
Beelzebub
Low-code honeypot framework using LLMs for safe system deception
2.1k stars 203 forks last commit first released GPL-3.0
Actively maintained
Last commit 24 Jul 2026.

Beelzebub is a secure, low-code honeypot framework designed to detect and analyze real attacker activity through deception. It uses large language models to simulate realistic, high-interaction behavior while keeping the underlying architecture safer and easier to operate.
Key Features
- YAML-based low-code configuration for defining decoy services and behaviors
- LLM-backed “high-interaction” simulation for realistic SSH and service responses
- Multi-protocol support including SSH, HTTP, raw TCP, and MCP-style tool honeypots
- Designed to reduce false positives by alerting only on interaction with decoys
- Prometheus metrics for observability and operational monitoring
- Container- and Kubernetes-friendly deployment (Docker Compose and Helm)
Use Cases
- Detect lateral movement and hands-on-keyboard activity inside networks using decoys
- Capture real attacker commands, payloads, and tactics for threat analysis and research
- Protect AI agent environments by deploying MCP/tool decoys to detect prompt-injection-driven tool abuse
Limitations and Considerations
- Realism and interaction quality depend on the chosen LLM provider/model and prompt design
- Operating internet-exposed honeypots requires careful isolation, logging, and incident processes
Beelzebub is well-suited for security teams and researchers who want flexible, cloud-native deception with minimal configuration overhead. It provides a practical way to observe attacker behavior and generate actionable telemetry without running fully vulnerable systems.
Categories:
Tags:
Tech Stack:
Similar to Beelzebub

VictoriaMetrics
High-performance time series database for monitoring and observability
Fast, resource-efficient time series database compatible with Prometheus and Grafana, for scalable monitoring and long-term metrics storage.

CrowdSec
Crowdsourced IDS/IPS and WAF with shared malicious IP intelligence
CrowdSec is an open-source security engine that detects attacks from logs and blocks malicious IPs using bouncers and community-curated threat intelligence.
Kite
Modern, lightweight Kubernetes dashboard
Kite is a modern Kubernetes dashboard for multi-cluster management, resource operations, and Prometheus-powered monitoring with logs, terminal access, and live YAML editing.


SIP3
SIP and VoIP QoS monitoring with call flow analytics
Self-hosted platform for capturing SIP/RTP traffic, analyzing call flows, and monitoring VoIP quality metrics with dashboards and alerts.

Grafana
Observability dashboards and alerting for metrics, logs, and traces
Grafana is an open source observability and data visualization platform for querying, graphing, and alerting on metrics, logs, and traces across many data sources.


Grafana Loki
Horizontally scalable, multi-tenant log aggregation system
Grafana Loki is a Prometheus-inspired log aggregation system that indexes labels (not log contents) for cost-effective storage and fast querying, with Grafana integration.




