
Beelzebub
Low-code honeypot framework using LLMs for safe system deception

Beelzebub is a secure, low-code honeypot framework designed to detect and analyze real attacker activity through deception. It uses large language models to simulate realistic, high-interaction behavior while keeping the underlying architecture safer and easier to operate.
Key Features
- YAML-based low-code configuration for defining decoy services and behaviors
- LLM-backed “high-interaction” simulation for realistic SSH and service responses
- Multi-protocol support including SSH, HTTP, raw TCP, and MCP-style tool honeypots
- Designed to reduce false positives by alerting only on interaction with decoys
- Prometheus metrics for observability and operational monitoring
- Container- and Kubernetes-friendly deployment (Docker Compose and Helm)
Use Cases
- Detect lateral movement and hands-on-keyboard activity inside networks using decoys
- Capture real attacker commands, payloads, and tactics for threat analysis and research
- Protect AI agent environments by deploying MCP/tool decoys to detect prompt-injection-driven tool abuse
Limitations and Considerations
- Realism and interaction quality depend on the chosen LLM provider/model and prompt design
- Operating internet-exposed honeypots requires careful isolation, logging, and incident processes
Beelzebub is well-suited for security teams and researchers who want flexible, cloud-native deception with minimal configuration overhead. It provides a practical way to observe attacker behavior and generate actionable telemetry without running fully vulnerable systems.
Categories:
Tags:
Tech Stack:
Similar Services
Web-Check
All-in-one OSINT tool for analyzing any website.
Comprehensive on-demand OSINT to analyze a website's security, architecture, and tech stack.

SafeLine
Self-hosted WAF and reverse proxy for securing web apps
SafeLine is a self-hosted Web Application Firewall (WAF) and reverse proxy that defends web apps from SQL injection, XSS, bot abuse, and DDoS using ML-powered threat dete...

Fail2Ban
Log-monitoring daemon that bans abusive IPs via firewall rules
Fail2Ban monitors service logs for repeated failures and automatically bans abusive IP addresses by updating firewall rules for a configurable time.
CrowdSec
Crowdsourced IDS/IPS and WAF with shared malicious IP intelligence
CrowdSec is an open-source security engine that detects attacks from logs and blocks malicious IPs using bouncers and community-curated threat intelligence.

Graylog
Centralized log management and analysis platform
Graylog is an open source platform for collecting, indexing, searching, and alerting on logs and machine data from many sources in one place.

OneUptime
Open-source monitoring, incident management, and observability platform
Self-hostable observability platform for uptime monitoring, alerting, incident management, on-call, status pages, logs, and APM in one integrated suite.
Ollama
Go
Kubernetes
Docker