Threat Intelligence tools identify potential attackers by deploying decoys and monitoring network activity. These tools use honeypots and deception frameworks to capture data on intrusion methods and unauthorized access attempts. Security analysts and network administrators use this type of software to gather evidence of breaches without risking production systems. Self-hosting these apps ensures that sensitive logs of attacker behavior and prompt injection attempts remain on private infrastructure. This approach allows you to customize deception services to match your specific network environment.
This page lists 2 open source tools in the Threat Intelligence category. The most popular are OpenCanary and Beelzebub. Most use the BSD-3-Clause or GPL-3.0 license, and 2 offer an official Docker image.
A multi-protocol network honeypot designed to detect intruders after they have breached non-public networks.
A deception runtime framework that deploys adaptive LLM-powered decoy services to collect threat intelligence.
Join our newsletter to get shiny new open source software delivered to your inbox. Unsubscribe anytime.