Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Honeypots
  3. Honeyλ (HoneyLambda)

Honeyλ (HoneyLambda)

GPL-3.0Python

A serverless application to create and monitor fake HTTP endpoints (URL honeytokens) on AWS Lambda and API Gateway.

GitHubGitHub
525 stars55 forks0 contributors

What is Honeyλ (HoneyLambda)?

honeyλ is a serverless application that creates and monitors fake HTTP endpoints, known as URL honeytokens, to detect malicious activity. It automatically deploys on AWS Lambda and API Gateway, providing alerts via Slack, email, or SMS when a trap is triggered. The tool helps identify attackers, malicious insiders, content scrapers, or bad bots by placing these tokens in documents, emails, or web pages.

Target Audience

Security engineers, DevOps professionals, and cloud administrators looking to implement lightweight, automated threat detection in serverless environments. It's also suitable for organizations needing cost-effective, scalable honeytoken deployment without managing infrastructure.

Value Proposition

Developers choose honeyλ for its simplicity, serverless architecture, and pay-per-use model, eliminating the need to manage servers. It offers flexible alerting, threat intelligence integration, and customizable responses, making it a versatile tool for proactive security monitoring in cloud-native setups.

Overview

honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS Lambda and Amazon API Gateway

Use Cases

Best For

  • Deploying automated honeytokens in AWS serverless environments
  • Detecting malicious bots or scrapers via fake HTTP endpoints
  • Monitoring for insider threats using hidden URL traps in documents
  • Setting up lightweight threat detection with Slack or email alerts
  • Integrating threat intelligence feeds for source IP analysis
  • Creating tracking pixels for email or web page monitoring

Not Ideal For

  • Teams deploying on cloud providers other than AWS without willingness to modify the Lambda function code
  • Projects requiring advanced HTTP client fingerprinting capabilities immediately, as it's a pending feature
  • Organizations with strict data privacy policies that prohibit using third-party APIs like Cymon or Twilio
  • Small teams lacking AWS operational expertise for manual API Gateway binary support configuration

Pros & Cons

Pros

Serverless Cost Efficiency

Built on AWS Lambda and API Gateway with a pay-per-use model, eliminating server management costs and scaling automatically, as highlighted in the README's 'pay-what-you-use' description.

Multi-Channel Alerting

Integrates Slack, email, and SMS via Twilio for real-time notifications when honeytokens are triggered, providing flexible monitoring options as shown in the setup instructions.

Custom Response Flexibility

Allows customization of HTTP responses per token, including binary data like tracking pixels, though it requires manual API Gateway configuration for binary media types.

Threat Intelligence Integration

Enhances alerts by looking up source IPs against Cymon API v2 feeds, adding context to detections as demonstrated in the Slack alert screenshot.

Cons

Manual Cloud Configuration

Requires manual steps in AWS API Gateway console to enable binary media types for image responses, adding deployment complexity and potential for errors.

Limited Cross-Cloud Testing

Although provider-agnostic via Serverless framework, it's only tested on AWS, and the README admits the main function may need changes for other providers.

Third-Party Service Dependencies

Relies on external services like Slack, Twilio, and Cymon, which introduce points of failure and require separate account setups, increasing operational overhead.

Frequently Asked Questions

Quick Stats

Stars525
Forks55
Contributors0
Open Issues3
Last commit7 years ago
CreatedSince 2017

Tags

#api-gateway#lambda#honeypot#honeytoken#serverless#security#python#twilio#aws-lambda#security-monitoring#aws#deception#cloud-security#threat-detection

Built With

A
Amazon API Gateway
A
Amazon S3
S
Serverless Framework
A
AWS Lambda

Included in

Honeypots10.2k
Auto-fetched 4 hours ago

Related Projects

T-PotT-Pot

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

Stars9,208
Forks1,363
Last commit2 months ago
EndlesshEndlessh

SSH tarpit that slowly sends an endless banner

Stars8,455
Forks303
Last commit1 year ago
AndroguardAndroguard

Reverse engineering and pentesting for Android applications

Stars6,066
Forks1,139
Last commit4 months ago
OpenCanaryOpenCanary

Modular and decentralised honeypot

Stars2,863
Forks397
Last commit1 day ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub