{"id":419,"url":"https://github.com/paralax/awesome-honeypots","last_synced_at":"2025-09-27T10:31:01.128Z","repository":{"id":33935688,"uuid":"37659549","full_name":"paralax/awesome-honeypots","owner":"paralax","description":"an awesome list of honeypot resources","archived":false,"fork":false,"pushed_at":"2024-03-25T14:32:04.000Z","size":428,"stargazers_count":8110,"open_issues_count":10,"forks_count":1223,"subscribers_count":379,"default_branch":"master","last_synced_at":"2024-05-22T13:16:59.339Z","etag":null,"topics":["awesome","awesome-list","honeyd","honeypot","list"],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"artistic-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/paralax.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null}},"created_at":"2015-06-18T12:57:01.000Z","updated_at":"2024-05-22T13:01:00.000Z","dependencies_parsed_at":"2022-07-14T09:22:29.535Z","dependency_job_id":"0f4fd0f0-3d30-4fe4-b058-777f93eeac5f","html_url":"https://github.com/paralax/awesome-honeypots","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/paralax%2Fawesome-honeypots","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/paralax%2Fawesome-honeypots/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/paralax%2Fawesome-honeypots/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/paralax%2Fawesome-honeypots/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/paralax","download_url":"https://codeload.github.com/paralax/awesome-honeypots/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":219871971,"owners_count":16554475,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["awesome","awesome-list","honeyd","honeypot","list"],"created_at":"2024-01-05T20:12:54.349Z","updated_at":"2025-09-27T10:31:01.121Z","avatar_url":"https://github.com/paralax.png","language":"Python","funding_links":[],"categories":["Security","Technical","Resources","[↑](#-table-of-contents) Related Awesome Lists","Other Awesome Security Lists","Online Resources","Related Awesome Lists","Uncategorized","Audi-1's SQLi-LABS","Go","Blue Team","Other Awesome Lists","Coordinated disclosure","Other","Network","SOC sensors, nice to have","Python","Table of Contents","Honeypots","Source","🔐 Security","Awesome Lists","HarmonyOS","📚 Learning \u0026 Resources","Awesome Repositories","Live Site:   [searchAwesome](https://search-awesome.vercel.app/)","\u003ca id=\"a2df15c7819a024c2f5c4a7489285597\"\u003e\u003c/a\u003e密罐\u0026\u0026Honeypot","Awesome Penetration Testing","扫描器、资产收集、子域名","安全","Awesome Penetration Testing (\"https://github.com/Muhammd/Awesome-Pentest\")","Responsible disclosure","蜜罐","awesome-list","***Cybersecurity Resources***","AWESOME LISTS","\u003ca id=\"efde8c850d8d09e7c94aa65a1ab92acf\"\u003e\u003c/a\u003e收集","Other Lists","\u003ca id=\"8c5a692b5d26527ef346687e047c5c21\"\u003e\u003c/a\u003e收集","📘 Valuable Repositories","Other Security Awesome Lists","LLM分析过程","Forensics, Reversing, and OSINT","Here is a collection of hackers, pentesters, security researchers, scripts and more:","Themed Directories","Articles","Blue Team, Detection \u0026 Incident Response"],"sub_categories":["awesome-*","Related Awesome Lists","[↑](#-table-of-contents) Telegram","Cloud","Other Lists Online","Uncategorized","CTF Courses","Episodes","Volatility","Other Security Awesome Lists","JavaScript","Other Resources","Other","Honey Pot / Honey Net","Endpoints hardening:","Awesome Repos","Supply chain security","Defcon Suggested Reading","Policy enforcement","Windows Manager","Labs","\u003ca id=\"efde8c850d8d09e7c94aa65a1ab92acf\"\u003e\u003c/a\u003e收集","Awesome Lists","网络服务_其他","Awesome Repositories","策略执行","***Rootkits (Development)***","TeX Lists","CTF Repos","Wifi Tools","Secure OSes","Updated this week"],"readme":"# Awesome Honeypots [![Awesome Honeypots](https://cdn.rawgit.com/sindresorhus/awesome/d7305f38d29fed78fa85652e3a63e154dd8e8829/media/badge.svg)](https://github.com/sindresorhus/awesome)\n\nA curated list of awesome honeypots, plus related components and much more, divided into categories such as Web, services, and others, with a focus on free and open source projects.\n\nThere is no pre-established order of items in each category, the order is for contribution. If you want to contribute, please read the [guide](CONTRIBUTING.md).\n\nDiscover more awesome lists at [sindresorhus/awesome](https://github.com/sindresorhus/awesome).\n\n# Contents\n\n- [Awesome Honeypots ](#awesome-honeypots-)\n- [Contents](#contents)\n  - [Related Lists](#related-lists)\n  - [Honeypots](#honeypots)\n  - [Honeyd Tools](#honeyd-tools)\n  - [Network and Artifact Analysis](#network-and-artifact-analysis)\n  - [Data Tools](#data-tools)\n  - [Guides](#guides)\n\n## Related Lists\n\n- [awesome-pcaptools](https://github.com/caesar0301/awesome-pcaptools) - Useful in network traffic analysis.\n- [awesome-malware-analysis](https://github.com/rshipp/awesome-malware-analysis) - Some overlap here for artifact analysis.\n\n## Honeypots\n\n- Database Honeypots\n\n  - [Delilah](https://github.com/SecurityTW/delilah) - Elasticsearch Honeypot written in Python (originally from Novetta).\n  - [ESPot](https://github.com/mycert/ESPot) - Elasticsearch honeypot written in NodeJS, to capture every attempts to exploit CVE-2014-3120.\n  - [ElasticPot](https://gitlab.com/bontchev/elasticpot) - An Elasticsearch Honeypot.\n  - [Elastic honey](https://github.com/jordan-wright/elastichoney) - Simple Elasticsearch Honeypot.\n  - [MongoDB-HoneyProxy](https://github.com/Plazmaz/MongoDB-HoneyProxy) - MongoDB honeypot proxy.\n  - [NoSQLpot](https://github.com/torque59/nosqlpot) - Honeypot framework built on a NoSQL-style database.\n  - [mysql-honeypotd](https://github.com/sjinks/mysql-honeypotd) - Low interaction MySQL honeypot written in C.\n  - [MysqlPot](https://github.com/schmalle/MysqlPot) - MySQL honeypot, still very early stage.\n  - [pghoney](https://github.com/betheroot/pghoney) - Low-interaction Postgres Honeypot.\n  - [sticky_elephant](https://github.com/betheroot/sticky_elephant) - Medium interaction postgresql honeypot.\n  - [RedisHoneyPot](https://github.com/cypwnpwnsocute/RedisHoneyPot) - High Interaction Honeypot Solution for Redis protocol.\n\n- Web honeypots\n  \n  - [Cloud Active Defense](https://github.com/SAP/cloud-active-defense?tab=readme-ov-file) - Cloud active defense lets you deploy decoys right into your cloud applications, putting adversaries into a dilemma: to hack or not to hack?\n  - [Express honeypot](https://github.com/christophe77/express-honeypot) - RFI \u0026 LFI honeypot using nodeJS and express.\n  - [EoHoneypotBundle](https://github.com/eymengunay/EoHoneypotBundle) - Honeypot type for Symfony2 forms.\n  - [Glastopf](https://github.com/mushorg/glastopf) - Web Application Honeypot.\n  - [Google Hack Honeypot](http://ghh.sourceforge.net) - Designed to provide reconnaissance against attackers that use search engines as a hacking tool against your resources.\n  - [HellPot](https://github.com/yunginnanet/HellPot) - Honeypot that tries to crash the bots and clients that visit it's location.\n  - [Laravel Application Honeypot](https://github.com/msurguy/Honeypot) - Simple spam prevention package for Laravel applications.\n  - [Lophiid](https://github.com/mrheinen/lophiid/) - Distributed web application honeypot to interact with large scale exploitation attempts.\n  - [Nodepot](https://github.com/schmalle/Nodepot) - NodeJS web application honeypot.\n  - [PasitheaHoneypot](https://github.com/Marist-Innovation-Lab/PasitheaHoneypot) - RestAPI honeypot.\n  - [Servletpot](https://github.com/schmalle/servletpot) - Web application Honeypot.\n  - [Shadow Daemon](https://shadowd.zecure.org/overview/introduction/) - Modular Web Application Firewall / High-Interaction Honeypot for PHP, Perl, and Python apps.\n  - [StrutsHoneypot](https://github.com/Cymmetria/StrutsHoneypot) - Struts Apache 2 based honeypot as well as a detection module for Apache 2 servers.\n  - [WebTrap](https://github.com/IllusiveNetworks-Labs/WebTrap) - Designed to create deceptive webpages to deceive and redirect attackers away from real websites.\n  - [basic-auth-pot (bap)](https://github.com/bjeborn/basic-auth-pot) - HTTP Basic Authentication honeypot.\n  - [bwpot](https://github.com/graneed/bwpot) - Breakable Web applications honeyPot.\n  - [django-admin-honeypot](https://github.com/dmpayton/django-admin-honeypot) - Fake Django admin login screen to notify admins of attempted unauthorized access.\n  - [drupo](https://github.com/d1str0/drupot) - Drupal Honeypot.\n  - [galah](https://github.com/0x4D31/galah) - an LLM-powered web honeypot using the OpenAI API.\n  - [honeyhttpd](https://github.com/bocajspear1/honeyhttpd) - Python-based web server honeypot builder.\n  - [honeyup](https://github.com/LogoiLab/honeyup) - An uploader honeypot designed to look like poor website security.\n  - [modpot](https://github.com/referefref/modpot) - Modpot is a modular web application honeypot framework and management application written in Golang and making use of gin framework.\n  - [owa-honeypot](https://github.com/joda32/owa-honeypot) - A basic flask based Outlook Web Honey pot.\n  - [phpmyadmin_honeypot](https://github.com/gfoss/phpmyadmin_honeypot) - Simple and effective phpMyAdmin honeypot.\n  - [shockpot](https://github.com/threatstream/shockpot) - WebApp Honeypot for detecting Shell Shock exploit attempts.\n  - [smart-honeypot](https://github.com/freak3dot/smart-honeypot) - PHP Script demonstrating a smart honey pot.\n  - Snare/Tanner - successors to Glastopf\n    - [Snare](https://github.com/mushorg/snare) - Super Next generation Advanced Reactive honeypot.\n    - [Tanner](https://github.com/mushorg/tanner) - Evaluating SNARE events.\n  - [stack-honeypot](https://github.com/CHH/stack-honeypot) - Inserts a trap for spam bots into responses.\n  - [tomcat-manager-honeypot](https://github.com/helospark/tomcat-manager-honeypot) - Honeypot that mimics Tomcat manager endpoints. Logs requests and saves attacker's WAR file for later study.\n  - WordPress honeypots\n    - [HonnyPotter](https://github.com/MartinIngesen/HonnyPotter) - WordPress login honeypot for collection and analysis of failed login attempts.\n    - [HoneyPress](https://github.com/kungfuguapo/HoneyPress) - Python based WordPress honeypot in a Docker container.\n    - [wp-smart-honeypot](https://github.com/freak3dot/wp-smart-honeypot) - WordPress plugin to reduce comment spam with a smarter honeypot.\n    - [wordpot](https://github.com/gbrindisi/wordpot) - WordPress Honeypot.\n  - [Python-Honeypot](https://github.com/OWASP/Python-Honeypot) - OWASP Honeypot, Automated Deception Framework.\n\n- Service Honeypots\n  - [ADBHoney](https://github.com/huuck/ADBHoney) - Low interaction honeypot that simulates an Android device running Android Debug Bridge (ADB) server process.\n  - [AMTHoneypot](https://github.com/packetflare/amthoneypot) - Honeypot for Intel's AMT Firmware Vulnerability CVE-2017-5689.\n  - [ddospot](https://github.com/aelth/ddospot) - NTP, DNS, SSDP, Chargen and generic UDP-based amplification DDoS honeypot.\n  - [dionaea](https://github.com/DinoTools/dionaea) - Home of the dionaea honeypot.\n  - [dhp](https://github.com/ciscocsirt/dhp) - Simple Docker Honeypot server emulating small snippets of the Docker HTTP API.\n  - [DolosHoneypot](https://github.com/Marist-Innovation-Lab/DolosHoneypot) - SDN (software defined networking) honeypot.\n  - [Ensnare](https://github.com/ahoernecke/ensnare) - Easy to deploy Ruby honeypot.\n  - [GenAIPot](https://github.com/ls1911/GenAIPot) - The first A.I based open source honeypot. supports POP3 and SMTP protocols and generates content using A.I based on user description.\n  - [Helix](https://github.com/Zeerg/helix-honeypot) - K8s API Honeypot with Active Defense Capabilities.\n  - [honeycomb_plugins](https://github.com/Cymmetria/honeycomb_plugins) - Plugin repository for Honeycomb, the honeypot framework by Cymmetria.\n  - [honeydb] (https://honeydb.io/downloads) - Multi-service honeypot that is easy to deploy and configure. Can be configured to send interaction data to to HoneyDB's centralized collectors for access via REST API.\n  - [honeyntp](https://github.com/fygrave/honeyntp) - NTP logger/honeypot.\n  - [honeypot-camera](https://github.com/alexbredo/honeypot-camera) - Observation camera honeypot.\n  - [honeypot-ftp](https://github.com/alexbredo/honeypot-ftp) - FTP Honeypot.\n  - [honeypots](https://github.com/qeeqbox/honeypots) - 25 different honeypots in a single pypi package! (dns, ftp, httpproxy, http, https, imap, mysql, pop3, postgres, redis, smb, smtp, socks5, ssh, telnet, vnc, mssql, elastic, ldap, ntp, memcache, snmp, oracle, sip and irc).\n  - [honeytrap](https://github.com/honeytrap/honeytrap) - Advanced Honeypot framework written in Go that can be connected with other honeypot software.\n  - [HoneyPy](https://github.com/foospidy/HoneyPy) - Low interaction honeypot.\n  - [Honeygrove](https://github.com/UHH-ISS/honeygrove) - Multi-purpose modular honeypot based on Twisted.\n  - [Honeyport](https://github.com/securitygeneration/Honeyport) - Simple honeyport written in Bash and Python.\n  - [Honeyprint](https://github.com/glaslos/honeyprint) - Printer honeypot.\n  - [Lyrebird](https://hub.docker.com/r/lyrebird/honeypot-base/) - Modern high-interaction honeypot framework.\n  - [MICROS honeypot](https://github.com/Cymmetria/micros_honeypot) - Low interaction honeypot to detect CVE-2018-2636 in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (MICROS).\n  - [node-ftp-honeypot](https://github.com/christophe77/node-ftp-honeypot) - FTP server honeypot in JS.\n  - [pyrdp](https://github.com/gosecure/pyrdp) - RDP man-in-the-middle and library for Python 3 with the ability to watch connections live or after the fact.\n  - [rdppot](https://github.com/kryptoslogic/rdppot) - RDP honeypot\n  - [RDPy](https://github.com/citronneur/rdpy) - Microsoft Remote Desktop Protocol (RDP) honeypot implemented in Python.\n  - [SMB Honeypot](https://github.com/r0hi7/HoneySMB) - High interaction SMB service honeypot capable of capturing wannacry-like Malware.\n  - [Tom's Honeypot](https://github.com/inguardians/toms_honeypot) - Low interaction Python honeypot.\n  - [Trapster Commmunity](https://github.com/0xBallpoint/trapster-community) - Modural and easy to install Python Honeypot, with comprehensive alerting\n  - [troje](https://github.com/dutchcoders/troje/) - Honeypot that runs each connection with the service within a separate LXC container.\n  - [WebLogic honeypot](https://github.com/Cymmetria/weblogic_honeypot) - Low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware.\n  - [WhiteFace Honeypot](https://github.com/csirtgadgets/csirtg-honeypot) - Twisted based honeypot for WhiteFace.\n \n- Distributed Honeypots\n\n  - [DemonHunter](https://github.com/RevengeComing/DemonHunter) - Low interaction honeypot server.\n\n- Anti-honeypot stuff\n\n  - [canarytokendetector](https://github.com/referefref/canarytokendetector) - Tool for detection and nullification of Thinkst CanaryTokens\n  - [honeydet](https://github.com/referefref/honeydet) - Signature based honeypot detector tool written in Golang\n  - [kippo_detect](https://github.com/andrew-morris/kippo_detect) - Offensive component that detects the presence of the kippo honeypot.\n\n- ICS/SCADA honeypots\n\n  - [Conpot](https://github.com/mushorg/conpot) - ICS/SCADA honeypot.\n  - [GasPot](https://github.com/sjhilt/GasPot) - Veeder Root Gaurdian AST, common in the oil and gas industry.\n  - [SCADA honeynet](http://scadahoneynet.sourceforge.net) - Building Honeypots for Industrial Networks.\n  - [gridpot](https://github.com/sk4ld/gridpot) - Open source tools for realistic-behaving electric grid honeynets.\n  - [scada-honeynet](http://www.digitalbond.com/blog/2007/07/24/scada-honeynet-article-in-infragard-publication/) - Mimics many of the services from a popular PLC and better helps SCADA researchers understand potential risks of exposed control system devices.\n\n- Other/random\n\n  - [CitrixHoneypot](https://github.com/MalwareTech/CitrixHoneypot) - Detect and log CVE-2019-19781 scan and exploitation attempts.\n  - [Damn Simple Honeypot (DSHP)](https://github.com/naorlivne/dshp) - Honeypot framework with pluggable handlers.\n  - [dicompot](https://github.com/nsmfoo/dicompot) - DICOM Honeypot.\n  - [IPP Honey](https://gitlab.com/bontchev/ipphoney) - A honeypot for the Internet Printing Protocol.\n  - [Log4Pot](https://github.com/thomaspatzke/Log4Pot) - A honeypot for the Log4Shell vulnerability (CVE-2021-44228).\n  - [Masscanned](https://github.com/ivre/masscanned) - Let's be scanned. A low-interaction honeypot focused on network scanners and bots. It integrates very well with IVRE to build a self-hosted alternative to GreyNoise.\n  - [medpot](https://github.com/schmalle/medpot) -  HL7 / FHIR honeypot.\n  - [NOVA](https://github.com/DataSoft/Nova) - Uses honeypots as detectors, looks like a complete system.\n  - [OpenFlow Honeypot (OFPot)](https://github.com/upa/ofpot) - Redirects traffic for unused IPs to a honeypot, built on POX.\n  - [OpenCanary](https://github.com/thinkst/opencanary) - Modular and decentralised honeypot daemon that runs several canary versions of services that alerts when a service is (ab)used.\n  - [ciscoasa_honeypot](https://github.com/cymmetria/ciscoasa_honeypot) A low interaction honeypot for the Cisco ASA component capable of detecting CVE-2018-0101, a DoS and remote code execution vulnerability.\n  - [miniprint](https://github.com/sa7mon/miniprint) - A medium interaction printer honeypot.\n\n- Botnet C2 tools\n\n  - [Hale](https://github.com/pjlantz/Hale) - Botnet command and control monitor.\n  - [dnsMole](https://code.google.com/archive/p/dns-mole/) - Analyses DNS traffic and potentionaly detect botnet command and control server activity, along with infected hosts.\n\n- IPv6 attack detection tool\n\n  - [ipv6-attack-detector](https://github.com/mzweilin/ipv6-attack-detector/) - Google Summer of Code 2012 project, supported by The Honeynet Project organization.\n\n- Dynamic code instrumentation toolkit\n\n  - [Frida](https://www.frida.re) - Inject JavaScript to explore native apps on Windows, Mac, Linux, iOS and Android.\n\n- Tool to convert website to server honeypots\n\n  - [HIHAT](http://hihat.sourceforge.net/) - Transform arbitrary PHP applications into web-based high-interaction Honeypots.\n\n- Malware collector\n\n  - [Kippo-Malware](https://bruteforcelab.com/kippo-malware) - Python script that will download all malicious files stored as URLs in a Kippo SSH honeypot database.\n\n- Distributed sensor deployment\n\n  - [Community Honey Network](https://communityhoneynetwork.readthedocs.io/en/stable/) - CHN aims to make deployments honeypots and honeypot management tools easy and flexible. The default deployment method uses Docker Compose and Docker to deploy with a few simple commands.\n  - [Modern Honey Network](https://github.com/threatstream/mhn) - Multi-snort and honeypot sensor management, uses a network of VMs, small footprint SNORT installations, stealthy dionaeas, and a centralized server for management.\n\n- Network Analysis Tool\n\n  - [Tracexploit](https://code.google.com/archive/p/tracexploit/) - Replay network packets.\n\n- Log anonymizer\n\n  - [LogAnon](http://code.google.com/archive/p/loganon/) - Log anonymization library that helps having anonymous logs consistent between logs and network captures.\n\n- Low interaction honeypot (router back door)\n\n  - [Honeypot-32764](https://github.com/knalli/honeypot-for-tcp-32764) - Honeypot for router backdoor (TCP 32764).\n  - [WAPot](https://github.com/lcashdol/WAPot) - Honeypot that can be used to observe traffic directed at home routers.\n\n- honeynet farm traffic redirector\n\n  - [Honeymole](https://web.archive.org/web/20100326040550/http://www.honeynet.org.pt:80/index.php/HoneyMole) - Deploy multiple sensors that redirect traffic to a centralized collection of honeypots.\n\n- HTTPS Proxy\n\n  - [mitmproxy](https://mitmproxy.org/) - Allows traffic flows to be intercepted, inspected, modified, and replayed.\n\n- System instrumentation\n\n  - [Sysdig](https://sysdig.com/opensource/) - Open source, system-level exploration allows one to capture system state and activity from a running GNU/Linux instance, then save, filter, and analyze the results.\n  - [Fibratus](https://github.com/rabbitstack/fibratus) - Tool for exploration and tracing of the Windows kernel.\n\n- Honeypot for USB-spreading malware\n\n  - [Ghost-usb](https://github.com/honeynet/ghost-usb-honeypot) - Honeypot for malware that propagates via USB storage devices.\n\n- Data Collection\n\n  - [Kippo2MySQL](https://bruteforcelab.com/kippo2mysql) - Extracts some very basic stats from Kippo’s text-based log files and inserts them in a MySQL database.\n  - [Kippo2ElasticSearch](https://bruteforcelab.com/kippo2elasticsearch) - Python script to transfer data from a Kippo SSH honeypot MySQL database to an ElasticSearch instance (server or cluster).\n\n- Passive network audit framework parser\n\n  - [Passive Network Audit Framework (pnaf)](https://github.com/jusafing/pnaf) - Framework that combines multiple passive and automated analysis techniques in order to provide a security assessment of network platforms.\n\n- VM monitoring and tools\n\n  - [Antivmdetect](https://github.com/nsmfoo/antivmdetection) - Script to create templates to use with VirtualBox to make VM detection harder.\n  - [VMCloak](https://github.com/hatching/vmcloak) - Automated Virtual Machine Generation and Cloaking for Cuckoo Sandbox.\n  - [vmitools](http://libvmi.com/) - C library with Python bindings that makes it easy to monitor the low-level details of a running virtual machine.\n\n- Binary debugger\n\n  - [Hexgolems - Pint Debugger Backend](https://github.com/hexgolems/pint) - Debugger backend and LUA wrapper for PIN.\n  - [Hexgolems - Schem Debugger Frontend](https://github.com/hexgolems/schem) - Debugger frontend.\n\n- Mobile Analysis Tool\n\n  - [Androguard](https://github.com/androguard/androguard) - Reverse engineering, Malware and goodware analysis of Android applications and more.\n  - [APKinspector](https://github.com/honeynet/apkinspector/) - Powerful GUI tool for analysts to analyze the Android applications.\n\n- Low interaction honeypot\n\n  - [Honeyperl](https://sourceforge.net/projects/honeyperl/) - Honeypot software based in Perl with plugins developed for many functions like : wingates, telnet, squid, smtp, etc.\n  - [T-Pot](https://github.com/dtag-dev-sec/tpotce) - All in one honeypot appliance from telecom provider T-Mobile\n  - [beelzebub](https://github.com/mariocandela/beelzebub) - A secure honeypot framework, extremely easy to configure by yaml 🚀\n\n- Honeynet data fusion\n\n  - [HFlow2](https://projects.honeynet.org/hflow) - Data coalesing tool for honeynet/network analysis.\n\n- Server\n\n  - [Amun](http://amunhoney.sourceforge.net) - Vulnerability emulation honeypot.\n  - [Artillery](https://github.com/trustedsec/artillery/) - Open-source blue team tool designed to protect Linux and Windows operating systems through multiple methods.\n  - [Bait and Switch](http://baitnswitch.sourceforge.net) - Redirects all hostile traffic to a honeypot that is partially mirroring your production system.\n  - [Bifrozt](https://github.com/Ziemeck/bifrozt-ansible) - Automatic deploy bifrozt with ansible.\n  - [Conpot](http://conpot.org/) - Low interactive server side Industrial Control Systems honeypot.\n  - [Heralding](https://github.com/johnnykv/heralding) - Credentials catching honeypot.\n  - [HoneyWRT](https://github.com/CanadianJeff/honeywrt) - Low interaction Python honeypot designed to mimic services or ports that might get targeted by attackers.\n  - [Honeyd](https://github.com/provos/honeyd) - See [honeyd tools](#honeyd-tools).\n  - [Honeysink](http://www.honeynet.org/node/773) - Open source network sinkhole that provides a mechanism for detection and prevention of malicious traffic on a given network.\n  - [Hontel](https://github.com/stamparm/hontel) - Telnet Honeypot.\n  - [KFSensor](http://www.keyfocus.net/kfsensor/) - Windows based honeypot Intrusion Detection System (IDS).\n  - [LaBrea](http://labrea.sourceforge.net/labrea-info.html) - Takes over unused IP addresses, and creates virtual servers that are attractive to worms, hackers, and other denizens of the Internet.\n  - [MTPot](https://github.com/Cymmetria/MTPot) - Open Source Telnet Honeypot, focused on Mirai malware.\n  - [SIREN](https://github.com/blaverick62/SIREN) - Semi-Intelligent HoneyPot Network - HoneyNet Intelligent Virtual Environment.\n  - [TelnetHoney](https://github.com/balte/TelnetHoney) - Simple telnet honeypot.\n  - [UDPot Honeypot](https://github.com/jekil/UDPot) - Simple UDP/DNS honeypot scripts.\n  - [Yet Another Fake Honeypot (YAFH)](https://github.com/fnzv/YAFH) - Simple honeypot written in Go.\n  - [arctic-swallow](https://github.com/ajackal/arctic-swallow) - Low interaction honeypot.\n  - [fapro](https://github.com/fofapro/fapro) - Fake Protocol Server.\n  - [glutton](https://github.com/mushorg/glutton) - All eating honeypot.\n  - [go-HoneyPot](https://github.com/Mojachieee/go-HoneyPot) - Honeypot server written in Go.\n  - [go-emulators](https://github.com/kingtuna/go-emulators) - Honeypot Golang emulators.\n  - [honeymail](https://github.com/sec51/honeymail) - SMTP honeypot written in Golang.\n  - [honeytrap](https://github.com/tillmannw/honeytrap) - Low-interaction honeypot and network security tool written to catch attacks against TCP and UDP services.\n  - [imap-honey](https://github.com/yvesago/imap-honey) - IMAP honeypot written in Golang.\n  - [mwcollectd](https://www.openhub.net/p/mwcollectd) - Versatile malware collection daemon, uniting the best features of nepenthes and honeytrap.\n  - [potd](https://github.com/lnslbrty/potd) - Highly scalable low- to medium-interaction SSH/TCP honeypot designed for OpenWrt/IoT devices leveraging several Linux kernel features, such as namespaces, seccomp and thread capabilities.\n  - [portlurker](https://github.com/bartnv/portlurker) - Port listener in Rust with protocol guessing and safe string display.\n  - [slipm-honeypot](https://github.com/rshipp/slipm-honeypot) - Simple low-interaction port monitoring honeypot.\n  - [telnet-iot-honeypot](https://github.com/Phype/telnet-iot-honeypot) - Python telnet honeypot for catching botnet binaries.\n  - [telnetlogger](https://github.com/robertdavidgraham/telnetlogger) - Telnet honeypot designed to track the Mirai botnet.\n  - [vnclowpot](https://github.com/magisterquis/vnclowpot) - Low interaction VNC honeypot.\n\n- IDS signature generation\n\n  - [Honeycomb](http://www.icir.org/christian/honeycomb/) - Automated signature creation using honeypots.\n\n- Lookup service for AS-numbers and prefixes\n\n  - [CC2ASN](http://www.cc2asn.com/) - Simple lookup service for AS-numbers and prefixes belonging to any given country in the world.\n\n- Data Collection / Data Sharing\n\n  - [HPfriends](http://hpfriends.honeycloud.net/#/home) - Honeypot data-sharing platform.\n    - [hpfriends - real-time social data-sharing](https://heipei.io/sigint-hpfriends/) - Presentation about HPFriends feed system\n  - [HPFeeds](https://github.com/rep/hpfeeds/) - Lightweight authenticated publish-subscribe protocol.\n\n- Central management tool\n\n  - [PHARM](http://www.nepenthespharm.com/) - Manage, report, and analyze your distributed Nepenthes instances.\n\n- Network connection analyzer\n\n  - [Impost](http://impost.sourceforge.net/) - Network security auditing tool designed to analyze the forensics behind compromised and/or vulnerable daemons.\n\n- Honeypot deployment\n\n  - [honeyfs](https://github.com/referefref/honeyfs) - Tool to create artificial file systems for medium/high interaction honeypots.\n  - [Modern Honeynet Network](http://threatstream.github.io/mhn/) - Streamlines deployment and management of secure honeypots.\n\n- Honeypot extensions to Wireshark\n\n  - [Wireshark Extensions](https://www.honeynet.org/project/WiresharkExtensions) - Apply Snort IDS rules and signatures against packet capture files using Wireshark.\n\n- Client\n\n  - [CWSandbox / GFI Sandbox](https://www.gfi.com/products-and-solutions/all-products)\n  - [Capture-HPC-Linux](https://redmine.honeynet.org/projects/linux-capture-hpc/wiki)\n  - [Capture-HPC-NG](https://github.com/CERT-Polska/HSN-Capture-HPC-NG)\n  - [Capture-HPC](https://projects.honeynet.org/capture-hpc) - High interaction client honeypot (also called honeyclient).\n  - [HoneyBOT](http://www.atomicsoftwaresolutions.com/)\n  - [HoneyC](https://projects.honeynet.org/honeyc)\n  - [HoneySpider Network](https://github.com/CERT-Polska/hsn2-bundle) - Highly-scalable system integrating multiple client honeypots to detect malicious websites.\n  - [HoneyWeb](https://code.google.com/archive/p/gsoc-honeyweb/) - Web interface created to manage and remotely share Honeyclients resources.\n  - [Jsunpack-n](https://github.com/urule99/jsunpack-n)\n  - [MonkeySpider](http://monkeyspider.sourceforge.net)\n  - [PhoneyC](https://github.com/honeynet/phoneyc) - Python honeyclient (later replaced by Thug).\n  - [Pwnypot](https://github.com/shjalayeri/pwnypot) - High Interaction Client Honeypot.\n  - [Rumal](https://github.com/thugs-rumal/) - Thug's Rumāl: a Thug's dress and weapon.\n  - [Shelia](https://www.cs.vu.nl/~herbertb/misc/shelia/) - Client-side honeypot for attack detection.\n  - [Thug](https://buffer.github.io/thug/) - Python-based low-interaction honeyclient.\n  - [Thug Distributed Task Queuing](https://thug-distributed.readthedocs.io/en/latest/index.html)\n  - [Trigona](https://www.honeynet.org/project/Trigona)\n  - [URLQuery](https://urlquery.net/)\n  - [YALIH (Yet Another Low Interaction Honeyclient)](https://github.com/Masood-M/yalih) - Low-interaction client honeypot designed to detect malicious websites through signature, anomaly, and pattern matching techniques.\n\n- Honeypot\n\n  - [Deception Toolkit](http://www.all.net/dtk/dtk.html)\n  - [IMHoneypot](https://github.com/mushorg/imhoneypot)\n\n- PDF document inspector\n\n  - [peepdf](https://github.com/jesparza/peepdf) - Powerful Python tool to analyze PDF documents.\n\n- Hybrid low/high interaction honeypot\n\n  - [HoneyBrid](http://honeybrid.sourceforge.net)\n\n- SSH Honeypots\n\n  - [Blacknet](https://github.com/morian/blacknet) - Multi-head SSH honeypot system.\n  - [Cowrie](https://github.com/cowrie/cowrie) - Cowrie SSH Honeypot (based on kippo).\n  - [DShield docker](https://github.com/xme/dshield-docker) - Docker container running cowrie with DShield output enabled.\n  - [endlessh](https://github.com/skeeto/endlessh) - SSH tarpit that slowly sends an endless banner. ([docker image](https://hub.docker.com/r/linuxserver/endlessh))\n  - [HonSSH](https://github.com/tnich/honssh) - Logs all SSH communications between a client and server.\n  - [HUDINX](https://github.com/Cryptix720/HUDINX) - Tiny interaction SSH honeypot engineered in Python to log brute force attacks and, most importantly, the entire shell interaction performed by the attacker.\n  - [Kippo](https://github.com/desaster/kippo) - Medium interaction SSH honeypot.\n  - [Kippo_JunOS](https://github.com/gregcmartin/Kippo_JunOS) - Kippo configured to be a backdoored netscreen.\n  - [Kojoney2](https://github.com/madirish/kojoney2) - Low interaction SSH honeypot written in Python and based on Kojoney by Jose Antonio Coret.\n  - [Kojoney](http://kojoney.sourceforge.net/) - Python-based Low interaction honeypot that emulates an SSH server implemented with Twisted Conch.\n  - [Longitudinal Analysis of SSH Cowrie Honeypot Logs](https://github.com/deroux/longitudinal-analysis-cowrie) - Python based command line tool to analyze cowrie logs over time.\n  - [LongTail Log Analysis @ Marist College](http://longtail.it.marist.edu/honey/) - Analyzed SSH honeypot logs.\n  - [Malbait](https://github.com/batchmcnulty/Malbait) - Simple TCP/UDP honeypot implemented in Perl.\n  - [MockSSH](https://github.com/ncouture/MockSSH) - Mock an SSH server and define all commands it supports (Python, Twisted).\n  - [cowrie2neo](https://github.com/xlfe/cowrie2neo) - Parse cowrie honeypot logs into a neo4j database.\n  - [go-sshoney](https://github.com/ashmckenzie/go-sshoney) - SSH Honeypot.\n  - [go0r](https://github.com/fzerorubigd/go0r) - Simple ssh honeypot in Golang.\n  - [gohoney](https://github.com/PaulMaddox/gohoney) - SSH honeypot written in Go.\n  - [hived](https://github.com/sahilm/hived) - Golang-based honeypot.\n  - [hnypots-agent)](https://github.com/joshrendek/hnypots-agent) - SSH Server in Go that logs username and password combinations.\n  - [honeypot.go](https://github.com/mdp/honeypot.go) - SSH Honeypot written in Go.\n  - [honeyssh](https://github.com/ppacher/honeyssh) - Credential dumping SSH honeypot with statistics.\n  - [hornet](https://github.com/czardoz/hornet) - Medium interaction SSH honeypot that supports multiple virtual hosts.\n  - [ssh-auth-logger](https://github.com/JustinAzoff/ssh-auth-logger) - Low/zero interaction SSH authentication logging honeypot.\n  - [ssh-honeypot](https://github.com/droberson/ssh-honeypot) - Fake sshd that logs IP addresses, usernames, and passwords.\n  - [ssh-honeypot](https://github.com/amv42/sshd-honeypot) - Modified version of the OpenSSH deamon that forwards commands to Cowrie where all commands are interpreted and returned.\n  - [ssh-honeypotd](https://github.com/sjinks/ssh-honeypotd) - Low-interaction SSH honeypot written in C.\n  - [sshForShits](https://github.com/traetox/sshForShits) - Framework for a high interaction SSH honeypot.\n  - [sshesame](https://github.com/jaksi/sshesame) - Fake SSH server that lets everyone in and logs their activity.\n  - [sshhipot](https://github.com/magisterquis/sshhipot) - High-interaction MitM SSH honeypot.\n  - [sshlowpot](https://github.com/magisterquis/sshlowpot) - Yet another no-frills low-interaction SSH honeypot in Go.\n  - [sshsyrup](https://github.com/mkishere/sshsyrup) - Simple SSH Honeypot with features to capture terminal activity and upload to asciinema.org.\n  - [twisted-honeypots](https://github.com/lanjelot/twisted-honeypots) - SSH, FTP and Telnet honeypots based on Twisted.\n\n- Distributed sensor project\n\n  - [DShield Web Honeypot Project](https://sites.google.com/site/webhoneypotsite/)\n\n- A pcap analyzer\n\n  - [Honeysnap](https://projects.honeynet.org/honeysnap/)\n\n- Network traffic redirector\n\n  - [Honeywall](https://projects.honeynet.org/honeywall/)\n\n- Honeypot Distribution with mixed content\n\n  - [HoneyDrive](https://bruteforcelab.com/honeydrive)\n\n- Honeypot sensor\n\n  - [Honeeepi](https://redmine.honeynet.org/projects/honeeepi/wiki) - Honeypot sensor on a Raspberry Pi based on a customized Raspbian OS.\n\n- File carving\n\n  - [TestDisk \u0026 PhotoRec](https://www.cgsecurity.org/)\n\n- Behavioral analysis tool for win32\n\n  - [Capture BAT](https://www.honeynet.org/node/315)\n\n- Live CD\n\n  - [DAVIX](https://www.secviz.org/node/89) - The DAVIX Live CD.\n\n- Spamtrap\n\n  - [Mail::SMTP::Honeypot](https://metacpan.org/pod/release/MIKER/Mail-SMTP-Honeypot-0.11/Honeypot.pm) - Perl module that appears to provide the functionality of a standard SMTP server.\n  - [Mailoney](https://github.com/phin3has/mailoney) - SMTP honeypot written in python.\n  - [SendMeSpamIDS.py](https://github.com/johestephan/VerySimpleHoneypot) - Simple SMTP fetch all IDS and analyzer.\n  - [Shiva](https://github.com/shiva-spampot/shiva) - Spam Honeypot with Intelligent Virtual Analyzer.\n    - [Shiva The Spam Honeypot Tips And Tricks For Getting It Up And Running](https://www.pentestpartners.com/security-blog/shiva-the-spam-honeypot-tips-and-tricks-for-getting-it-up-and-running/)\n  - [SMTPLLMPot](https://github.com/referefref/SMTPLLMPot) - A super simple SMTP Honeypot built using GPT3.5\n  - [SpamHAT](https://github.com/miguelraulb/spamhat) - Spam Honeypot Tool.\n  - [Spamhole](http://www.spamhole.net/)\n  - [honeypot](https://github.com/jadb/honeypot) - The Project Honey Pot un-official PHP SDK.\n  - [spamd](http://man.openbsd.org/cgi-bin/man.cgi?query=spamd%26apropos=0%26sektion=0%26manpath=OpenBSD+Current%26arch=i386%26format=html)\n\n- Commercial honeynet\n\n  - [Cymmetria Mazerunner](ttps://cymmetria.com/products/mazerunner/) - Leads attackers away from real targets and creates a footprint of the attack.\n\n- Server (Bluetooth)\n\n  - [Bluepot](https://github.com/andrewmichaelsmith/bluepot)\n\n- Dynamic analysis of Android apps\n\n  - [Droidbox](https://code.google.com/archive/p/droidbox/)\n\n- Dockerized Low Interaction packaging\n\n  - [Docker honeynet](https://github.com/sreinhardt/Docker-Honeynet) - Several Honeynet tools set up for Docker containers.\n  - [Dockerized Thug](https://hub.docker.com/r/honeynet/thug/) - Dockerized [Thug](https://github.com/buffer/thug) to analyze malicious web content.\n  - [Dockerpot](https://github.com/mrschyte/dockerpot) - Docker based honeypot.\n  - [Manuka](https://github.com/andrewmichaelsmith/manuka) - Docker based honeypot (Dionaea and Kippo).\n  - [honey_ports](https://github.com/run41/honey_ports) - Very simple but effective docker deployed honeypot to detect port scanning in your environment.\n  - [mhn-core-docker](https://github.com/MattCarothers/mhn-core-docker) - Core elements of the Modern Honey Network implemented in Docker.\n\n- Network analysis\n\n  - [Quechua](https://bitbucket.org/zaccone/quechua)\n\n- SIP Server\n\n  - [Artemnesia VoIP](http://artemisa.sourceforge.net)\n\n- SIP\n\n  - [SentryPeer](https://github.com/SentryPeer/SentryPeer) - Protect your SIP Servers from bad actors.\n\n- IOT Honeypot\n\n  - [HoneyThing](https://github.com/omererdem/honeything) - TR-069 Honeypot.\n  - [Kako](https://github.com/darkarnium/kako) - Honeypots for a number of well known and deployed embedded device vulnerabilities.\n\n- Honeytokens\n  - [CanaryTokens](https://github.com/thinkst/canarytokens) - Self-hostable honeytoken generator and reporting dashboard; demo version available at [CanaryTokens.org](https://canarytokens.org/generate).\n  - [Honeybits](https://github.com/0x4D31/honeybits) - Simple tool designed to enhance the effectiveness of your traps by spreading breadcrumbs and honeytokens across your production servers and workstations to lure the attacker toward your honeypots.\n  - [Honeyλ (HoneyLambda)](https://github.com/0x4D31/honeylambda) - Simple, serverless application designed to create and monitor URL honeytokens, on top of AWS Lambda and Amazon API Gateway.\n  - [dcept](https://github.com/secureworks/dcept) - Tool for deploying and detecting use of Active Directory honeytokens.\n  - [honeyku](https://github.com/0x4D31/honeyku) - Heroku-based web honeypot that can be used to create and monitor fake HTTP endpoints (i.e. honeytokens).\n\n## Honeyd Tools\n\n- Honeyd plugin\n\n  - [Honeycomb](http://www.honeyd.org/tools.php)\n\n- Honeyd viewer\n\n  - [Honeyview](http://honeyview.sourceforge.net/)\n\n- Honeyd to MySQL connector\n\n  - [Honeyd2MySQL](https://bruteforcelab.com/honeyd2mysql)\n\n- A script to visualize statistics from honeyd\n\n  - [Honeyd-Viz](https://bruteforcelab.com/honeyd-viz)\n\n- Honeyd stats\n  - [Honeydsum.pl](https://github.com/DataSoft/Honeyd/blob/master/scripts/misc/honeydsum-v0.3/honeydsum.pl)\n\n## Network and Artifact Analysis\n\n- Sandbox\n\n  - [Argos](http://www.few.vu.nl/argos/) - Emulator for capturing zero-day attacks.\n  - [COMODO automated sandbox](https://help.comodo.com/topic-72-1-451-4768-.html)\n  - [Cuckoo](https://cuckoosandbox.org/) - Leading open source automated malware analysis system.\n  - [Pylibemu](https://github.com/buffer/pylibemu) - Libemu Cython wrapper.\n  - [RFISandbox](https://monkey.org/~jose/software/rfi-sandbox/) - PHP 5.x script sandbox built on top of [funcall](https://pecl.php.net/package/funcall).\n  - [dorothy2](https://github.com/m4rco-/dorothy2) - Malware/botnet analysis framework written in Ruby.\n  - [imalse](https://github.com/hbhzwj/imalse) - Integrated MALware Simulator and Emulator.\n  - [libemu](https://github.com/buffer/libemu) - Shellcode emulation library, useful for shellcode detection.\n\n- Sandbox-as-a-Service\n\n  - [Hybrid Analysis](https://www.hybrid-analysis.com) - Free malware analysis service powered by Payload Security that detects and analyzes unknown threats using a unique Hybrid Analysis technology.\n  - [Joebox Cloud](https://jbxcloud.joesecurity.org/login) - Analyzes the behavior of malicious files including PEs, PDFs, DOCs, PPTs, XLSs, APKs, URLs and MachOs on Windows, Android and Mac OS X for suspicious activities.\n  - [VirusTotal](https://www.virustotal.com/) - Analyze suspicious files and URLs to detect types of malware, and automatically share them with the security community.\n  - [malwr.com](https://malwr.com/) - Free malware analysis service and community.\n\n## Data Tools\n\n- Front Ends\n\n  - [DionaeaFR](https://github.com/rubenespadas/DionaeaFR) - Front Web to Dionaea low-interaction honeypot.\n  - [Django-kippo](https://github.com/jedie/django-kippo) - Django App for kippo SSH Honeypot.\n  - [Shockpot-Frontend](https://github.com/GovCERT-CZ/Shockpot-Frontend) - Full featured script to visualize statistics from a Shockpot honeypot.\n  - [Tango](https://github.com/aplura/Tango) - Honeypot Intelligence with Splunk.\n  - [Wordpot-Frontend](https://github.com/GovCERT-CZ/Wordpot-Frontend) - Full featured script to visualize statistics from a Wordpot honeypot.\n  - [honeyalarmg2](https://github.com/schmalle/honeyalarmg2) - Simplified UI for showing honeypot alarms.\n  - [honeypotDisplay](https://github.com/Joss-Steward/honeypotDisplay) - Flask website which displays data gathered from an SSH Honeypot.\n\n- Visualization\n\n  - [Acapulco](https://github.com/hgascon/acapulco) - Automated Attack Community Graph Construction.\n  - [Afterglow Cloud](https://github.com/ayrus/afterglow-cloud)\n  - [Afterglow](http://afterglow.sourceforge.net/)\n  - [Glastopf Analytics](https://github.com/katkad/Glastopf-Analytics) - Easy honeypot statistics.\n  - [HoneyMalt](https://github.com/SneakersInc/HoneyMalt) - Maltego tranforms for mapping Honeypot systems.\n  - [HoneyMap](https://github.com/fw42/honeymap) - Real-time websocket stream of GPS events on a fancy SVG world map.\n  - [HoneyStats](https://sourceforge.net/projects/honeystats/) - Statistical view of the recorded activity on a Honeynet.\n  - [HpfeedsHoneyGraph](https://github.com/yuchincheng/HpfeedsHoneyGraph) - Visualization app to visualize hpfeeds logs.\n  - [IVRE](https://github.com/ivre/ivre) - Network recon framework, published by @cea-sec \u0026 @ANSSI-FR. Build your own, self-hosted and fully-controlled alternatives to Criminalip / Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, collect and analyse network intelligence from your sensors, and much more!\n  - [Kippo stats](https://github.com/mfontani/kippo-stats) - Mojolicious app to display statistics for your kippo SSH honeypot.\n  - [Kippo-Graph](https://bruteforcelab.com/kippo-graph) - Full featured script to visualize statistics from a Kippo SSH honeypot.\n  - [The Intelligent HoneyNet](https://github.com/jpyorre/IntelligentHoneyNet) - Create actionable information from honeypots.\n  - [ovizart](https://github.com/oguzy/ovizart) - Visual analysis for network traffic.\n\n## Guides\n\n- [T-Pot: A Multi-Honeypot Platform](https://dtag-dev-sec.github.io/mediator/feature/2015/03/17/concept.html)\n- [Honeypot (Dionaea and kippo) setup script](https://github.com/andrewmichaelsmith/honeypot-setup-script/)\n\n- Deployment\n\n  - [Dionaea and EC2 in 20 Minutes](http://andrewmichaelsmith.com/2012/03/dionaea-honeypot-on-ec2-in-20-minutes/) - Tutorial on setting up Dionaea on an EC2 instance.\n  - [Using a Raspberry Pi honeypot to contribute data to DShield/ISC](https://isc.sans.edu/diary/22680) - The Raspberry Pi based system will allow us to maintain one code base that will make it easier to collect rich logs beyond firewall logs.\n  - [honeypotpi](https://github.com/free5ty1e/honeypotpi) - Script for turning a Raspberry Pi into a HoneyPot Pi.\n\n- Research Papers\n\n  - [Honeypot research papers](https://github.com/shbhmsingh72/Honeypot-Research-Papers) - PDFs of research papers on honeypots.\n  - [vEYE](https://link.springer.com/article/10.1007%2Fs10115-008-0137-3) - Behavioral footprinting for self-propagating worm detection and profiling.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fparalax%2Fawesome-honeypots","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fparalax%2Fawesome-honeypots","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fparalax%2Fawesome-honeypots/lists"}