Projects

This page contains a list of tools and services that we use on a regular basis. Most of these tools have been created by our members and GSoC students, but some are also external and not affiliated with the Honeynet Project. If you see that a specific tool is not listed, but should, feel free to email [email protected]. Projects are sorted by last commit date.

Active Projects

DRAKVUF

Black-box Binary Analysis

introspection malware-analysis virtualization xen

mitmproxy

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Website GitHub 40.1k Python MIT
debugging http http2 man-in-the-middle mitmproxy proxy python security ssl tls websocket

thug

Python low-interaction honeyclient

GitHub 1017 Python GPL-2.0
client-honeypot honeyclient low-interaction python security-tools shellcode virustotal

BuffaLogs

an Open Source Django App whose main purpose is to detect login anomalies

GitHub 47 Python

T-Pot

The All In One Multi Honeypot Platform ๐Ÿ

GitHub 8152 C GPL-3.0
deception docker elk honeypot network-security security t-pot

Intel Owl

IntelOwl: manage your Threat Intelligence at scale

Website GitHub 4230 Python AGPL-3.0
cyber-security cyber-threat-intelligence cybersecurity dfir enrichment hacktoberfest honeynet incident-response intel-owl ioc malware-analysis malware-analyzer osint osint-python python

GreedyBear

Threat Intel Platform for T-POTs

GitHub 159 Python MIT
cyber-threat-intelligence cybersecurity hacktoberfest honeypot ioc open-source python threat-intelligence threatintel tpot

Glutton

Generic Low Interaction Honeypot

GitHub 283 Go MIT
hacktoberfest honeypot

ochi

Website GitHub 32 Go GPL-3.0
honeypot visualization

PcapMonkey

will provide an easy way to analyze pcap using the latest version of Suricata and Zeek.

GitHub 156 Zeek

Conpot

ICS/SCADA honeypot

GitHub 1367 Python GPL-2.0
hacktoberfest honeypot ics python scada security

honeyscanner

A vulnerability analyzer for honeypots

Website GitHub 46 Python MIT
cybersecurity cybersecurity-assessments dos-attack exploitation fuzzing honeypots passive-vulnerability-scanner ssh-honeypot vulnerability-scanner

TANNER

He who flays the hide

GitHub 228 Python GPL-3.0
honeypot security

DroidBot

A lightweight test input generator for Android. Similar to Monkey, but with more intelligence and cool features!

GitHub 895 Python MIT

Old Projects

dionaea

Home of the dionaea honeypot

Website GitHub 759 Python GPL-2.0
dionaea honeypot security

Glastopf

Web Application Honeypot

SNARE

Super Next generation Advanced Reactive honEypot

Website GitHub 467 Python GPL-3.0
hacktoberfest honeypot security

WhisperPot

VoIP honeypot system

GitHub 20 Python MIT
honeypot voip

RIoTPot

the IoT and OT (Operational Technology) Honeypot

GitHub 25 Go MIT

Kippo

SSH Honeypot

GitHub 1699 Python

Droidbox

Dynamic analysis of Android apps

GitHub 783 Python

cuckoo

Sandbox is an automated dynamic malware analysis system

Website GitHub 5767 JavaScript

dockpot

GitHub 52 Python

Google Hack Honeypot

Google Hack Honeypot

GitHub 7 PHP GPL-2.0
honeypot security

Honeytrap

a low-interaction honeypot

GitHub 94 C GPL-2.0

GVol

GitHub 20 Java MIT

Capture-HPC

A high interaction client honeypot

Capture BAT

a behavioral analysis tool of applications for the Win32 operating system family.

GitHub 32 C++ GPL-2.0

honeysnap

GitHub 13 Python

honeyc

GitHub 8 Ruby

HFlow2

GitHub 5 C++ GPL-2.0

APKinspector

a powerful GUI tool for analysts to analyze the Android applications.

GitHub 846 Java

HoneyBow

A high-interaction malware collection toolkit

Honeyd

A low-interaction honeypot

Honeystick

A portable honeynet demonstration and incident response tool

Latest Activity

drona-gyawali opened a pull request in certego/BuffaLogs. ยท at August 9, 2025
16 additions and 33 deletions in 2 changed files.
tklengyel pushed to tklengyel/drakvuf ยท at August 8, 2025
1 commit to tklengyel/drakvuf
a7db19a Fix: changed make_hook_id to not overwrite return hook when apicall was nested โ€ฆ
psrok1 opened a pull request in tklengyel/drakvuf. ยท at August 8, 2025
errorxyz opened a pull request in mitmproxy/mitmproxy. ยท at August 8, 2025
2 additions and 6 deletions in 1 changed files.
faux-eccles opened a pull request in intelowlproject/IntelOwl. ยท at August 8, 2025
1 additions and 1 deletions in 1 changed files.
buffer pushed to buffer/thug ยท at August 7, 2025
2 commits to buffer/thug
8cd7989 Update requirements: Bump pymongo from 4.13.2 to 4.14.0 051d3a2 Merge pull request #416 from buffer/dependabot/pip/pymongo-4.14.0
Lorygold pushed to certego/BuffaLogs ยท at August 7, 2025
1 commit to certego/BuffaLogs
efa1034 Refactor Ingestions tests for performance and fixed Opensearch data structure in โ€ฆ
t3chn0m4g3 pushed to telekom-security/tpotce ยท at August 7, 2025
0be973b Bump Elastic Stack to 8.18.4
t3chn0m4g3 pushed to telekom-security/tpotce ยท at August 6, 2025
443a9d1 Update and pin Glutton to latest master
pranjalg1331 pushed to intelowlproject/IntelOwl ยท at August 6, 2025
fe729a2 no changes to pr automation
sujaldev opened a pull request in mitmproxy/mitmproxy. ยท at August 6, 2025
7 additions and 0 deletions in 1 changed files.
mlodic pushed to intelowlproject/GreedyBear ยท at July 18, 2025
4e955e8 added filter for whatsmyip domains (#557)
mlodic pushed to intelowlproject/GreedyBear ยท at July 18, 2025
b644cda added migration file and admin