# beelzebub-labs/beelzebub

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Repository: https://github.com/beelzebub-labs/beelzebub
Canonical: https://ross.abutalabs.com/products/beelzebub
Homepage: https://docs.beelzebub.ai
Language: Go
License: GPL-3.0
License Family: copyleft
Topics: cybersecurity, security, honeypot, framework, go, research-project, whitehat, cloudnative, cloudsecurity, llm, llm-security, llm-honeypot, deception, llama, mcp, mcp-honeypot, decoys, agentic-ai-security, acis, preemptive-cybersecurity
Last push: 2026-08-24T06:41:15+00:00

## Health v2 (maintenance only)
Score: 98/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 96, longevity 100
- inputs: {"age_days": 1578, "days_push": 9, "days_rel": 28, "gap_med": 15, "n_releases_24m": 42}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2165, forks 206 (observed 2026-08-28T04:06:21.268833+00:00)

## What it is
Beelzebub is an open-source deception runtime framework written in Go that deploys adaptive, LLM-powered honeypot decoy services across SSH, HTTP, TCP, TELNET, and MCP protocols. It engages attackers in realistic interactions to collect threat intelligence and detect prompt injection attacks against AI agents, with YAML-based configuration and a plugin system.

## Use cases
- deploy an SSH honeypot to detect brute-force attacks
- run an LLM-powered honeypot that simulates a realistic Linux terminal
- detect prompt injection attacks against AI agents and MCP servers
- collect threat intelligence from attackers in a Kubernetes cluster
- set up low-code deception decoys across HTTP, TCP, and TELNET protocols
- monitor honeypot events with Prometheus metrics and RabbitMQ
- simulate vulnerable services to study attacker behavior

## When to choose
- you want a low-code, YAML-configured honeypot framework with multi-protocol support
- you need LLM-driven high-fidelity attacker interaction without a fully compromised system
- you want to secure Kubernetes environments against lateral movement with deception
- you need to detect and study prompt injection attacks on AI infrastructure

## When to avoid
- you need a production firewall, IDS, or endpoint protection rather than deception technology
- you cannot expose decoy services on your network or lack the resources to monitor them
- you want a fully high-interaction honeypot with real OS virtualization
- you require a license more permissive than GPL-3.0

## Facets
- artifact type: framework
- maturity: active
- function: security, monitoring, logging, plugin-system, llm-inference, mcp
- domain: security, artificial-intelligence, large-language-models, self-hosted, cloud-computing
- platform: go, self-hosted, cloud
- tags: honeypot, deception-technology, threat-intelligence, prompt-injection-detection, decoy-services, ssh-honeypot, http-honeypot, mcp-honeypot, llm-security, yaml-configuration, prometheus-metrics, rabbitmq, linux, docker, kubernetes

## Member repositories
- beelzebub-labs/beelzebub (main) score 98

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:21.268833+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:49:59.149683+00:00, confidence not recorded.
  - readme: https://github.com/beelzebub-labs/beelzebub (fetched 2026-08-28T04:06:21.268833+00:00, sha 098a8a9a22ab)
  - homepage: https://docs.beelzebub.ai (fetched 2026-08-29T10:29:50.651025+00:00, sha 7aec4faa7de1)
  - site_page: https://docs.beelzebub.ai/getting-started/quickstart (fetched 2026-08-29T10:29:50.660150+00:00, sha a82669a18a9c)
  - site_page: https://docs.beelzebub.ai/basics/integrations (fetched 2026-08-29T10:29:50.662080+00:00, sha ec10bb0f26e2)
  - site_page: https://docs.beelzebub.ai/basics/publish-your-docs (fetched 2026-08-29T10:29:50.664112+00:00, sha 551f186c9dd9)
- Data as of 2026-08-30T08:39:29.467469+00:00.
