Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Honeypots
  3. HoneyThing

HoneyThing

GPL-3.0Python

A honeypot that emulates vulnerable TR-069 (CWMP) devices to detect and analyze attacks targeting IoT modems/routers.

GitHubGitHub
128 stars44 forks0 contributors

What is HoneyThing?

HoneyThing is a honeypot that emulates IoT devices using the TR-069 (CWMP) protocol, commonly found in modems and routers. It simulates vulnerabilities like Misfortune Cookie and Rom-0 to attract attackers, log their activities, and help security researchers analyze threats targeting embedded systems.

Target Audience

Security researchers, IoT security professionals, and network administrators focused on detecting and studying attacks against TR-069-enabled devices.

Value Proposition

It provides a specialized, open-source honeypot for TR-069 devices with realistic protocol emulation and vulnerability simulation, filling a gap in IoT threat detection tools.

Overview

TR-069 Honeypot

Use Cases

Best For

  • Detecting and analyzing attacks targeting TR-069 (CWMP) devices
  • Studying exploitation attempts against RomPager vulnerabilities
  • Security research on IoT modem/router threats
  • Deploying decoy systems in network security monitoring
  • Logging and parsing attacker interactions with simulated IoT devices
  • Academic or research projects on honeypot technologies

Not Ideal For

  • Production environments needing real TR-069 device functionality for operational purposes
  • Security teams requiring a multi-protocol honeypot for broad threat detection
  • Systems without Python 2.7 or PycURL support, due to installation dependencies
  • Users seeking out-of-the-box deployment with stable, pre-built packages

Pros & Cons

Pros

Targeted Protocol Emulation

Implements common TR-069 commands like GetRPCMethods and SetParameterValues, providing realistic simulation of modem/router devices to bait attackers effectively.

Vulnerability Baiting

Emulates known RomPager vulnerabilities such as Misfortune Cookie and Rom-0, specifically attracting exploit attempts against IoT devices.

Engaging Attacker Interface

Includes a modem-like web interface to increase interaction with attackers, enhancing logging opportunities for security analysis.

Parsable Logging

Logs all HTTP and CWMP communications in text formats, making it easy to analyze attacker activities and patterns for research.

Cons

Outdated Python Dependency

Requires Python 2.7, which is end-of-life and unsupported, posing security risks and compatibility issues for modern systems.

Incomplete Packaging

Pre-built Debian and RPM packages are noted as 'will be available soon' in the README, indicating unreliable or manual installation processes.

Limited English Documentation

The primary academic paper is in Turkish, reducing accessibility and support for non-Turkish speaking security researchers.

Frequently Asked Questions

Quick Stats

Stars128
Forks44
Contributors0
Open Issues4
Last commit10 years ago
CreatedSince 2015

Tags

#honeypot#vulnerability-emulation#iot-security#python#network-security#threat-detection

Built With

P
PycURL
P
Python

Included in

Honeypots10.2k
Auto-fetched 18 hours ago

Related Projects

T-PotT-Pot

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

Stars9,360
Forks1,379
Last commit1 month ago
EndlesshEndlessh

SSH tarpit that slowly sends an endless banner

Stars8,496
Forks300
Last commit2 years ago
CowrieCowrie

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

Stars6,480
Forks1,041
Last commit1 day ago
AndroguardAndroguard

Reverse engineering and pentesting for Android applications

Stars6,161
Forks1,139
Last commit1 month ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub