Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Honeypots
  3. Honeytrap

Honeytrap

NOASSERTIONGo

An extensible open-source framework for running, monitoring, and managing honeypots to detect and analyze cyber threats.

Visit WebsiteGitHubGitHub
1.3k stars182 forks0 contributors

What is Honeytrap?

Honeytrap is an extensible open-source framework for deploying, monitoring, and managing honeypots. It enables security teams to set up low- to high-interaction honeypots that mimic real services, helping detect and analyze malicious activity, lateral movement, and payload-based attacks in networks.

Target Audience

Security professionals, SOC teams, and network administrators who need to monitor for intrusions, gather threat intelligence, or test their network defenses using honeypot technology.

Value Proposition

Developers choose Honeytrap for its extensibility, centralized management of multiple agents, support for both low- and high-interaction honeypots, and advanced logging integrations with tools like Elasticsearch and Splunk.

Overview

Advanced Honeypot framework.

Use Cases

Best For

  • Deploying centralized honeypot networks with multiple agents
  • Monitoring lateral movement and payload-based attacks in internal networks
  • Integrating existing honeypots like cowrie or glutton into a unified framework
  • Setting up high-interaction honeypots using LXC or remote hosts
  • Logging and analyzing honeypot data to Elasticsearch, Kafka, or Splunk
  • Redirecting suspicious traffic from production networks to isolated environments

Not Ideal For

  • Organizations needing a simple, GUI-based honeypot solution for quick deployment without command-line configuration
  • Teams with limited resources for ongoing maintenance and monitoring of complex honeypot infrastructures
  • Environments where minimal performance overhead is critical, as high-interaction modes involve resource-intensive proxying

Pros & Cons

Pros

Extensible Honeypot Framework

Allows integration of existing honeypots like cowrie or glutton, enabling reuse within Honeytrap's logging and management system, as highlighted in the features list.

Centralized Multi-Agent Management

Supports deploying many agents that automatically download configuration from a central server, simplifying large-scale honeypot deployments, as described in the centralized management feature.

Advanced Payload Detection

Uses payload analysis to handle multiple protocols on a single port, improving detection of sophisticated attacks, based on the payload detection capability mentioned.

Flexible Interaction Levels

Provides seamless upgrades from low- to high-interaction honeypots, including LXC or remote host directors for in-depth monitoring, as noted in the seamless interaction upgrades feature.

Comprehensive Logging Integrations

Logs to various backends like Elasticsearch, Kafka, and Splunk with filtering, facilitating integration into existing security workflows, per the advanced logging system description.

Cons

Complex Initial Setup

Requires significant configuration and understanding of honeypot concepts, as evidenced by the need to refer to external documentation for getting started.

Resource Intensive Operations

High-interaction honeypots, especially using LXC or man-in-the-middle proxying, can consume substantial system resources, potentially impacting performance.

Limited Built-in Services

While extensible, out-of-the-box services might be basic, requiring custom development or integration for specific use cases not covered by default.

Community-Dependent Support

As an open-source project, support relies on community forums and mailing lists, which may not provide timely assistance for critical issues compared to commercial solutions.

Frequently Asked Questions

Quick Stats

Stars1,306
Forks182
Contributors0
Open Issues114
Last commit2 years ago
CreatedSince 2017

Tags

#honeypot#splunk#kafka#security#framework#intrusion-detection#network-security#docker#cybersecurity#go#elasticsearch#honeypot-framework#threat-detection

Built With

G
Go
D
Docker

Links & Resources

Website

Included in

Malware Analysis13.6kHoneypots10.2k
Auto-fetched 22 hours ago

Related Projects

T-PotT-Pot

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

Stars9,423
Forks1,383
Last commit17 days ago
EndlesshEndlessh

SSH tarpit that slowly sends an endless banner

Stars8,542
Forks300
Last commit2 years ago
CowrieCowrie

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

Stars6,500
Forks1,055
Last commit3 days ago
CowrieCowrie

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

Stars6,500
Forks1,055
Last commit3 days ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub