# honeytrap/honeytrap

Advanced Honeypot framework.

Repository: https://github.com/honeytrap/honeytrap
Canonical: https://ross.abutalabs.com/products/honeytrap
Homepage: https://docs.honeytrap.io/
Language: Go
License: NOASSERTION
License Family: other
Topics: honeypot, framework, security
Last push: 2023-10-09T08:33:27+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 3493, "days_push": 1059, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1307, forks 182 (observed 2026-08-28T04:04:19.083167+00:00)

## What it is
Honeytrap is an extensible open-source honeypot framework written in Go for running, monitoring, and managing honeypots. It supports low- to high-interaction honeypots, centralized agent management, payload-based protocol detection, and logging to destinations like Elasticsearch, Kafka, and Splunk.

## Use cases
- deploy honeypots to detect attackers on my network
- run multiple fake services on one honeypot
- centralize logging from many honeypot agents
- monitor lateral movement inside my network
- capture payloads on a single port across multiple protocols
- proxy traffic to high-interaction honeypot backends
- integrate existing honeypots like cowrie into one framework

## When to choose
- you need a flexible, extensible honeypot framework with centralized agent management
- you want low- to high-interaction honeypots with seamless connection upgrades
- you need advanced logging pipelines to Elasticsearch, Kafka, Splunk, or Slack

## When to avoid
- you need a simple single-service honeypot with minimal setup
- you require actively maintained software with frequent releases
- you need a GUI-driven honeypot management solution

## Facets
- artifact type: framework
- maturity: maintenance
- function: security, monitoring, logging, networking
- domain: security, networking, self-hosted, developer-tools
- platform: go, cross-platform
- tags: honeypot, intrusion-detection, threat-intelligence, deception, agent-server-architecture, linux, docker

## Member repositories
- honeytrap/honeytrap (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:19.083167+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:50:09.135309+00:00, confidence not recorded.
  - readme: https://github.com/honeytrap/honeytrap (fetched 2026-08-28T04:04:19.083167+00:00, sha d9ceb2e744b1)
  - homepage: https://docs.honeytrap.io/ (fetched 2026-08-29T12:08:33.990155+00:00, sha 67a753fb10bb)
- Data as of 2026-08-30T08:39:29.467469+00:00.
