Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

fucking-awesome-honeypots

An awesome list of honeypot resources. With repository stars⭐ and forks🍴
https://github.com/Correia-jpv/fucking-awesome-honeypots

Last synced: about 12 hours ago
JSON representation

  • Uncategorized

  • Honeypots

    • Delilah - Elasticsearch Honeypot written in Python (originally from Novetta).
    • ESPot - Elasticsearch honeypot written in NodeJS, to capture every attempts to exploit CVE-2014-3120.
    • Elastic honey - Simple Elasticsearch Honeypot.
    • MongoDB-HoneyProxy - MongoDB honeypot proxy.
    • NoSQLpot - Honeypot framework built on a NoSQL-style database.
    • mysql-honeypotd - Low interaction MySQL honeypot written in C.
    • MysqlPot - MySQL honeypot, still very early stage.
    • pghoney - Low-interaction Postgres Honeypot.
    • sticky_elephant - Medium interaction postgresql honeypot.
    • RedisHoneyPot - High Interaction Honeypot Solution for Redis protocol.
    • Express honeypot - RFI & LFI honeypot using nodeJS and express.
    • EoHoneypotBundle - Honeypot type for Symfony2 forms.
    • Glastopf - Web Application Honeypot.
    • HellPot - Honeypot that tries to crash the bots and clients that visit it's location.
    • Laravel Application Honeypot - Simple spam prevention package for Laravel applications.
    • Nodepot - NodeJS web application honeypot.
    • PasitheaHoneypot - RestAPI honeypot.
    • Servletpot - Web application Honeypot.
    • StrutsHoneypot - Struts Apache 2 based honeypot as well as a detection module for Apache 2 servers.
    • WebTrap - Designed to create deceptive webpages to deceive and redirect attackers away from real websites.
    • basic-auth-pot (bap) - HTTP Basic Authentication honeypot.
    • bwpot - Breakable Web applications honeyPot.
    • django-admin-honeypot - Fake Django admin login screen to notify admins of attempted unauthorized access.
    • drupo - Drupal Honeypot.
    • galah - an LLM-powered web honeypot using the OpenAI API.
    • honeyhttpd - Python-based web server honeypot builder.
    • modpot - Modpot is a modular web application honeypot framework and management application written in Golang and making use of gin framework.
    • owa-honeypot - A basic flask based Outlook Web Honey pot.
    • phpmyadmin_honeypot - Simple and effective phpMyAdmin honeypot.
    • smart-honeypot - PHP Script demonstrating a smart honey pot.
    • Snare - Super Next generation Advanced Reactive honeypot.
    • Tanner - Evaluating SNARE events.
    • stack-honeypot - Inserts a trap for spam bots into responses.
    • tomcat-manager-honeypot - Honeypot that mimics Tomcat manager endpoints. Logs requests and saves attacker's WAR file for later study.
    • HonnyPotter - WordPress login honeypot for collection and analysis of failed login attempts.
    • HoneyPress - Python based WordPress honeypot in a Docker container.
    • wp-smart-honeypot - WordPress plugin to reduce comment spam with a smarter honeypot.
    • wordpot - WordPress Honeypot.
    • Python-Honeypot - OWASP Honeypot, Automated Deception Framework.
    • ADBHoney - Low interaction honeypot that simulates an Android device running Android Debug Bridge (ADB) server process.
    • ddospot - NTP, DNS, SSDP, Chargen and generic UDP-based amplification DDoS honeypot.
    • dionaea - Home of the dionaea honeypot.
    • dhp - Simple Docker Honeypot server emulating small snippets of the Docker HTTP API.
    • DolosHoneypot - SDN (software defined networking) honeypot.
    • Ensnare - Easy to deploy Ruby honeypot.
    • Helix - K8s API Honeypot with Active Defense Capabilities.
    • honeycomb_plugins - Plugin repository for Honeycomb, the honeypot framework by Cymmetria.
    • honeyntp - NTP logger/honeypot.
    • honeypot-camera - Observation camera honeypot.
    • honeypot-ftp - FTP Honeypot.
    • honeypots - 25 different honeypots in a single pypi package! (dns, ftp, httpproxy, http, https, imap, mysql, pop3, postgres, redis, smb, smtp, socks5, ssh, telnet, vnc, mssql, elastic, ldap, ntp, memcache, snmp, oracle, sip and irc).
    • honeytrap - Advanced Honeypot framework written in Go that can be connected with other honeypot software.
    • HoneyPy - Low interaction honeypot.
    • Honeygrove - Multi-purpose modular honeypot based on Twisted.
    • Honeyport - Simple honeyport written in Bash and Python.
    • Honeyprint - Printer honeypot.
    • MICROS honeypot - Low interaction honeypot to detect CVE-2018-2636 in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (MICROS).
    • node-ftp-honeypot - FTP server honeypot in JS.
    • pyrdp - RDP man-in-the-middle and library for Python 3 with the ability to watch connections live or after the fact.
    • rdppot - RDP honeypot
    • RDPy - Microsoft Remote Desktop Protocol (RDP) honeypot implemented in Python.
    • Tom's Honeypot - Low interaction Python honeypot.
    • WebLogic honeypot - Low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware.
    • WhiteFace Honeypot - Twisted based honeypot for WhiteFace.
    • DemonHunter - Low interaction honeypot server.
    • canarytokendetector - Tool for detection and nullification of Thinkst CanaryTokens
    • honeydet - Signature based honeypot detector tool written in Golang
    • kippo_detect - Offensive component that detects the presence of the kippo honeypot.
    • Conpot - ICS/SCADA honeypot.
    • GasPot - Veeder Root Gaurdian AST, common in the oil and gas industry.
    • gridpot - Open source tools for realistic-behaving electric grid honeynets.
    • CitrixHoneypot - Detect and log CVE-2019-19781 scan and exploitation attempts.
    • Damn Simple Honeypot (DSHP) - Honeypot framework with pluggable handlers.
    • dicompot - DICOM Honeypot.
    • Log4Pot - A honeypot for the Log4Shell vulnerability (CVE-2021-44228).
    • Masscanned - Let's be scanned. A low-interaction honeypot focused on network scanners and bots. It integrates very well with IVRE to build a self-hosted alternative to GreyNoise.
    • medpot - HL7 / FHIR honeypot.
    • NOVA - Uses honeypots as detectors, looks like a complete system.
    • OpenFlow Honeypot (OFPot) - Redirects traffic for unused IPs to a honeypot, built on POX.
    • OpenCanary - Modular and decentralised honeypot daemon that runs several canary versions of services that alerts when a service is (ab)used.
    • ciscoasa_honeypot - 2018-0101, a DoS and remote code execution vulnerability.
    • miniprint - A medium interaction printer honeypot.
    • Hale - Botnet command and control monitor.
    • AMTHoneypot - Honeypot for Intel's AMT Firmware Vulnerability CVE-2017-5689.
    • Trapster Commmunity - Modural and easy to install Python Honeypot, with comprehensive alerting
    • honeyup - An uploader honeypot designed to look like poor website security.
    • ipv6-attack-detector - Google Summer of Code 2012 project, supported by The Honeynet Project organization.
    • SMB Honeypot - High interaction SMB service honeypot capable of capturing wannacry-like Malware.
    • troje - Honeypot that runs each connection with the service within a separate LXC container.
    • shockpot - WebApp Honeypot for detecting Shell Shock exploit attempts.
    • Modern Honey Network - Multi-snort and honeypot sensor management, uses a network of VMs, small footprint SNORT installations, stealthy dionaeas, and a centralized server for management.
    • Conpot - Low interactive server side Industrial Control Systems honeypot.
    • Honeysink - Open source network sinkhole that provides a mechanism for detection and prevention of malicious traffic on a given network.
    • Honeycomb - Automated signature creation using honeypots.
    • HPfriends - Honeypot data-sharing platform.
    • PHARM - Manage, report, and analyze your distributed Nepenthes instances.
    • Modern Honeynet Network - Streamlines deployment and management of secure honeypots.
    • Pwnypot - High Interaction Client Honeypot.
    • Deception Toolkit
    • LongTail Log Analysis @ Marist College - Analyzed SSH honeypot logs.
    • Spamhole
    • spamd
    • Artemnesia VoIP
    • Amun - Vulnerability emulation honeypot.
    • Bait and Switch - Redirects all hostile traffic to a honeypot that is partially mirroring your production system.
    • SCADA honeynet - Building Honeypots for Industrial Networks.
  • Honeyd Tools

  • Network and Artifact Analysis

    • Argos - Emulator for capturing zero-day attacks.
  • Source