Beelzebub logo

Beelzebub

Website

Low-code honeypot framework using LLMs for safe system deception

2.1k stars 203 forks last commit first released GPL-3.0

Actively maintained

Last commit 24 Jul 2026.

Beelzebub screenshot

Beelzebub is a secure, low-code honeypot framework designed to detect and analyze real attacker activity through deception. It uses large language models to simulate realistic, high-interaction behavior while keeping the underlying architecture safer and easier to operate.

Key Features

  • YAML-based low-code configuration for defining decoy services and behaviors
  • LLM-backed “high-interaction” simulation for realistic SSH and service responses
  • Multi-protocol support including SSH, HTTP, raw TCP, and MCP-style tool honeypots
  • Designed to reduce false positives by alerting only on interaction with decoys
  • Prometheus metrics for observability and operational monitoring
  • Container- and Kubernetes-friendly deployment (Docker Compose and Helm)

Use Cases

  • Detect lateral movement and hands-on-keyboard activity inside networks using decoys
  • Capture real attacker commands, payloads, and tactics for threat analysis and research
  • Protect AI agent environments by deploying MCP/tool decoys to detect prompt-injection-driven tool abuse

Limitations and Considerations

  • Realism and interaction quality depend on the chosen LLM provider/model and prompt design
  • Operating internet-exposed honeypots requires careful isolation, logging, and incident processes

Beelzebub is well-suited for security teams and researchers who want flexible, cloud-native deception with minimal configuration overhead. It provides a practical way to observe attacker behavior and generate actionable telemetry without running fully vulnerable systems.

Categories:

Tags:

Tech Stack:

Share:

Similar to Beelzebub

VictoriaMetrics logo

VictoriaMetrics

High-performance time series database for monitoring and observability

17.4k
1.7k
Last commit

Fast, resource-efficient time series database compatible with Prometheus and Grafana, for scalable monitoring and long-term metrics storage.

Apache-2.0Actively maintained
Alternative to:
Grafana Cloud logo
Grafana Cloud
+9
CrowdSec logo

CrowdSec

Crowdsourced IDS/IPS and WAF with shared malicious IP intelligence

14.3k
688
Last commit

CrowdSec is an open-source security engine that detects attacks from logs and blocks malicious IPs using bouncers and community-curated threat intelligence.

MITActively maintained
Alternative to:
Fail2Ban logo
Fail2Ban
+10
Kite logo

Kite

Modern, lightweight Kubernetes dashboard

2.9k
281
Last commit

Kite is a modern Kubernetes dashboard for multi-cluster management, resource operations, and Prometheus-powered monitoring with logs, terminal access, and live YAML editing.

Apache-2.0Actively maintained
Alternative to:
Portainer Business Edition (Portainer Cloud) logo
Portainer Business Edition (Portainer Cloud)
+4
SIP3 logo

SIP3

SIP and VoIP QoS monitoring with call flow analytics

Self-hosted platform for capturing SIP/RTP traffic, analyzing call flows, and monitoring VoIP quality metrics with dashboards and alerts.

Activity unknown
Alternative to:
VoIPmonitor Cloud logo
VoIPmonitor Cloud
+4
Grafana logo

Grafana

Observability dashboards and alerting for metrics, logs, and traces

75.8k
14.4k
Last commit

Grafana is an open source observability and data visualization platform for querying, graphing, and alerting on metrics, logs, and traces across many data sources.

AGPL-3.0Actively maintained
Alternative to:
Grafana Cloud logo
Grafana Cloud
+19
Grafana Loki logo

Grafana Loki

Horizontally scalable, multi-tenant log aggregation system

28.6k
4.1k
Last commit

Grafana Loki is a Prometheus-inspired log aggregation system that indexes labels (not log contents) for cost-effective storage and fast querying, with Grafana integration.

AGPL-3.0Actively maintained
Alternative to:
Datadog Log Management logo
Datadog Log Management
+19