHP 5.x script sandbox built on top of funcall.
- dorothy2 (⭐197) - Malware/botnet analysis framework written in Ruby.
- imalse (⭐13) - Integrated MALware Simulator and Emulator.
- libemu (⭐151) - Shellcode emulation library, useful for shellcode detection.
Sandbox-as-a-Service
- Hybrid Analysis - Free malware analysis service powered by Payload Security that detects and analyzes unknown threats using a unique Hybrid Analysis technology.
- Joebox Cloud - Analyzes the behavior of malicious files including PEs, PDFs, DOCs, PPTs, XLSs, APKs, URLs and MachOs on Windows, Android and Mac OS X for suspicious activities.
- VirusTotal - Analyze suspicious files and URLs to detect types of malware, and automatically share them with the security community.
- malwr.com - Free malware analysis service and community.
Data Tools
Front Ends
- DionaeaFR (⭐66) - Front Web to Dionaea low-interaction honeypot.
- Django-kippo (⭐12) - Django App for kippo SSH Honeypot.
- Shockpot-Frontend (⭐3) - Full featured script to visualize statistics from a Shockpot honeypot.
- Tango (⭐254) - Honeypot Intelligence with Splunk.
- Wordpot-Frontend (⭐5) - Full featured script to visualize statistics from a Wordpot honeypot.
- honeyalarmg2 (⭐4) - Simplified UI for showing honeypot alarms.
- honeypotDisplay (⭐3) - Flask website which displays data gathered from an SSH Honeypot.
Visualization
- Acapulco (⭐10) - Automated Attack Community Graph Construction.
- Afterglow Cloud (⭐15)
- Afterglow
- Glastopf Analytics (⭐3) - Easy honeypot statistics.
- HoneyMalt (⭐14) - Maltego tranforms for mapping Honeypot systems.
- HoneyMap (⭐219) - Real-time websocket stream of GPS events on a fancy SVG world map.
- HoneyStats - Statistical view of the recorded activity on a Honeynet.
- HpfeedsHoneyGraph (⭐15) - Visualization app to visualize hpfeeds logs.
- IVRE (⭐3.7k) - Network recon framework, published by @cea-sec & @ANSSI-FR. Build your own, self-hosted and fully-controlled alternatives to Criminalip / Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, collect and analyse network intelligence from your sensors, and much more!
- Kippo stats (⭐18) - Mojolicious app to display statistics for your kippo SSH honeypot.
- Kippo-Graph - Full featured script to visualize statistics from a Kippo SSH honeypot.
- The Intelligent HoneyNet (⭐62) - Create actionable information from honeypots.
- ovizart (⭐47) - Visual analysis for network traffic.
Guides
Deployment
- Dionaea and EC2 in 20 Minutes - Tutorial on setting up Dionaea on an EC2 instance.
- Using a Raspberry Pi honeypot to contribute data to DShield/ISC - The Raspberry Pi based system will allow us to maintain one code base that will make it easier to collect rich logs beyond firewall logs.
- honeypotpi (⭐34) - Script for turning a Raspberry Pi into a HoneyPot Pi.
Research Papers
- Honeypot research papers (⭐31) - PDFs of research papers on honeypots.
- vEYE - Behavioral footprinting for self-propagating worm detection and profiling.
Jul 30 - Aug 05, 2018
Related Lists
- awesome-pcaptools (⭐3.2k) - Useful in network traffic analysis.
- awesome-malware-analysis (⭐12k) - Some overlap here for artifact analysis.
Aug 10 - Aug 16, 2015
Guides
Jul 06 - Jul 12, 2015
Guides