<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Track Awesome Honeypots Updates Weekly</title>
  <id>https://www.trackawesomelist.com/paralax/awesome-honeypots/week/feed.xml</id>
  <updated>2023-12-27T09:01:20.895Z</updated>
  <link rel="self" type="application/atom+xml" href="https://www.trackawesomelist.com/paralax/awesome-honeypots/week/feed.xml"/>
  <link rel="alternate" type="application/json" href="https://www.trackawesomelist.com/paralax/awesome-honeypots/week/feed.json"/>
  <link rel="alternate" type="text/html" href="https://www.trackawesomelist.com/paralax/awesome-honeypots/week/"/>
  <generator uri="https://github.com/bcomnes/jsonfeed-to-atom#readme" version="1.2.2">jsonfeed-to-atom</generator>
  <icon>https://www.trackawesomelist.com/favicon.ico</icon>
  <logo>https://www.trackawesomelist.com/icon.png</logo>
  <subtitle>an awesome list of honeypot resources</subtitle>
  <entry>
    <id>https://www.trackawesomelist.com/2023/52/</id>
    <title>Awesome Honeypots Updates on Dec 25 - Dec 31, 2023</title>
    <updated>2023-12-27T09:01:20.895Z</updated>
    <published>2023-12-27T09:01:20.829Z</published>
    <content type="html"><![CDATA[<h3><p>Honeypots</p>
</h3>
<ul>
<li><p>Anti-honeypot stuff</p>
<ul>
<li><a href="https://github.com/referefref/canarytokendetector" rel="noopener noreferrer">canarytokendetector (⭐20)</a> - Tool for detection and nullification of Thinkst CanaryTokens</li>
<li><a href="https://github.com/referefref/honeydet" rel="noopener noreferrer">honeydet (⭐89)</a> - Signature based honeypot detector tool written in Golang</li>
<li><a href="https://github.com/andrew-morris/kippo_detect" rel="noopener noreferrer">kippo_detect (⭐57)</a> - Offensive component that detects the presence of the kippo honeypot.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Honeypot deployment</p>
<ul>
<li><a href="https://github.com/referefref/honeyfs" rel="noopener noreferrer">honeyfs (⭐7)</a> - Tool to create artificial file systems for medium/high interaction honeypots.</li>
<li><a href="http://threatstream.github.io/mhn/" rel="noopener noreferrer">Modern Honeynet Network</a> - Streamlines deployment and management of secure honeypots.</li>
</ul>
</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2023/52/"/>
    <summary>2 awesome projects updated on Dec 25 - Dec 31, 2023</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2022/34/</id>
    <title>Awesome Honeypots Updates on Aug 22 - Aug 28, 2022</title>
    <updated>2022-08-27T11:45:26.000Z</updated>
    <published>2022-08-27T11:45:26.000Z</published>
    <content type="html"><![CDATA[<h3><p>Honeypots</p>
</h3>
<ul>
<li><p>Database Honeypots</p>
<ul>
<li><a href="https://github.com/SecurityTW/delilah" rel="noopener noreferrer">Delilah (⭐23)</a> - Elasticsearch Honeypot written in Python (originally from Novetta).</li>
<li><a href="https://github.com/mycert/ESPot" rel="noopener noreferrer">ESPot (⭐27)</a> - Elasticsearch honeypot written in NodeJS, to capture every attempts to exploit CVE-2014-3120.</li>
<li><a href="https://gitlab.com/bontchev/elasticpot" rel="noopener noreferrer">ElasticPot</a> - An Elasticsearch Honeypot.</li>
<li><a href="https://github.com/jordan-wright/elastichoney" rel="noopener noreferrer">Elastic honey (⭐185)</a> - Simple Elasticsearch Honeypot.</li>
<li><a href="https://github.com/Plazmaz/MongoDB-HoneyProxy" rel="noopener noreferrer">MongoDB-HoneyProxy (⭐92)</a> - MongoDB honeypot proxy.</li>
<li><a href="https://github.com/torque59/nosqlpot" rel="noopener noreferrer">NoSQLpot (⭐102)</a> - Honeypot framework built on a NoSQL-style database.</li>
<li><a href="https://github.com/sjinks/mysql-honeypotd" rel="noopener noreferrer">mysql-honeypotd (⭐32)</a> - Low interaction MySQL honeypot written in C.</li>
<li><a href="https://github.com/schmalle/MysqlPot" rel="noopener noreferrer">MysqlPot (⭐21)</a> - MySQL honeypot, still very early stage.</li>
<li><a href="https://github.com/betheroot/pghoney" rel="noopener noreferrer">pghoney (⭐19)</a> - Low-interaction Postgres Honeypot.</li>
<li><a href="https://github.com/betheroot/sticky_elephant" rel="noopener noreferrer">sticky_elephant (⭐11)</a> - Medium interaction postgresql honeypot.</li>
<li><a href="https://github.com/cypwnpwnsocute/RedisHoneyPot" rel="noopener noreferrer">RedisHoneyPot (⭐24)</a> - High Interaction Honeypot Solution for Redis protocol.</li>
</ul>
</li>
</ul>

<ul>
<li><p>SIP</p>
<ul>
<li><a href="https://github.com/SentryPeer/SentryPeer" rel="noopener noreferrer">SentryPeer (⭐190)</a> - Protect your SIP Servers from bad actors.</li>
</ul>
</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2022/34/"/>
    <summary>2 awesome projects updated on Aug 22 - Aug 28, 2022</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2022/32/</id>
    <title>Awesome Honeypots Updates on Aug 08 - Aug 14, 2022</title>
    <updated>2022-08-10T15:55:21.000Z</updated>
    <published>2022-08-10T15:55:21.000Z</published>
    <content type="html"><![CDATA[<h3><p>Honeypots</p>
</h3>
<ul>
<li><p>Low interaction honeypot</p>
<ul>
<li><a href="https://sourceforge.net/projects/honeyperl/" rel="noopener noreferrer">Honeyperl</a> - Honeypot software based in Perl with plugins developed for many functions like : wingates, telnet, squid, smtp, etc.</li>
<li><a href="https://github.com/dtag-dev-sec/tpotce" rel="noopener noreferrer">T-Pot (⭐7.7k)</a> - All in one honeypot appliance from telecom provider T-Mobile</li>
<li><a href="https://github.com/mariocandela/beelzebub" rel="noopener noreferrer">beelzebub (⭐879)</a> - A secure honeypot framework, extremely easy to configure by yaml 🚀</li>
</ul>
</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2022/32/"/>
    <summary>1 awesome projects updated on Aug 08 - Aug 14, 2022</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2022/2/</id>
    <title>Awesome Honeypots Updates on Jan 10 - Jan 16, 2022</title>
    <updated>2022-01-11T18:12:26.000Z</updated>
    <published>2022-01-11T18:12:26.000Z</published>
    <content type="html"><![CDATA[<h3><p>Honeypots</p>
</h3>
<ul>
<li>Service Honeypots<ul>
<li><a href="https://github.com/huuck/ADBHoney" rel="noopener noreferrer">ADBHoney (⭐165)</a> - Low interaction honeypot that simulates an Android device running Android Debug Bridge (ADB) server process.</li>
<li><a href="https://github.com/packetflare/amthoneypot" rel="noopener noreferrer">AMTHoneypot (⭐18)</a> - Honeypot for Intel's AMT Firmware Vulnerability CVE-2017-5689.</li>
<li><a href="https://github.com/aelth/ddospot" rel="noopener noreferrer">ddospot (⭐55)</a> - NTP, DNS, SSDP, Chargen and generic UDP-based amplification DDoS honeypot.</li>
<li><a href="https://github.com/DinoTools/dionaea" rel="noopener noreferrer">dionaea (⭐739)</a> - Home of the dionaea honeypot.</li>
<li><a href="https://github.com/ciscocsirt/dhp" rel="noopener noreferrer">dhp (⭐30)</a> - Simple Docker Honeypot server emulating small snippets of the Docker HTTP API.</li>
<li><a href="https://github.com/Marist-Innovation-Lab/DolosHoneypot" rel="noopener noreferrer">DolosHoneypot (⭐2)</a> - SDN (software defined networking) honeypot.</li>
<li><a href="https://github.com/ahoernecke/ensnare" rel="noopener noreferrer">Ensnare (⭐66)</a> - Easy to deploy Ruby honeypot.</li>
<li><a href="https://github.com/ls1911/GenAIPot" rel="noopener noreferrer">GenAIPot (⭐16)</a> - The first A.I based open source honeypot. supports POP3 and SMTP protocols and generates content using A.I based on user description.</li>
<li><a href="https://github.com/Zeerg/helix-honeypot" rel="noopener noreferrer">Helix (⭐40)</a> - K8s API Honeypot with Active Defense Capabilities.</li>
<li><a href="https://github.com/Cymmetria/honeycomb_plugins" rel="noopener noreferrer">honeycomb_plugins (⭐26)</a> - Plugin repository for Honeycomb, the honeypot framework by Cymmetria.</li>
<li>[honeydb] (<a href="https://honeydb.io/downloads" rel="noopener noreferrer">https://honeydb.io/downloads</a>) - Multi-service honeypot that is easy to deploy and configure. Can be configured to send interaction data to to HoneyDB's centralized collectors for access via REST API.</li>
<li><a href="https://github.com/fygrave/honeyntp" rel="noopener noreferrer">honeyntp (⭐53)</a> - NTP logger/honeypot.</li>
<li><a href="https://github.com/alexbredo/honeypot-camera" rel="noopener noreferrer">honeypot-camera (⭐50)</a> - Observation camera honeypot.</li>
<li><a href="https://github.com/alexbredo/honeypot-ftp" rel="noopener noreferrer">honeypot-ftp (⭐31)</a> - FTP Honeypot.</li>
<li><a href="https://github.com/qeeqbox/honeypots" rel="noopener noreferrer">honeypots (⭐767)</a> - 25 different honeypots in a single pypi package! (dns, ftp, httpproxy, http, https, imap, mysql, pop3, postgres, redis, smb, smtp, socks5, ssh, telnet, vnc, mssql, elastic, ldap, ntp, memcache, snmp, oracle, sip and irc).</li>
<li><a href="https://github.com/honeytrap/honeytrap" rel="noopener noreferrer">honeytrap (⭐1.2k)</a> - Advanced Honeypot framework written in Go that can be connected with other honeypot software.</li>
<li><a href="https://github.com/foospidy/HoneyPy" rel="noopener noreferrer">HoneyPy (⭐466)</a> - Low interaction honeypot.</li>
<li><a href="https://github.com/UHH-ISS/honeygrove" rel="noopener noreferrer">Honeygrove (⭐20)</a> - Multi-purpose modular honeypot based on Twisted.</li>
<li><a href="https://github.com/securitygeneration/Honeyport" rel="noopener noreferrer">Honeyport (⭐44)</a> - Simple honeyport written in Bash and Python.</li>
<li><a href="https://github.com/glaslos/honeyprint" rel="noopener noreferrer">Honeyprint (⭐19)</a> - Printer honeypot.</li>
<li><a href="https://hub.docker.com/r/lyrebird/honeypot-base/" rel="noopener noreferrer">Lyrebird</a> - Modern high-interaction honeypot framework.</li>
<li><a href="https://github.com/Cymmetria/micros_honeypot" rel="noopener noreferrer">MICROS honeypot (⭐16)</a> - Low interaction honeypot to detect CVE-2018-2636 in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (MICROS).</li>
<li><a href="https://github.com/christophe77/node-ftp-honeypot" rel="noopener noreferrer">node-ftp-honeypot (⭐5)</a> - FTP server honeypot in JS.</li>
<li><a href="https://github.com/gosecure/pyrdp" rel="noopener noreferrer">pyrdp (⭐1.6k)</a> - RDP man-in-the-middle and library for Python 3 with the ability to watch connections live or after the fact.</li>
<li><a href="https://github.com/kryptoslogic/rdppot" rel="noopener noreferrer">rdppot (⭐65)</a> - RDP honeypot</li>
<li><a href="https://github.com/citronneur/rdpy" rel="noopener noreferrer">RDPy (⭐1.7k)</a> - Microsoft Remote Desktop Protocol (RDP) honeypot implemented in Python.</li>
<li><a href="https://github.com/r0hi7/HoneySMB" rel="noopener noreferrer">SMB Honeypot (⭐48)</a> - High interaction SMB service honeypot capable of capturing wannacry-like Malware.</li>
<li><a href="https://github.com/inguardians/toms_honeypot" rel="noopener noreferrer">Tom's Honeypot (⭐26)</a> - Low interaction Python honeypot.</li>
<li><a href="https://github.com/0xBallpoint/trapster-community" rel="noopener noreferrer">Trapster Commmunity (⭐116)</a> - Modural and easy to install Python Honeypot, with comprehensive alerting</li>
<li><a href="https://github.com/dutchcoders/troje/" rel="noopener noreferrer">troje (⭐45)</a> - Honeypot that runs each connection with the service within a separate LXC container.</li>
<li><a href="https://github.com/Cymmetria/weblogic_honeypot" rel="noopener noreferrer">WebLogic honeypot (⭐32)</a> - Low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware.</li>
<li><a href="https://github.com/csirtgadgets/csirtg-honeypot" rel="noopener noreferrer">WhiteFace Honeypot (⭐5)</a> - Twisted based honeypot for WhiteFace.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Distributed Honeypots</p>
<ul>
<li><a href="https://github.com/RevengeComing/DemonHunter" rel="noopener noreferrer">DemonHunter (⭐61)</a> - Low interaction honeypot server.</li>
</ul>
</li>
</ul>

<ul>
<li><p>ICS/SCADA honeypots</p>
<ul>
<li><a href="https://github.com/mushorg/conpot" rel="noopener noreferrer">Conpot (⭐1.3k)</a> - ICS/SCADA honeypot.</li>
<li><a href="https://github.com/sjhilt/GasPot" rel="noopener noreferrer">GasPot (⭐139)</a> - Veeder Root Gaurdian AST, common in the oil and gas industry.</li>
<li><a href="http://scadahoneynet.sourceforge.net" rel="noopener noreferrer">SCADA honeynet</a> - Building Honeypots for Industrial Networks.</li>
<li><a href="https://github.com/sk4ld/gridpot" rel="noopener noreferrer">gridpot (⭐55)</a> - Open source tools for realistic-behaving electric grid honeynets.</li>
<li><a href="http://www.digitalbond.com/blog/2007/07/24/scada-honeynet-article-in-infragard-publication/" rel="noopener noreferrer">scada-honeynet</a> - Mimics many of the services from a popular PLC and better helps SCADA researchers understand potential risks of exposed control system devices.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Other/random</p>
<ul>
<li><a href="https://github.com/MalwareTech/CitrixHoneypot" rel="noopener noreferrer">CitrixHoneypot (⭐114)</a> - Detect and log CVE-2019-19781 scan and exploitation attempts.</li>
<li><a href="https://github.com/naorlivne/dshp" rel="noopener noreferrer">Damn Simple Honeypot (DSHP) (⭐17)</a> - Honeypot framework with pluggable handlers.</li>
<li><a href="https://github.com/nsmfoo/dicompot" rel="noopener noreferrer">dicompot (⭐24)</a> - DICOM Honeypot.</li>
<li><a href="https://gitlab.com/bontchev/ipphoney" rel="noopener noreferrer">IPP Honey</a> - A honeypot for the Internet Printing Protocol.</li>
<li><a href="https://github.com/thomaspatzke/Log4Pot" rel="noopener noreferrer">Log4Pot (⭐92)</a> - A honeypot for the Log4Shell vulnerability (CVE-2021-44228).</li>
<li><a href="https://github.com/ivre/masscanned" rel="noopener noreferrer">Masscanned (⭐119)</a> - Let's be scanned. A low-interaction honeypot focused on network scanners and bots. It integrates very well with IVRE to build a self-hosted alternative to GreyNoise.</li>
<li><a href="https://github.com/schmalle/medpot" rel="noopener noreferrer">medpot (⭐25)</a> -  HL7 / FHIR honeypot.</li>
<li><a href="https://github.com/DataSoft/Nova" rel="noopener noreferrer">NOVA (⭐75)</a> - Uses honeypots as detectors, looks like a complete system.</li>
<li><a href="https://github.com/upa/ofpot" rel="noopener noreferrer">OpenFlow Honeypot (OFPot) (⭐23)</a> - Redirects traffic for unused IPs to a honeypot, built on POX.</li>
<li><a href="https://github.com/thinkst/opencanary" rel="noopener noreferrer">OpenCanary (⭐2.4k)</a> - Modular and decentralised honeypot daemon that runs several canary versions of services that alerts when a service is (ab)used.</li>
<li><a href="https://github.com/cymmetria/ciscoasa_honeypot" rel="noopener noreferrer">ciscoasa_honeypot (⭐51)</a> A low interaction honeypot for the Cisco ASA component capable of detecting CVE-2018-0101, a DoS and remote code execution vulnerability.</li>
<li><a href="https://github.com/sa7mon/miniprint" rel="noopener noreferrer">miniprint (⭐202)</a> - A medium interaction printer honeypot.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Botnet C2 tools</p>
<ul>
<li><a href="https://github.com/pjlantz/Hale" rel="noopener noreferrer">Hale (⭐191)</a> - Botnet command and control monitor.</li>
<li><a href="https://code.google.com/archive/p/dns-mole/" rel="noopener noreferrer">dnsMole</a> - Analyses DNS traffic and potentionaly detect botnet command and control server activity, along with infected hosts.</li>
</ul>
</li>
</ul>

<ul>
<li><p>IPv6 attack detection tool</p>
<ul>
<li><a href="https://github.com/mzweilin/ipv6-attack-detector/" rel="noopener noreferrer">ipv6-attack-detector (⭐39)</a> - Google Summer of Code 2012 project, supported by The Honeynet Project organization.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Dynamic code instrumentation toolkit</p>
<ul>
<li><a href="https://www.frida.re" rel="noopener noreferrer">Frida</a> - Inject JavaScript to explore native apps on Windows, Mac, Linux, iOS and Android.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Tool to convert website to server honeypots</p>
<ul>
<li><a href="http://hihat.sourceforge.net/" rel="noopener noreferrer">HIHAT</a> - Transform arbitrary PHP applications into web-based high-interaction Honeypots.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Malware collector</p>
<ul>
<li><a href="https://bruteforcelab.com/kippo-malware" rel="noopener noreferrer">Kippo-Malware</a> - Python script that will download all malicious files stored as URLs in a Kippo SSH honeypot database.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Distributed sensor deployment</p>
<ul>
<li><a href="https://communityhoneynetwork.readthedocs.io/en/stable/" rel="noopener noreferrer">Community Honey Network</a> - CHN aims to make deployments honeypots and honeypot management tools easy and flexible. The default deployment method uses Docker Compose and Docker to deploy with a few simple commands.</li>
<li><a href="https://github.com/threatstream/mhn" rel="noopener noreferrer">Modern Honey Network</a> - Multi-snort and honeypot sensor management, uses a network of VMs, small footprint SNORT installations, stealthy dionaeas, and a centralized server for management.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Network Analysis Tool</p>
<ul>
<li><a href="https://code.google.com/archive/p/tracexploit/" rel="noopener noreferrer">Tracexploit</a> - Replay network packets.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Log anonymizer</p>
<ul>
<li><a href="http://code.google.com/archive/p/loganon/" rel="noopener noreferrer">LogAnon</a> - Log anonymization library that helps having anonymous logs consistent between logs and network captures.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Low interaction honeypot (router back door)</p>
<ul>
<li><a href="https://github.com/knalli/honeypot-for-tcp-32764" rel="noopener noreferrer">Honeypot-32764 (⭐18)</a> - Honeypot for router backdoor (TCP 32764).</li>
<li><a href="https://github.com/lcashdol/WAPot" rel="noopener noreferrer">WAPot (⭐19)</a> - Honeypot that can be used to observe traffic directed at home routers.</li>
</ul>
</li>
</ul>

<ul>
<li><p>honeynet farm traffic redirector</p>
<ul>
<li><a href="https://web.archive.org/web/20100326040550/http://www.honeynet.org.pt:80/index.php/HoneyMole" rel="noopener noreferrer">Honeymole</a> - Deploy multiple sensors that redirect traffic to a centralized collection of honeypots.</li>
</ul>
</li>
</ul>

<ul>
<li><p>HTTPS Proxy</p>
<ul>
<li><a href="https://mitmproxy.org/" rel="noopener noreferrer">mitmproxy</a> - Allows traffic flows to be intercepted, inspected, modified, and replayed.</li>
</ul>
</li>
</ul>

<ul>
<li><p>System instrumentation</p>
<ul>
<li><a href="https://sysdig.com/opensource/" rel="noopener noreferrer">Sysdig</a> - Open source, system-level exploration allows one to capture system state and activity from a running GNU/Linux instance, then save, filter, and analyze the results.</li>
<li><a href="https://github.com/rabbitstack/fibratus" rel="noopener noreferrer">Fibratus (⭐2.3k)</a> - Tool for exploration and tracing of the Windows kernel.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Honeypot for USB-spreading malware</p>
<ul>
<li><a href="https://github.com/honeynet/ghost-usb-honeypot" rel="noopener noreferrer">Ghost-usb (⭐97)</a> - Honeypot for malware that propagates via USB storage devices.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Data Collection</p>
<ul>
<li><a href="https://bruteforcelab.com/kippo2mysql" rel="noopener noreferrer">Kippo2MySQL</a> - Extracts some very basic stats from Kippo’s text-based log files and inserts them in a MySQL database.</li>
<li><a href="https://bruteforcelab.com/kippo2elasticsearch" rel="noopener noreferrer">Kippo2ElasticSearch</a> - Python script to transfer data from a Kippo SSH honeypot MySQL database to an ElasticSearch instance (server or cluster).</li>
</ul>
</li>
</ul>

<ul>
<li><p>Passive network audit framework parser</p>
<ul>
<li><a href="https://github.com/jusafing/pnaf" rel="noopener noreferrer">Passive Network Audit Framework (pnaf) (⭐32)</a> - Framework that combines multiple passive and automated analysis techniques in order to provide a security assessment of network platforms.</li>
</ul>
</li>
</ul>

<ul>
<li><p>VM monitoring and tools</p>
<ul>
<li><a href="https://github.com/nsmfoo/antivmdetection" rel="noopener noreferrer">Antivmdetect (⭐736)</a> - Script to create templates to use with VirtualBox to make VM detection harder.</li>
<li><a href="https://github.com/hatching/vmcloak" rel="noopener noreferrer">VMCloak (⭐496)</a> - Automated Virtual Machine Generation and Cloaking for Cuckoo Sandbox.</li>
<li><a href="http://libvmi.com/" rel="noopener noreferrer">vmitools</a> - C library with Python bindings that makes it easy to monitor the low-level details of a running virtual machine.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Binary debugger</p>
<ul>
<li><a href="https://github.com/hexgolems/pint" rel="noopener noreferrer">Hexgolems - Pint Debugger Backend (⭐32)</a> - Debugger backend and LUA wrapper for PIN.</li>
<li><a href="https://github.com/hexgolems/schem" rel="noopener noreferrer">Hexgolems - Schem Debugger Frontend (⭐142)</a> - Debugger frontend.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Mobile Analysis Tool</p>
<ul>
<li><a href="https://github.com/androguard/androguard" rel="noopener noreferrer">Androguard (⭐5.5k)</a> - Reverse engineering, Malware and goodware analysis of Android applications and more.</li>
<li><a href="https://github.com/honeynet/apkinspector/" rel="noopener noreferrer">APKinspector (⭐838)</a> - Powerful GUI tool for analysts to analyze the Android applications.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Honeynet data fusion</p>
<ul>
<li><a href="https://projects.honeynet.org/hflow" rel="noopener noreferrer">HFlow2</a> - Data coalesing tool for honeynet/network analysis.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Server</p>
<ul>
<li><a href="http://amunhoney.sourceforge.net" rel="noopener noreferrer">Amun</a> - Vulnerability emulation honeypot.</li>
<li><a href="https://github.com/trustedsec/artillery/" rel="noopener noreferrer">Artillery (⭐330)</a> - Open-source blue team tool designed to protect Linux and Windows operating systems through multiple methods.</li>
<li><a href="http://baitnswitch.sourceforge.net" rel="noopener noreferrer">Bait and Switch</a> - Redirects all hostile traffic to a honeypot that is partially mirroring your production system.</li>
<li><a href="https://github.com/Ziemeck/bifrozt-ansible" rel="noopener noreferrer">Bifrozt (⭐5)</a> - Automatic deploy bifrozt with ansible.</li>
<li><a href="http://conpot.org/" rel="noopener noreferrer">Conpot</a> - Low interactive server side Industrial Control Systems honeypot.</li>
<li><a href="https://github.com/johnnykv/heralding" rel="noopener noreferrer">Heralding (⭐378)</a> - Credentials catching honeypot.</li>
<li><a href="https://github.com/CanadianJeff/honeywrt" rel="noopener noreferrer">HoneyWRT (⭐21)</a> - Low interaction Python honeypot designed to mimic services or ports that might get targeted by attackers.</li>
<li><a href="https://github.com/provos/honeyd" rel="noopener noreferrer">Honeyd (⭐11)</a> - See <a href="#honeyd-tools">honeyd tools</a>.</li>
<li><a href="http://www.honeynet.org/node/773" rel="noopener noreferrer">Honeysink</a> - Open source network sinkhole that provides a mechanism for detection and prevention of malicious traffic on a given network.</li>
<li><a href="https://github.com/stamparm/hontel" rel="noopener noreferrer">Hontel (⭐160)</a> - Telnet Honeypot.</li>
<li><a href="http://www.keyfocus.net/kfsensor/" rel="noopener noreferrer">KFSensor</a> - Windows based honeypot Intrusion Detection System (IDS).</li>
<li><a href="http://labrea.sourceforge.net/labrea-info.html" rel="noopener noreferrer">LaBrea</a> - Takes over unused IP addresses, and creates virtual servers that are attractive to worms, hackers, and other denizens of the Internet.</li>
<li><a href="https://github.com/Cymmetria/MTPot" rel="noopener noreferrer">MTPot (⭐104)</a> - Open Source Telnet Honeypot, focused on Mirai malware.</li>
<li><a href="https://github.com/blaverick62/SIREN" rel="noopener noreferrer">SIREN (⭐13)</a> - Semi-Intelligent HoneyPot Network - HoneyNet Intelligent Virtual Environment.</li>
<li><a href="https://github.com/balte/TelnetHoney" rel="noopener noreferrer">TelnetHoney (⭐1)</a> - Simple telnet honeypot.</li>
<li><a href="https://github.com/jekil/UDPot" rel="noopener noreferrer">UDPot Honeypot (⭐48)</a> - Simple UDP/DNS honeypot scripts.</li>
<li><a href="https://github.com/fnzv/YAFH" rel="noopener noreferrer">Yet Another Fake Honeypot (YAFH) (⭐9)</a> - Simple honeypot written in Go.</li>
<li><a href="https://github.com/ajackal/arctic-swallow" rel="noopener noreferrer">arctic-swallow (⭐2)</a> - Low interaction honeypot.</li>
<li><a href="https://github.com/fofapro/fapro" rel="noopener noreferrer">fapro (⭐1.6k)</a> - Fake Protocol Server.</li>
<li><a href="https://github.com/mushorg/glutton" rel="noopener noreferrer">glutton (⭐271)</a> - All eating honeypot.</li>
<li><a href="https://github.com/Mojachieee/go-HoneyPot" rel="noopener noreferrer">go-HoneyPot (⭐43)</a> - Honeypot server written in Go.</li>
<li><a href="https://github.com/kingtuna/go-emulators" rel="noopener noreferrer">go-emulators (⭐10)</a> - Honeypot Golang emulators.</li>
<li><a href="https://github.com/sec51/honeymail" rel="noopener noreferrer">honeymail (⭐29)</a> - SMTP honeypot written in Golang.</li>
<li><a href="https://github.com/tillmannw/honeytrap" rel="noopener noreferrer">honeytrap (⭐94)</a> - Low-interaction honeypot and network security tool written to catch attacks against TCP and UDP services.</li>
<li><a href="https://github.com/yvesago/imap-honey" rel="noopener noreferrer">imap-honey (⭐25)</a> - IMAP honeypot written in Golang.</li>
<li><a href="https://www.openhub.net/p/mwcollectd" rel="noopener noreferrer">mwcollectd</a> - Versatile malware collection daemon, uniting the best features of nepenthes and honeytrap.</li>
<li><a href="https://github.com/lnslbrty/potd" rel="noopener noreferrer">potd (⭐30)</a> - Highly scalable low- to medium-interaction SSH/TCP honeypot designed for OpenWrt/IoT devices leveraging several Linux kernel features, such as namespaces, seccomp and thread capabilities.</li>
<li><a href="https://github.com/bartnv/portlurker" rel="noopener noreferrer">portlurker (⭐33)</a> - Port listener in Rust with protocol guessing and safe string display.</li>
<li><a href="https://github.com/rshipp/slipm-honeypot" rel="noopener noreferrer">slipm-honeypot (⭐17)</a> - Simple low-interaction port monitoring honeypot.</li>
<li><a href="https://github.com/Phype/telnet-iot-honeypot" rel="noopener noreferrer">telnet-iot-honeypot (⭐304)</a> - Python telnet honeypot for catching botnet binaries.</li>
<li><a href="https://github.com/robertdavidgraham/telnetlogger" rel="noopener noreferrer">telnetlogger (⭐240)</a> - Telnet honeypot designed to track the Mirai botnet.</li>
<li><a href="https://github.com/magisterquis/vnclowpot" rel="noopener noreferrer">vnclowpot (⭐22)</a> - Low interaction VNC honeypot.</li>
</ul>
</li>
</ul>

<ul>
<li><p>IDS signature generation</p>
<ul>
<li><a href="http://www.icir.org/christian/honeycomb/" rel="noopener noreferrer">Honeycomb</a> - Automated signature creation using honeypots.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Lookup service for AS-numbers and prefixes</p>
<ul>
<li><a href="http://www.cc2asn.com/" rel="noopener noreferrer">CC2ASN</a> - Simple lookup service for AS-numbers and prefixes belonging to any given country in the world.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Data Collection / Data Sharing</p>
<ul>
<li><a href="http://hpfriends.honeycloud.net/#/home" rel="noopener noreferrer">HPfriends</a> - Honeypot data-sharing platform.<ul>
<li><a href="https://heipei.io/sigint-hpfriends/" rel="noopener noreferrer">hpfriends - real-time social data-sharing</a> - Presentation about HPFriends feed system</li>
</ul>
</li>
<li><a href="https://github.com/rep/hpfeeds/" rel="noopener noreferrer">HPFeeds (⭐214)</a> - Lightweight authenticated publish-subscribe protocol.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Central management tool</p>
<ul>
<li><a href="http://www.nepenthespharm.com/" rel="noopener noreferrer">PHARM</a> - Manage, report, and analyze your distributed Nepenthes instances.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Network connection analyzer</p>
<ul>
<li><a href="http://impost.sourceforge.net/" rel="noopener noreferrer">Impost</a> - Network security auditing tool designed to analyze the forensics behind compromised and/or vulnerable daemons.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Honeypot extensions to Wireshark</p>
<ul>
<li><a href="https://www.honeynet.org/project/WiresharkExtensions" rel="noopener noreferrer">Wireshark Extensions</a> - Apply Snort IDS rules and signatures against packet capture files using Wireshark.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Client</p>
<ul>
<li><a href="https://www.gfi.com/products-and-solutions/all-products" rel="noopener noreferrer">CWSandbox / GFI Sandbox</a></li>
<li><a href="https://redmine.honeynet.org/projects/linux-capture-hpc/wiki" rel="noopener noreferrer">Capture-HPC-Linux</a></li>
<li><a href="https://github.com/CERT-Polska/HSN-Capture-HPC-NG" rel="noopener noreferrer">Capture-HPC-NG (⭐11)</a></li>
<li><a href="https://projects.honeynet.org/capture-hpc" rel="noopener noreferrer">Capture-HPC</a> - High interaction client honeypot (also called honeyclient).</li>
<li><a href="http://www.atomicsoftwaresolutions.com/" rel="noopener noreferrer">HoneyBOT</a></li>
<li><a href="https://projects.honeynet.org/honeyc" rel="noopener noreferrer">HoneyC</a></li>
<li><a href="https://github.com/CERT-Polska/hsn2-bundle" rel="noopener noreferrer">HoneySpider Network (⭐29)</a> - Highly-scalable system integrating multiple client honeypots to detect malicious websites.</li>
<li><a href="https://code.google.com/archive/p/gsoc-honeyweb/" rel="noopener noreferrer">HoneyWeb</a> - Web interface created to manage and remotely share Honeyclients resources.</li>
<li><a href="https://github.com/urule99/jsunpack-n" rel="noopener noreferrer">Jsunpack-n (⭐164)</a></li>
<li><a href="http://monkeyspider.sourceforge.net" rel="noopener noreferrer">MonkeySpider</a></li>
<li><a href="https://github.com/honeynet/phoneyc" rel="noopener noreferrer">PhoneyC (⭐26)</a> - Python honeyclient (later replaced by Thug).</li>
<li><a href="https://github.com/shjalayeri/pwnypot" rel="noopener noreferrer">Pwnypot</a> - High Interaction Client Honeypot.</li>
<li><a href="https://github.com/thugs-rumal/" rel="noopener noreferrer">Rumal</a> - Thug's Rumāl: a Thug's dress and weapon.</li>
<li><a href="https://www.cs.vu.nl/~herbertb/misc/shelia/" rel="noopener noreferrer">Shelia</a> - Client-side honeypot for attack detection.</li>
<li><a href="https://buffer.github.io/thug/" rel="noopener noreferrer">Thug</a> - Python-based low-interaction honeyclient.</li>
<li><a href="https://thug-distributed.readthedocs.io/en/latest/index.html" rel="noopener noreferrer">Thug Distributed Task Queuing</a></li>
<li><a href="https://www.honeynet.org/project/Trigona" rel="noopener noreferrer">Trigona</a></li>
<li><a href="https://urlquery.net/" rel="noopener noreferrer">URLQuery</a></li>
<li><a href="https://github.com/Masood-M/yalih" rel="noopener noreferrer">YALIH (Yet Another Low Interaction Honeyclient) (⭐68)</a> - Low-interaction client honeypot designed to detect malicious websites through signature, anomaly, and pattern matching techniques.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Honeypot</p>
<ul>
<li><a href="http://www.all.net/dtk/dtk.html" rel="noopener noreferrer">Deception Toolkit</a></li>
<li><a href="https://github.com/mushorg/imhoneypot" rel="noopener noreferrer">IMHoneypot (⭐16)</a></li>
</ul>
</li>
</ul>

<ul>
<li><p>PDF document inspector</p>
<ul>
<li><a href="https://github.com/jesparza/peepdf" rel="noopener noreferrer">peepdf (⭐1.4k)</a> - Powerful Python tool to analyze PDF documents.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Hybrid low/high interaction honeypot</p>
<ul>
<li><a href="http://honeybrid.sourceforge.net" rel="noopener noreferrer">HoneyBrid</a></li>
</ul>
</li>
</ul>

<ul>
<li><p>SSH Honeypots</p>
<ul>
<li><a href="https://github.com/morian/blacknet" rel="noopener noreferrer">Blacknet (⭐20)</a> - Multi-head SSH honeypot system.</li>
<li><a href="https://github.com/cowrie/cowrie" rel="noopener noreferrer">Cowrie (⭐5.5k)</a> - Cowrie SSH Honeypot (based on kippo).</li>
<li><a href="https://github.com/xme/dshield-docker" rel="noopener noreferrer">DShield docker (⭐15)</a> - Docker container running cowrie with DShield output enabled.</li>
<li><a href="https://github.com/skeeto/endlessh" rel="noopener noreferrer">endlessh (⭐7.6k)</a> - SSH tarpit that slowly sends an endless banner. (<a href="https://hub.docker.com/r/linuxserver/endlessh" rel="noopener noreferrer">docker image</a>)</li>
<li><a href="https://github.com/tnich/honssh" rel="noopener noreferrer">HonSSH (⭐374)</a> - Logs all SSH communications between a client and server.</li>
<li><a href="https://github.com/Cryptix720/HUDINX" rel="noopener noreferrer">HUDINX (⭐5)</a> - Tiny interaction SSH honeypot engineered in Python to log brute force attacks and, most importantly, the entire shell interaction performed by the attacker.</li>
<li><a href="https://github.com/desaster/kippo" rel="noopener noreferrer">Kippo (⭐1.7k)</a> - Medium interaction SSH honeypot.</li>
<li><a href="https://github.com/gregcmartin/Kippo_JunOS" rel="noopener noreferrer">Kippo_JunOS (⭐10)</a> - Kippo configured to be a backdoored netscreen.</li>
<li><a href="https://github.com/madirish/kojoney2" rel="noopener noreferrer">Kojoney2 (⭐37)</a> - Low interaction SSH honeypot written in Python and based on Kojoney by Jose Antonio Coret.</li>
<li><a href="http://kojoney.sourceforge.net/" rel="noopener noreferrer">Kojoney</a> - Python-based Low interaction honeypot that emulates an SSH server implemented with Twisted Conch.</li>
<li><a href="https://github.com/deroux/longitudinal-analysis-cowrie" rel="noopener noreferrer">Longitudinal Analysis of SSH Cowrie Honeypot Logs (⭐18)</a> - Python based command line tool to analyze cowrie logs over time.</li>
<li><a href="http://longtail.it.marist.edu/honey/" rel="noopener noreferrer">LongTail Log Analysis @ Marist College</a> - Analyzed SSH honeypot logs.</li>
<li><a href="https://github.com/batchmcnulty/Malbait" rel="noopener noreferrer">Malbait (⭐8)</a> - Simple TCP/UDP honeypot implemented in Perl.</li>
<li><a href="https://github.com/ncouture/MockSSH" rel="noopener noreferrer">MockSSH (⭐126)</a> - Mock an SSH server and define all commands it supports (Python, Twisted).</li>
<li><a href="https://github.com/xlfe/cowrie2neo" rel="noopener noreferrer">cowrie2neo (⭐7)</a> - Parse cowrie honeypot logs into a neo4j database.</li>
<li><a href="https://github.com/ashmckenzie/go-sshoney" rel="noopener noreferrer">go-sshoney (⭐31)</a> - SSH Honeypot.</li>
<li><a href="https://github.com/fzerorubigd/go0r" rel="noopener noreferrer">go0r (⭐35)</a> - Simple ssh honeypot in Golang.</li>
<li><a href="https://github.com/PaulMaddox/gohoney" rel="noopener noreferrer">gohoney (⭐11)</a> - SSH honeypot written in Go.</li>
<li><a href="https://github.com/sahilm/hived" rel="noopener noreferrer">hived (⭐3)</a> - Golang-based honeypot.</li>
<li><a href="https://github.com/joshrendek/hnypots-agent" rel="noopener noreferrer">hnypots-agent) (⭐37)</a> - SSH Server in Go that logs username and password combinations.</li>
<li><a href="https://github.com/mdp/honeypot.go" rel="noopener noreferrer">honeypot.go (⭐28)</a> - SSH Honeypot written in Go.</li>
<li><a href="https://github.com/ppacher/honeyssh" rel="noopener noreferrer">honeyssh (⭐12)</a> - Credential dumping SSH honeypot with statistics.</li>
<li><a href="https://github.com/czardoz/hornet" rel="noopener noreferrer">hornet (⭐22)</a> - Medium interaction SSH honeypot that supports multiple virtual hosts.</li>
<li><a href="https://github.com/JustinAzoff/ssh-auth-logger" rel="noopener noreferrer">ssh-auth-logger (⭐21)</a> - Low/zero interaction SSH authentication logging honeypot.</li>
<li><a href="https://github.com/droberson/ssh-honeypot" rel="noopener noreferrer">ssh-honeypot (⭐646)</a> - Fake sshd that logs IP addresses, usernames, and passwords.</li>
<li><a href="https://github.com/amv42/sshd-honeypot" rel="noopener noreferrer">ssh-honeypot (⭐26)</a> - Modified version of the OpenSSH deamon that forwards commands to Cowrie where all commands are interpreted and returned.</li>
<li><a href="https://github.com/sjinks/ssh-honeypotd" rel="noopener noreferrer">ssh-honeypotd (⭐17)</a> - Low-interaction SSH honeypot written in C.</li>
<li><a href="https://github.com/traetox/sshForShits" rel="noopener noreferrer">sshForShits (⭐39)</a> - Framework for a high interaction SSH honeypot.</li>
<li><a href="https://github.com/jaksi/sshesame" rel="noopener noreferrer">sshesame (⭐1.6k)</a> - Fake SSH server that lets everyone in and logs their activity.</li>
<li><a href="https://github.com/magisterquis/sshhipot" rel="noopener noreferrer">sshhipot (⭐167)</a> - High-interaction MitM SSH honeypot.</li>
<li><a href="https://github.com/magisterquis/sshlowpot" rel="noopener noreferrer">sshlowpot (⭐14)</a> - Yet another no-frills low-interaction SSH honeypot in Go.</li>
<li><a href="https://github.com/mkishere/sshsyrup" rel="noopener noreferrer">sshsyrup (⭐97)</a> - Simple SSH Honeypot with features to capture terminal activity and upload to asciinema.org.</li>
<li><a href="https://github.com/lanjelot/twisted-honeypots" rel="noopener noreferrer">twisted-honeypots (⭐86)</a> - SSH, FTP and Telnet honeypots based on Twisted.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Distributed sensor project</p>
<ul>
<li><a href="https://sites.google.com/site/webhoneypotsite/" rel="noopener noreferrer">DShield Web Honeypot Project</a></li>
</ul>
</li>
</ul>

<ul>
<li><p>A pcap analyzer</p>
<ul>
<li><a href="https://projects.honeynet.org/honeysnap/" rel="noopener noreferrer">Honeysnap</a></li>
</ul>
</li>
</ul>

<ul>
<li><p>Network traffic redirector</p>
<ul>
<li><a href="https://projects.honeynet.org/honeywall/" rel="noopener noreferrer">Honeywall</a></li>
</ul>
</li>
</ul>

<ul>
<li><p>Honeypot Distribution with mixed content</p>
<ul>
<li><a href="https://bruteforcelab.com/honeydrive" rel="noopener noreferrer">HoneyDrive</a></li>
</ul>
</li>
</ul>

<ul>
<li><p>Honeypot sensor</p>
<ul>
<li><a href="https://redmine.honeynet.org/projects/honeeepi/wiki" rel="noopener noreferrer">Honeeepi</a> - Honeypot sensor on a Raspberry Pi based on a customized Raspbian OS.</li>
</ul>
</li>
</ul>

<ul>
<li><p>File carving</p>
<ul>
<li><a href="https://www.cgsecurity.org/" rel="noopener noreferrer">TestDisk &amp; PhotoRec</a></li>
</ul>
</li>
</ul>

<ul>
<li><p>Behavioral analysis tool for win32</p>
<ul>
<li><a href="https://www.honeynet.org/node/315" rel="noopener noreferrer">Capture BAT</a></li>
</ul>
</li>
</ul>

<ul>
<li><p>Live CD</p>
<ul>
<li><a href="https://www.secviz.org/node/89" rel="noopener noreferrer">DAVIX</a> - The DAVIX Live CD.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Spamtrap</p>
<ul>
<li><a href="https://metacpan.org/pod/release/MIKER/Mail-SMTP-Honeypot-0.11/Honeypot.pm" rel="noopener noreferrer">Mail::SMTP::Honeypot</a> - Perl module that appears to provide the functionality of a standard SMTP server.</li>
<li><a href="https://github.com/phin3has/mailoney" rel="noopener noreferrer">Mailoney (⭐264)</a> - SMTP honeypot written in python.</li>
<li><a href="https://github.com/johestephan/VerySimpleHoneypot" rel="noopener noreferrer">SendMeSpamIDS.py (⭐12)</a> - Simple SMTP fetch all IDS and analyzer.</li>
<li><a href="https://github.com/shiva-spampot/shiva" rel="noopener noreferrer">Shiva (⭐136)</a> - Spam Honeypot with Intelligent Virtual Analyzer.<ul>
<li><a href="https://www.pentestpartners.com/security-blog/shiva-the-spam-honeypot-tips-and-tricks-for-getting-it-up-and-running/" rel="noopener noreferrer">Shiva The Spam Honeypot Tips And Tricks For Getting It Up And Running</a></li>
</ul>
</li>
<li><a href="https://github.com/referefref/SMTPLLMPot" rel="noopener noreferrer">SMTPLLMPot (⭐6)</a> - A super simple SMTP Honeypot built using GPT3.5</li>
<li><a href="https://github.com/miguelraulb/spamhat" rel="noopener noreferrer">SpamHAT (⭐26)</a> - Spam Honeypot Tool.</li>
<li><a href="http://www.spamhole.net/" rel="noopener noreferrer">Spamhole</a></li>
<li><a href="https://github.com/jadb/honeypot" rel="noopener noreferrer">honeypot (⭐2)</a> - The Project Honey Pot un-official PHP SDK.</li>
<li><a href="http://man.openbsd.org/cgi-bin/man.cgi?query=spamd%26apropos=0%26sektion=0%26manpath=OpenBSD+Current%26arch=i386%26format=html" rel="noopener noreferrer">spamd</a></li>
</ul>
</li>
</ul>

<ul>
<li><p>Commercial honeynet</p>
<ul>
<li><a rel="noopener noreferrer">Cymmetria Mazerunner</a> - Leads attackers away from real targets and creates a footprint of the attack.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Server (Bluetooth)</p>
<ul>
<li><a href="https://github.com/andrewmichaelsmith/bluepot" rel="noopener noreferrer">Bluepot (⭐251)</a></li>
</ul>
</li>
</ul>

<ul>
<li><p>Dynamic analysis of Android apps</p>
<ul>
<li><a href="https://code.google.com/archive/p/droidbox/" rel="noopener noreferrer">Droidbox</a></li>
</ul>
</li>
</ul>

<ul>
<li><p>Dockerized Low Interaction packaging</p>
<ul>
<li><a href="https://github.com/sreinhardt/Docker-Honeynet" rel="noopener noreferrer">Docker honeynet (⭐22)</a> - Several Honeynet tools set up for Docker containers.</li>
<li><a href="https://hub.docker.com/r/honeynet/thug/" rel="noopener noreferrer">Dockerized Thug</a> - Dockerized <a href="https://github.com/buffer/thug" rel="noopener noreferrer">Thug (⭐1k)</a> to analyze malicious web content.</li>
<li><a href="https://github.com/mrschyte/dockerpot" rel="noopener noreferrer">Dockerpot (⭐148)</a> - Docker based honeypot.</li>
<li><a href="https://github.com/andrewmichaelsmith/manuka" rel="noopener noreferrer">Manuka (⭐24)</a> - Docker based honeypot (Dionaea and Kippo).</li>
<li><a href="https://github.com/run41/honey_ports" rel="noopener noreferrer">honey_ports (⭐7)</a> - Very simple but effective docker deployed honeypot to detect port scanning in your environment.</li>
<li><a href="https://github.com/MattCarothers/mhn-core-docker" rel="noopener noreferrer">mhn-core-docker (⭐34)</a> - Core elements of the Modern Honey Network implemented in Docker.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Network analysis</p>
<ul>
<li><a href="https://bitbucket.org/zaccone/quechua" rel="noopener noreferrer">Quechua</a></li>
</ul>
</li>
</ul>

<ul>
<li><p>SIP Server</p>
<ul>
<li><a href="http://artemisa.sourceforge.net" rel="noopener noreferrer">Artemnesia VoIP</a></li>
</ul>
</li>
</ul>

<ul>
<li><p>IOT Honeypot</p>
<ul>
<li><a href="https://github.com/omererdem/honeything" rel="noopener noreferrer">HoneyThing (⭐123)</a> - TR-069 Honeypot.</li>
<li><a href="https://github.com/darkarnium/kako" rel="noopener noreferrer">Kako (⭐27)</a> - Honeypots for a number of well known and deployed embedded device vulnerabilities.</li>
</ul>
</li>
</ul>

<ul>
<li>Honeytokens<ul>
<li><a href="https://github.com/thinkst/canarytokens" rel="noopener noreferrer">CanaryTokens (⭐1.8k)</a> - Self-hostable honeytoken generator and reporting dashboard; demo version available at <a href="https://canarytokens.org/generate" rel="noopener noreferrer">CanaryTokens.org</a>.</li>
<li><a href="https://github.com/0x4D31/honeybits" rel="noopener noreferrer">Honeybits (⭐272)</a> - Simple tool designed to enhance the effectiveness of your traps by spreading breadcrumbs and honeytokens across your production servers and workstations to lure the attacker toward your honeypots.</li>
<li><a href="https://github.com/0x4D31/honeylambda" rel="noopener noreferrer">Honeyλ (HoneyLambda) (⭐516)</a> - Simple, serverless application designed to create and monitor URL honeytokens, on top of AWS Lambda and Amazon API Gateway.</li>
<li><a href="https://github.com/secureworks/dcept" rel="noopener noreferrer">dcept (⭐505)</a> - Tool for deploying and detecting use of Active Directory honeytokens.</li>
<li><a href="https://github.com/0x4D31/honeyku" rel="noopener noreferrer">honeyku (⭐63)</a> - Heroku-based web honeypot that can be used to create and monitor fake HTTP endpoints (i.e. honeytokens).</li>
</ul>
</li>
</ul>
<h3><p>Honeyd Tools</p>
</h3>
<ul>
<li><p>Honeyd plugin</p>
<ul>
<li><a href="http://www.honeyd.org/tools.php" rel="noopener noreferrer">Honeycomb</a></li>
</ul>
</li>
</ul>

<ul>
<li><p>Honeyd viewer</p>
<ul>
<li><a href="http://honeyview.sourceforge.net/" rel="noopener noreferrer">Honeyview</a></li>
</ul>
</li>
</ul>

<ul>
<li><p>Honeyd to MySQL connector</p>
<ul>
<li><a href="https://bruteforcelab.com/honeyd2mysql" rel="noopener noreferrer">Honeyd2MySQL</a></li>
</ul>
</li>
</ul>

<ul>
<li><p>A script to visualize statistics from honeyd</p>
<ul>
<li><a href="https://bruteforcelab.com/honeyd-viz" rel="noopener noreferrer">Honeyd-Viz</a></li>
</ul>
</li>
</ul>

<ul>
<li>Honeyd stats<ul>
<li><a href="https://github.com/DataSoft/Honeyd/blob/master/scripts/misc/honeydsum-v0.3/honeydsum.pl" rel="noopener noreferrer">Honeydsum.pl (⭐369)</a></li>
</ul>
</li>
</ul>
<h3><p>Network and Artifact Analysis</p>
</h3>
<ul>
<li><p>Sandbox</p>
<ul>
<li><a href="http://www.few.vu.nl/argos/" rel="noopener noreferrer">Argos</a> - Emulator for capturing zero-day attacks.</li>
<li><a href="https://help.comodo.com/topic-72-1-451-4768-.html" rel="noopener noreferrer">COMODO automated sandbox</a></li>
<li><a href="https://cuckoosandbox.org/" rel="noopener noreferrer">Cuckoo</a> - Leading open source automated malware analysis system.</li>
<li><a href="https://github.com/buffer/pylibemu" rel="noopener noreferrer">Pylibemu (⭐126)</a> - Libemu Cython wrapper.</li>
<li><a href="https://monkey.org/~jose/software/rfi-sandbox/" rel="noopener noreferrer">RFISandbox</a> - PHP 5.x script sandbox built on top of <a href="https://pecl.php.net/package/funcall" rel="noopener noreferrer">funcall</a>.</li>
<li><a href="https://github.com/m4rco-/dorothy2" rel="noopener noreferrer">dorothy2 (⭐197)</a> - Malware/botnet analysis framework written in Ruby.</li>
<li><a href="https://github.com/hbhzwj/imalse" rel="noopener noreferrer">imalse (⭐13)</a> - Integrated MALware Simulator and Emulator.</li>
<li><a href="https://github.com/buffer/libemu" rel="noopener noreferrer">libemu (⭐151)</a> - Shellcode emulation library, useful for shellcode detection.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Sandbox-as-a-Service</p>
<ul>
<li><a href="https://www.hybrid-analysis.com" rel="noopener noreferrer">Hybrid Analysis</a> - Free malware analysis service powered by Payload Security that detects and analyzes unknown threats using a unique Hybrid Analysis technology.</li>
<li><a href="https://jbxcloud.joesecurity.org/login" rel="noopener noreferrer">Joebox Cloud</a> - Analyzes the behavior of malicious files including PEs, PDFs, DOCs, PPTs, XLSs, APKs, URLs and MachOs on Windows, Android and Mac OS X for suspicious activities.</li>
<li><a href="https://www.virustotal.com/" rel="noopener noreferrer">VirusTotal</a> - Analyze suspicious files and URLs to detect types of malware, and automatically share them with the security community.</li>
<li><a href="https://malwr.com/" rel="noopener noreferrer">malwr.com</a> - Free malware analysis service and community.</li>
</ul>
</li>
</ul>
<h3><p>Data Tools</p>
</h3>
<ul>
<li><p>Front Ends</p>
<ul>
<li><a href="https://github.com/rubenespadas/DionaeaFR" rel="noopener noreferrer">DionaeaFR (⭐66)</a> - Front Web to Dionaea low-interaction honeypot.</li>
<li><a href="https://github.com/jedie/django-kippo" rel="noopener noreferrer">Django-kippo (⭐12)</a> - Django App for kippo SSH Honeypot.</li>
<li><a href="https://github.com/GovCERT-CZ/Shockpot-Frontend" rel="noopener noreferrer">Shockpot-Frontend (⭐3)</a> - Full featured script to visualize statistics from a Shockpot honeypot.</li>
<li><a href="https://github.com/aplura/Tango" rel="noopener noreferrer">Tango (⭐254)</a> - Honeypot Intelligence with Splunk.</li>
<li><a href="https://github.com/GovCERT-CZ/Wordpot-Frontend" rel="noopener noreferrer">Wordpot-Frontend (⭐5)</a> - Full featured script to visualize statistics from a Wordpot honeypot.</li>
<li><a href="https://github.com/schmalle/honeyalarmg2" rel="noopener noreferrer">honeyalarmg2 (⭐4)</a> - Simplified UI for showing honeypot alarms.</li>
<li><a href="https://github.com/Joss-Steward/honeypotDisplay" rel="noopener noreferrer">honeypotDisplay (⭐3)</a> - Flask website which displays data gathered from an SSH Honeypot.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Visualization</p>
<ul>
<li><a href="https://github.com/hgascon/acapulco" rel="noopener noreferrer">Acapulco (⭐10)</a> - Automated Attack Community Graph Construction.</li>
<li><a href="https://github.com/ayrus/afterglow-cloud" rel="noopener noreferrer">Afterglow Cloud (⭐15)</a></li>
<li><a href="http://afterglow.sourceforge.net/" rel="noopener noreferrer">Afterglow</a></li>
<li><a href="https://github.com/katkad/Glastopf-Analytics" rel="noopener noreferrer">Glastopf Analytics (⭐3)</a> - Easy honeypot statistics.</li>
<li><a href="https://github.com/SneakersInc/HoneyMalt" rel="noopener noreferrer">HoneyMalt (⭐14)</a> - Maltego tranforms for mapping Honeypot systems.</li>
<li><a href="https://github.com/fw42/honeymap" rel="noopener noreferrer">HoneyMap (⭐219)</a> - Real-time websocket stream of GPS events on a fancy SVG world map.</li>
<li><a href="https://sourceforge.net/projects/honeystats/" rel="noopener noreferrer">HoneyStats</a> - Statistical view of the recorded activity on a Honeynet.</li>
<li><a href="https://github.com/yuchincheng/HpfeedsHoneyGraph" rel="noopener noreferrer">HpfeedsHoneyGraph (⭐15)</a> - Visualization app to visualize hpfeeds logs.</li>
<li><a href="https://github.com/ivre/ivre" rel="noopener noreferrer">IVRE (⭐3.7k)</a> - Network recon framework, published by @cea-sec &amp; @ANSSI-FR. Build your own, self-hosted and fully-controlled alternatives to Criminalip / Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, collect and analyse network intelligence from your sensors, and much more!</li>
<li><a href="https://github.com/mfontani/kippo-stats" rel="noopener noreferrer">Kippo stats (⭐18)</a> - Mojolicious app to display statistics for your kippo SSH honeypot.</li>
<li><a href="https://bruteforcelab.com/kippo-graph" rel="noopener noreferrer">Kippo-Graph</a> - Full featured script to visualize statistics from a Kippo SSH honeypot.</li>
<li><a href="https://github.com/jpyorre/IntelligentHoneyNet" rel="noopener noreferrer">The Intelligent HoneyNet (⭐62)</a> - Create actionable information from honeypots.</li>
<li><a href="https://github.com/oguzy/ovizart" rel="noopener noreferrer">ovizart (⭐47)</a> - Visual analysis for network traffic.</li>
</ul>
</li>
</ul>
<h3><p>Guides</p>
</h3>
<ul>
<li><p>Deployment</p>
<ul>
<li><a href="http://andrewmichaelsmith.com/2012/03/dionaea-honeypot-on-ec2-in-20-minutes/" rel="noopener noreferrer">Dionaea and EC2 in 20 Minutes</a> - Tutorial on setting up Dionaea on an EC2 instance.</li>
<li><a href="https://isc.sans.edu/diary/22680" rel="noopener noreferrer">Using a Raspberry Pi honeypot to contribute data to DShield/ISC</a> - The Raspberry Pi based system will allow us to maintain one code base that will make it easier to collect rich logs beyond firewall logs.</li>
<li><a href="https://github.com/free5ty1e/honeypotpi" rel="noopener noreferrer">honeypotpi (⭐34)</a> - Script for turning a Raspberry Pi into a HoneyPot Pi.</li>
</ul>
</li>
</ul>

<ul>
<li><p>Research Papers</p>
<ul>
<li><a href="https://github.com/shbhmsingh72/Honeypot-Research-Papers" rel="noopener noreferrer">Honeypot research papers (⭐31)</a> - PDFs of research papers on honeypots.</li>
<li><a href="https://link.springer.com/article/10.1007%2Fs10115-008-0137-3" rel="noopener noreferrer">vEYE</a> - Behavioral footprinting for self-propagating worm detection and profiling.</li>
</ul>
</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2022/2/"/>
    <summary>63 awesome projects updated on Jan 10 - Jan 16, 2022</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/31/</id>
    <title>Awesome Honeypots Updates on Jul 30 - Aug 05, 2018</title>
    <updated>2018-07-31T19:44:30.000Z</updated>
    <published>2018-07-31T19:44:30.000Z</published>
    <content type="html"><![CDATA[<h3><p>Related Lists</p>
</h3>
<ul>
<li><a href="https://github.com/caesar0301/awesome-pcaptools" rel="noopener noreferrer">awesome-pcaptools (⭐3.2k)</a> - Useful in network traffic analysis.</li>
</ul>

<ul>
<li><a href="https://github.com/rshipp/awesome-malware-analysis" rel="noopener noreferrer">awesome-malware-analysis (⭐12k)</a> - Some overlap here for artifact analysis.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/31/"/>
    <summary>2 awesome projects updated on Jul 30 - Aug 05, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2015/32/</id>
    <title>Awesome Honeypots Updates on Aug 10 - Aug 16, 2015</title>
    <updated>2015-08-05T16:29:14.000Z</updated>
    <published>2015-08-05T16:29:14.000Z</published>
    <content type="html"><![CDATA[<h3><p>Guides</p>
</h3>
<ul>
<li><a href="https://github.com/andrewmichaelsmith/honeypot-setup-script/" rel="noopener noreferrer">Honeypot (Dionaea and kippo) setup script (⭐84)</a></li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2015/32/"/>
    <summary>1 awesome projects updated on Aug 10 - Aug 16, 2015</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2015/27/</id>
    <title>Awesome Honeypots Updates on Jul 06 - Jul 12, 2015</title>
    <updated>2015-07-03T18:13:47.000Z</updated>
    <published>2015-07-03T18:13:47.000Z</published>
    <content type="html"><![CDATA[<h3><p>Guides</p>
</h3>
<ul>
<li><a href="https://dtag-dev-sec.github.io/mediator/feature/2015/03/17/concept.html" rel="noopener noreferrer">T-Pot: A Multi-Honeypot Platform</a></li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2015/27/"/>
    <summary>1 awesome projects updated on Jul 06 - Jul 12, 2015</summary>
  </entry>
</feed>