A serverless application to create and monitor fake HTTP endpoints (URL honeytokens) on AWS Lambda and API Gateway.
honeyλ is a serverless application that creates and monitors fake HTTP endpoints, known as URL honeytokens, to detect malicious activity. It automatically deploys on AWS Lambda and API Gateway, providing alerts via Slack, email, or SMS when a trap is triggered. The tool helps identify attackers, malicious insiders, content scrapers, or bad bots by placing these tokens in documents, emails, or web pages.
Security engineers, DevOps professionals, and cloud administrators looking to implement lightweight, automated threat detection in serverless environments. It's also suitable for organizations needing cost-effective, scalable honeytoken deployment without managing infrastructure.
Developers choose honeyλ for its simplicity, serverless architecture, and pay-per-use model, eliminating the need to manage servers. It offers flexible alerting, threat intelligence integration, and customizable responses, making it a versatile tool for proactive security monitoring in cloud-native setups.
honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS Lambda and Amazon API Gateway
Built on AWS Lambda and API Gateway with a pay-per-use model, eliminating server management costs and scaling automatically, as highlighted in the README's 'pay-what-you-use' description.
Integrates Slack, email, and SMS via Twilio for real-time notifications when honeytokens are triggered, providing flexible monitoring options as shown in the setup instructions.
Allows customization of HTTP responses per token, including binary data like tracking pixels, though it requires manual API Gateway configuration for binary media types.
Enhances alerts by looking up source IPs against Cymon API v2 feeds, adding context to detections as demonstrated in the Slack alert screenshot.
Requires manual steps in AWS API Gateway console to enable binary media types for image responses, adding deployment complexity and potential for errors.
Although provider-agnostic via Serverless framework, it's only tested on AWS, and the README admits the main function may need changes for other providers.
Relies on external services like Slack, Twilio, and Cymon, which introduce points of failure and require separate account setups, increasing operational overhead.
🍯 T-Pot - The All In One Multi Honeypot Platform 🐝
SSH tarpit that slowly sends an endless banner
Reverse engineering and pentesting for Android applications
Modular and decentralised honeypot
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.