beelzebub-labs/beelzebub
A secure low code deception runtime framework, leveraging AI for System Virtualization. observed · 2026-08-28
Health v2 · maintenance only
98/100
- Activity 99
- Release rhythm 96
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 15
- age_days: 1578
- days_rel: 28
- days_push: 9
- n_releases_24m: 42
Adoption not part of the score
2165 stars · 206 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Beelzebub is an open-source deception runtime framework written in Go that deploys adaptive, LLM-powered honeypot decoy services across SSH, HTTP, TCP, TELNET, and MCP protocols. It engages attackers in realistic interactions to collect threat intelligence and detect prompt injection attacks against AI agents, with YAML-based configuration and a plugin system.
Use cases
- deploy an SSH honeypot to detect brute-force attacks
- run an LLM-powered honeypot that simulates a realistic Linux terminal
- detect prompt injection attacks against AI agents and MCP servers
- collect threat intelligence from attackers in a Kubernetes cluster
- set up low-code deception decoys across HTTP, TCP, and TELNET protocols
- monitor honeypot events with Prometheus metrics and RabbitMQ
- simulate vulnerable services to study attacker behavior
When to choose
- you want a low-code, YAML-configured honeypot framework with multi-protocol support
- you need LLM-driven high-fidelity attacker interaction without a fully compromised system
- you want to secure Kubernetes environments against lateral movement with deception
- you need to detect and study prompt injection attacks on AI infrastructure
When to avoid
- you need a production firewall, IDS, or endpoint protection rather than deception technology
- you cannot expose decoy services on your network or lack the resources to monitor them
- you want a fully high-interaction honeypot with real OS virtualization
- you require a license more permissive than GPL-3.0
Facets
framework · maturity active
security monitoring logging plugin-system llm-inference mcp security artificial-intelligence large-language-models self-hosted cloud-computing go self-hosted cloud honeypot deception-technology threat-intelligence prompt-injection-detection decoy-services ssh-honeypot http-honeypot mcp-honeypot llm-security yaml-configuration prometheus-metrics rabbitmq linux docker kubernetes
5 sources
- readme: https://github.com/beelzebub-labs/beelzebub · fetched 2026-08-28 · 098a8a9a22ab
- homepage: https://docs.beelzebub.ai · fetched 2026-08-29 · 7aec4faa7de1
- site_page: https://docs.beelzebub.ai/getting-started/quickstart · fetched 2026-08-29 · a82669a18a9c
- site_page: https://docs.beelzebub.ai/basics/integrations · fetched 2026-08-29 · ec10bb0f26e2
- site_page: https://docs.beelzebub.ai/basics/publish-your-docs · fetched 2026-08-29 · 551f186c9dd9
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| beelzebub-labs/beelzebub | main | 98 |
For agents
markdown · JSON · MCP: product_card(name="beelzebub-labs/beelzebub")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem