The "Awesome Honeypots" project is a curated collection of resources focused on honeypots, which are decoy systems designed to attract and analyze potential cyber attacks. This list includes various types of honeypot software, deployment tools, research papers, and case studies that illustrate their effectiveness in cybersecurity. It benefits security professionals, researchers, and organizations looking to enhance their threat detection capabilities and understand attacker behavior. By leveraging these resources, users can improve their security posture and gain valuable insights into the tactics employed by malicious actors.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.
The "Awesome Hacking" project is a curated resource list designed for those interested in the field of hacking, which involves exploring and exploiting vulnerabilities in computer systems and networks. This list encompasses a wide range of categories, including penetration testing tools, ethical hacking tutorials, security research papers, and community forums. It serves as a valuable resource for beginners looking to learn the basics of cybersecurity, as well as experienced professionals seeking advanced techniques and tools. Whether you are aiming to enhance your skills or stay updated on the latest security trends, this collection offers a wealth of information to support your hacking journey.
The "Awesome Security" project is a curated collection of resources focused on enhancing security practices in the digital realm. This list encompasses a wide range of categories including security tools, libraries, frameworks, tutorials, and best practices for various platforms and technologies. It is designed to benefit security professionals, developers, and system administrators alike, providing valuable insights and tools to safeguard applications and data. Whether you are a beginner looking to understand security fundamentals or an experienced practitioner seeking advanced techniques, this project offers a wealth of information to help you improve your security posture and protect your digital assets.
The "Awesome Malware Analysis" project is a curated resource list designed to assist security professionals and researchers in the field of malware analysis. Malware analysis involves examining malicious software to understand its behavior, functionality, and impact. This list includes tools for static and dynamic analysis, reverse engineering resources, malware databases, and educational materials such as tutorials and courses. It is valuable for both beginners looking to learn the basics and experienced analysts seeking advanced techniques and tools. Users can find a wealth of resources to enhance their skills and improve their malware analysis capabilities.
The "Awesome Web Security" project is a curated collection of resources focused on the security of web applications and services. Web security encompasses practices and technologies designed to protect websites and online services from cyber threats, vulnerabilities, and attacks. This list includes tools for penetration testing, secure coding practices, frameworks, libraries, and educational materials such as articles and tutorials. It is valuable for developers, security professionals, and researchers who seek to enhance their understanding of web security and implement robust security measures. Users can find essential tools and knowledge to safeguard their web applications effectively and stay ahead of potential threats.
A Python-based Elasticsearch honeypot that detects and analyzes attacks exploiting the CVE-2015-1427 Groovy vulnerability.
An Elasticsearch honeypot written in Node.js to capture exploitation attempts targeting CVE-2014-3120.
A honeypot designed to detect and log attacks targeting Elasticsearch remote code execution vulnerabilities.
A honeypot proxy that logs all traffic to a dummy MongoDB server to detect and analyze attack attempts.
An open-source honeypot framework for NoSQL databases that simulates servers to detect and log attacks.
A low-interaction MySQL honeypot written in C that logs unauthorized access attempts.
A low-interaction honeypot that mimics a PostgreSQL server to detect and log unauthorized connection attempts.
A medium-interaction PostgreSQL honeypot that logs attacker queries and connections for security monitoring.
A high-interaction honeypot system that emulates Redis protocol to detect and analyze unauthorized access attempts.
An Express.js honeypot that catches bots scanning for remote and local file inclusion vulnerabilities using fake URLs.
A Symfony bundle that adds honeypot spam protection to forms by detecting and blocking automated bot submissions.
A high-performance HTTP honeypot that punishes unruly bots by serving them an infinite stream of deceptive content.
A Laravel package that prevents spam using honeypot fields and form submission timing validation.
A hybrid AI honeypot for detecting and interacting with mass web application exploitation attempts.
A Node.js web application honeypot designed for small environments like Raspberry Pi.
A REST API honeypot that logs malicious API requests to detect and analyze attacks.
Apache 2-based honeypot and detection module for detecting and blocking the Struts CVE-2017-5638 exploit.
A honeypot webservice that logs HTTP basic authentication attempts in a parser-friendly format.
A high-interaction honeypot for HTTP/HTTPS that emulates vulnerable web applications to observe attacker behavior.
A honeypot that mimics Drupal CMS to detect and log malicious scanning and attack attempts.
An LLM-powered web honeypot that dynamically crafts realistic HTTP responses to mimic various applications and detect malicious traffic.
A Python-based web server honeypot and service imitation builder for faking HTTP services and recording requests.
A honeypot that mimics a vulnerable file upload endpoint to detect and collect malicious uploads.
A modular web application honeypot framework written in Go and Gin for detecting web attacks through deceptive applications.
A Flask-based honeypot that mimics Outlook Web Access to detect and log authentication attempts.
A simple and effective honeypot that mimics phpMyAdmin to detect and log unauthorized access attempts.
A PHP script implementing a smart honeypot form with server-side validation and email submission.
A web application honeypot sensor that clones websites to attract and analyze malicious attacks.
A remote data analysis and classification service that evaluates HTTP requests and emulates vulnerabilities for honeypot systems.
A PHP middleware that inserts hidden spam trap fields into forms to detect and block spambots.
A WordPress honeypot plugin that logs failed login attempts to a publicly accessible file.
A Python-based WordPress honeypot that mimics a WordPress installation to detect and log attack attempts.
A WordPress plugin that reduces comment spam using a smarter honeypot technique with randomized fields and form expiration.
A WordPress honeypot that detects probes for plugins, themes, and common files used to fingerprint WordPress installations.
An open-source Python framework for creating honeypots and honeynets to detect and analyze cyber attacks.
A low-interaction honeypot that mimics Android Debug Bridge (ADB) over TCP/IP to capture malware targeting exposed port 5555.
A honeypot platform for monitoring and analyzing UDP-based DDoS amplification attacks via DNS, NTP, SSDP, Chargen, and generic UDP services.
A low-interaction honeypot that emulates vulnerable services to capture malware and analyze attacks.
A simple Docker honeypot server that emulates parts of the Docker HTTP API to detect and log reconnaissance and container creation attempts.
A software-defined networking honeypot that captures and analyzes malicious traffic by simulating vulnerable network services.
A Ruby on Rails gem plugin for deploying a malicious behavior detection and response honeypot in under ten minutes.
A Kubernetes API honeypot with multi-protocol emulation and active defense capabilities for detecting malicious infrastructure attacks.
A Python-based NTP honeypot that logs NTP scan attempts and DDoS reconnaissance into Redis for security monitoring.
A proof-of-concept honeypot that mimics an observation camera with simulated features to detect unauthorized access.
A Python-based FTP honeypot that captures credentials, malware files, and distributes honeytokens.
A Python package with 30 low-high level honeypots for monitoring network traffic, bots, and credential attacks.
An extensible open-source framework for running, monitoring, and managing honeypots to detect and analyze cyber threats.
A low to medium interaction honeypot written in Python, designed for easy deployment and extensibility.
A modular, medium-interaction honeypot built with Python and Twisted for detecting and analyzing cyber attacks.
Bash and Python scripts that listen on unused ports and automatically blacklist IPs that connect to them.
A printer honeypot proof-of-concept that simulates network printers to detect and analyze unauthorized access attempts.
A low-interaction honeypot that simulates Oracle MICROS servers to detect exploitation attempts of the CVE-2018-2636 directory traversal vulnerability.
A Node.js FTP honeypot that captures malicious file uploads from bots and scanners.
A Python RDP man-in-the-middle tool and library for intercepting, monitoring, and analyzing Remote Desktop Protocol connections.
An RDP honeypot that captures attack telemetry by simulating Windows RDP sessions with virtual machines.
A pure Python implementation of Microsoft's Remote Desktop Protocol (RDP) and VNC client/server, built on Twisted.
A high-interaction honeypot that emulates the SMB protocol to detect and analyze network attacks.
A network security honeypot designed to detect and analyze malicious activity as featured in Applied Network Security Monitoring.
A low-interaction honeypot that mimics network services and clones websites with AI-powered responses to detect intruders.
A honeypot that isolates each attacker connection in a separate LXC container for monitoring and analysis.
A low-interaction honeypot that detects exploitation attempts targeting the CVE-2017-10271 WebLogic remote code execution vulnerability.
A Twisted-based honeypot for detecting and logging network attacks.
A distributed low-interaction honeypot with agent/master architecture for monitoring attacks across multiple protocols.
A script to detect and remove Thinkst Canarytokens from files using signature-based detection.
A signature-based, multi-threaded honeypot detection tool written in Go that identifies emulated services via crafted requests.
A proof-of-concept tool to externally detect Kippo SSH honeypot instances.
An open-source ICS/SCADA honeypot designed to emulate industrial control systems and collect adversary intelligence.
A honeypot that simulates Veeder Root Guardian AST tank gauges used in gas stations to detect and log cyber threats.
Open-source tools for creating realistic-behaving electric grid honeynets to detect and analyze cyber threats.
A minimal honeypot that detects unauthorized connection attempts and triggers customizable alerts.
A DICOM honeypot server that logs and analyzes medical imaging protocol traffic for security monitoring.
A honeypot that detects and logs exploitation attempts targeting the Log4Shell vulnerability (CVE-2021-44228).
A low-interaction honeypot that responds to network scanners and bots across multiple protocols, designed for self-hosted threat intelligence.
A honeypot that emulates HL7/FHIR healthcare data interfaces to detect and log unauthorized access attempts.
An OpenFlow honeypot that redirects traffic destined for unused IP addresses to a specified honeypot using ARP spoofing and MAC address manipulation.
A modular, low-resource network honeypot that mimics services to detect breaches and alert on attacker interactions.
A low-interaction honeypot that emulates Cisco ASA devices to detect exploitation attempts targeting CVE-2018-0101.
A medium interaction printer honeypot that mimics an exposed network printer to detect and log attacks.
A modular botnet command & control monitor for tracking and researching malware networks via IRC, HTTP, and XMPP.
IPv6 attack detector that identifies link-local security threats from tools like THC-IPv6 and Nmap.
A honeypot that mimics the TCP 32764 router backdoor to detect and log exploitation attempts.
A honeypot that emulates a Belkin N300 wireless router to observe malicious traffic targeting home networks.
A Windows security tool for real-time adversary tradecraft detection, memory scanning, and forensics via behavior-driven rules.
A honeypot that emulates USB storage devices to detect and capture malware that spreads via USB propagation.
A modular Perl framework for passive network security assessment by analyzing traffic with multiple analysis engines.
A script that generates VirtualBox templates to harden Windows VMs against malware detection.
Automated tool for creating and preparing virtual machines for Cuckoo Sandbox malware analysis.
A Lua wrapper and debugger backend for Intel PIN, enabling dynamic binary instrumentation via Lua scripts.
A backend-agnostic debugger frontend for reverse engineering and analyzing binaries without source code access.
A Python toolkit for reverse engineering, analyzing, and pentesting Android applications (APK, DEX, resources).
An all-in-one, optionally distributed, multi-architecture honeypot platform with 20+ honeypots, visualization via Elastic Stack, and live attack maps.
A secure low-code honeypot framework that uses AI to create high-interaction decoy systems for cyber attack detection and analysis.
An open-source blue team tool that protects Linux and Windows operating systems through multiple security methods.
Ansible playbook for automatically deploying the Bifrozt honeypot system.
A low-interaction Python honeypot that mimics vulnerable services to detect and log intrusion attempts.
A Python-based Telnet honeypot that emulates a Telnet service inside a chroot environment to capture malicious activity.
An open-source telnet honeypot designed to detect and fingerprint IoT botnets like Mirai by simulating vulnerable devices.
A DNS honeypot that logs requests to SQLite/JSON and mimics an open resolver with configurable sinkhole behavior.
A lightweight honeypot written in Go that emulates SSH and Telnet services to log attacker activity.
A low-interaction honeypot designed to detect and analyze network attacks with minimal resource usage.
A free, cross-platform, single-file fake protocol server simulator that can start or stop multiple network services.
A protocol-agnostic, low-interaction honeypot that intercepts and logs network traffic to analyze malicious activities.
A honeypot server written in Go that logs attacker interactions to a database.
A collection of honeypot service emulators written in Go for improved security and performance.
A configurable SMTP honeypot written in Go that captures and analyzes spam emails for security research.
A low-interaction honeypot that catches attacks against TCP and UDP services by emulating protocols, mirroring, or proxying connections.
A lightweight IMAP and SMTP honeypot written in Go for detecting and logging email protocol attacks.
A scalable SSH/TCP honeypot using Linux security features, designed for OpenWrt and IoT devices.
A Rust-based port listener and honeypot with protocol guessing, safe string display, and SQLite logging.
A Python telnet honeypot that emulates a shell environment to catch IoT botnet binaries and analyze malware networks.
A Telnet honeypot that logs failed login attempts to track botnet activity like Mirai.
A low-interaction VNC honeypot that logs authentication attempts against a static challenge.
A lightweight authenticated publish-subscribe protocol for binary data feeds, commonly used in security monitoring.
Creates fake file systems for honeypots using LLMs to generate realistic lures and configurations for threat engagement.
A browser emulation tool that detects exploits targeting browser and browser plugin vulnerabilities by analyzing various file types.
A Python honeyclient for detecting malicious web content through client-side emulation and analysis.
A low-interaction client honeypot that detects malicious websites using signature, anomaly, and pattern matching techniques.
A honeypot that logs attacks on instant messaging protocols to analyze malicious activity patterns.
A Python tool for analyzing PDF files to detect malicious content and perform security research.
A Docker container running the Cowrie SSH honeypot with DShield reporting to contribute to internet threat intelligence.
An SSH tarpit that slowly sends an endless banner to trap and waste attackers' time.
A medium interaction SSH honeypot that logs brute force attacks and attacker shell interactions in Python.
A medium interaction SSH honeypot that logs brute force attacks and attacker shell interactions.
A medium interaction SSH honeypot designed to log brute force attacks and attacker shell interactions.
A command-line map-reduce tool for analyzing and visualizing SSH Cowrie honeypot logs over time.
A simple Perl honeypot that creates fake TCP/UDP servers to monitor and log malicious network traffic.
A Python library to mock SSH servers and define custom commands for testing automation scripts.
Parses Cowrie honeypot logs and imports them into a Neo4j graph database for security analysis.
A lightweight SSH honeypot that logs connection attempts, including IP, username, password, and client version.
A simple SSH honeypot written in Go to log and monitor unauthorized SSH login attempts.
A Go-based SSH honeypot that logs attacker commands and IP addresses in a fake shell environment.
A honeypot for detecting and analyzing unauthorized access attempts.
A Go-based honeypot agent that emulates multiple network services to capture attacker activity and credentials.
A Go-based SSH honeypot that logs and notifies you of unauthorized SSH login attempts on your server.
An SSH honeypot that logs credentials from brute-force attacks and provides statistics via an HTTP API.
A low/zero interaction SSH authentication logging honeypot that logs attempts as structured JSON.
A low-interaction SSH honeypot that logs attacker IPs, usernames, and passwords for security intelligence.
A modified OpenSSH daemon that forwards attacker commands to Cowrie for logging and interaction interpretation.
A low-interaction SSH honeypot written in C for detecting and logging unauthorized access attempts.
A framework for building high-interaction SSH honeypots with customizable command emulation.
A lightweight SSH honeypot that logs all connection attempts and activity without executing commands.
A high-interaction SSH honeypot that logs and proxies attacker connections to a real SSH server.
A no-frills low-interaction SSH honeypot written in Go that logs authentication attempts.
A low-to-medium interaction SSH honeypot written in Go that captures terminal sessions and logs attacker activity.
A Python-based honeypot suite for SSH, FTP, and Telnet that captures credentials to build attack dictionaries.
A modern SMTP honeypot that simulates a vulnerable mail server to capture and log email-based attacks with database integration.
A lightweight honeypot for analyzing network attacks with configurable services and LEEF-compliant logging.
A Python-based spam honeypot that acts as an SMTP server to collect, analyze, and track spam campaigns for threat intelligence.
A proof-of-concept SMTP honeypot that uses GPT-3.5 to generate realistic email responses.
A Perl-based open relay simulator that captures and analyzes spam emails for security research.
Unofficial PHP SDK for Project Honey Pot to detect malicious visitors and deter new threats.
A Java-based Bluetooth honeypot for Linux that detects and analyzes Bluetooth-based attacks like BlueBugging and BlueSnarfing.
A Docker-based honeypot that creates disposable containers to capture and analyze attack attempts.
A Docker-based script to deploy Dionaea and Kippo honeypots, moving SSH to port 65534 and logging attacks.
A Docker-deployed honeypot that detects port scanning attempts by exposing fake services.
A Dockerized subset of the Modern Honey Network running honeypots (Cowrie and Dionaea) with a centralized broker for event collection and visualization.
A peer-to-peer SIP honeypot and fraud detection tool that collects and shares malicious IP addresses and phone numbers.
A honeypot that emulates vulnerable TR-069 (CWMP) devices to detect and analyze attacks targeting IoT modems/routers.
A Python honeypot framework that simulates vulnerable IoT devices to capture attack sources, droppers, and payloads.
Deploy honeytokens across your network to detect unauthorized access and data exfiltration attempts.
A proof-of-concept tool that spreads deceptive breadcrumbs and honeytokens across systems to lure attackers toward honeypots.
A serverless application to create and monitor fake HTTP endpoints (URL honeytokens) on AWS Lambda and API Gateway.
A honeytoken-based tripwire for detecting Active Directory credential theft and privilege escalation attempts.
A Heroku-based web honeypot for creating and monitoring fake HTTP endpoints (honeytokens) to detect attackers and malicious activity.
A Ruby framework for automated malware and botnet analysis using sandboxed virtual machines and network traffic dissection.
A Django-based web frontend for visualizing and analyzing data from the Dionaea low-interaction honeypot.
A PHP-based web interface for visualizing attack statistics from the Shockpot SSH honeypot.
A Splunk-based platform for deploying honeypots and analyzing attacker sessions with intelligence dashboards and threat feeds.
A PHP-based web dashboard for visualizing attack statistics from the Wordpot WordPress honeypot.
A Splunk app that clusters security events from hpfeeds channels and visualizes them with D3.js parallel coordinates graphs.
A security visualization tool that lets users upload data and generate graphs on-the-fly.
A Perl web application that provides simple statistics and analytics for the Glastopf honeypot.
Maltego transform pack for analyzing and visualizing honeypot data, starting with Kippo honeypot systems.
Real-time visualization of GPS events on an interactive SVG world map using websockets.
A visualization application for analyzing and displaying hpfeeds honeypot log data in graphical form.
A self-hosted network reconnaissance framework for building alternatives to Shodan, ZoomEye, Censys, and GreyNoise.
A honeynet system that deploys multiple honeypots, processes attack data with threat intelligence, and provides a web dashboard for analysis.
A Django-based web application for visual analysis of network traffic from PCAP files.