Showing 36 of 359 projects
A low/zero interaction SSH authentication logging honeypot that logs attempts as structured JSON.
A lightweight IMAP and SMTP honeypot written in Go for detecting and logging email protocol attacks.
An Elixir wrapper for NMAP that provides a programmatic interface for network discovery and security scanning.
A network security honeypot designed to detect and analyze malicious activity as featured in Applied Network Security Monitoring.
An OpenFlow honeypot that redirects traffic destined for unused IP addresses to a specified honeypot using ARP spoofing and MAC address manipulation.
A Python-based Elasticsearch honeypot that detects and analyzes attacks exploiting the CVE-2015-1427 Groovy vulnerability.
A high-interaction honeypot system that emulates Redis protocol to detect and analyze unauthorized access attempts.
A low-interaction Python honeypot that mimics vulnerable services to detect and log intrusion attempts.
A Python DNS crawler that finds identical domain names across different TLDs by querying authoritative SOA records.
A low-interaction VNC honeypot that logs authentication attempts against a static challenge.
A modern web-based management system for Suricata IDS/IPS, featuring advanced analytics and visualization capabilities.
A honeypot that emulates a Belkin N300 wireless router to observe malicious traffic targeting home networks.
A printer honeypot proof-of-concept that simulates network printers to detect and analyze unauthorized access attempts.
A native macOS app for managing your hosts file with curated protection levels to block ads, trackers, and distractions.
A Gemini CLI extension that analyzes packet captures using RAG, MCP, and custom slash commands.
A low-interaction SSH honeypot written in C for detecting and logging unauthorized access attempts.
A low-interaction honeypot that mimics a PostgreSQL server to detect and log unauthorized connection attempts.
A modular, medium-interaction honeypot built with Python and Twisted for detecting and analyzing cyber attacks.
A honeypot that mimics the TCP 32764 router backdoor to detect and log exploitation attempts.
A minimal honeypot that detects unauthorized connection attempts and triggers customizable alerts.
A visualization application for analyzing and displaying hpfeeds honeypot log data in graphical form.
A honeypot that logs attacks on instant messaging protocols to analyze malicious activity patterns.
A Docker container running the Cowrie SSH honeypot with DShield reporting to contribute to internet threat intelligence.
A no-frills low-interaction SSH honeypot written in Go that logs authentication attempts.
A Suricata plugin that outputs Eve JSON events to Apache Kafka for real-time network security monitoring.
An SSH honeypot that logs credentials from brute-force attacks and provides statistics via an HTTP API.
A Go-based SSH honeypot that logs attacker commands and IP addresses in a fake shell environment.
A Go library for reading SiLK network flow data files without C dependencies.
A medium-interaction PostgreSQL honeypot that logs attacker queries and connections for security monitoring.
A GUI interface for Suricata IPS on Qubes OS, providing desktop notifications for suspicious network packets.
Syntax highlighting for Suricata rules in Visual Studio Code.
A command-line tool that formats and syntax highlights Suricata intrusion detection rules for improved readability.
A Go client library for interacting with Suricata's Unix socket to execute commands and retrieve data.
An experimental Rust parser for Suricata rules that converts them into structured JSON/YAML representations.
A zero-dependency Go client library for interacting with the Sophos UTM 9 REST API.
A lightweight honeypot for analyzing network attacks with configurable services and LEEF-compliant logging.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.