Beelzebub

Beelzebub

Low-code honeypot framework using LLMs for safe system deception

1.8kstars
168forks
Last commit: 2d ago
Repo age: 4y old
Beelzebub screenshot

Beelzebub is a secure, low-code honeypot framework designed to detect and analyze real attacker activity through deception. It uses large language models to simulate realistic, high-interaction behavior while keeping the underlying architecture safer and easier to operate.

Key Features

  • YAML-based low-code configuration for defining decoy services and behaviors
  • LLM-backed “high-interaction” simulation for realistic SSH and service responses
  • Multi-protocol support including SSH, HTTP, raw TCP, and MCP-style tool honeypots
  • Designed to reduce false positives by alerting only on interaction with decoys
  • Prometheus metrics for observability and operational monitoring
  • Container- and Kubernetes-friendly deployment (Docker Compose and Helm)

Use Cases

  • Detect lateral movement and hands-on-keyboard activity inside networks using decoys
  • Capture real attacker commands, payloads, and tactics for threat analysis and research
  • Protect AI agent environments by deploying MCP/tool decoys to detect prompt-injection-driven tool abuse

Limitations and Considerations

  • Realism and interaction quality depend on the chosen LLM provider/model and prompt design
  • Operating internet-exposed honeypots requires careful isolation, logging, and incident processes

Beelzebub is well-suited for security teams and researchers who want flexible, cloud-native deception with minimal configuration overhead. It provides a practical way to observe attacker behavior and generate actionable telemetry without running fully vulnerable systems.

Categories:

Tags:

Tech Stack:

Share:

Similar Services

Web-Check

Web-Check

All-in-one OSINT tool for analyzing any website.

30k
2.4k
Last commit: 4d ago

Comprehensive on-demand OSINT to analyze a website's security, architecture, and tech stack.

Alternative to:
Shodan
Shodan
+8
SafeLine

SafeLine

Self-hosted WAF and reverse proxy for securing web apps

20.1k
1.3k
Last commit: 2mo ago

SafeLine is a self-hosted Web Application Firewall (WAF) and reverse proxy that defends web apps from SQL injection, XSS, bot abuse, and DDoS using ML-powered threat dete...

Alternative to:
Cloudflare Web Application Firewall (WAF)
Cloudflare Web Application Firewall (WAF)
+7
Fail2Ban

Fail2Ban

Log-monitoring daemon that bans abusive IPs via firewall rules

16.6k
1.4k
Last commit: 15d ago

Fail2Ban monitors service logs for repeated failures and automatically bans abusive IP addresses by updating firewall rules for a configurable time.

Alternative to:
CrowdSec
CrowdSec
CrowdSec

CrowdSec

Crowdsourced IDS/IPS and WAF with shared malicious IP intelligence

12.2k
567
Last commit: 18h ago

CrowdSec is an open-source security engine that detects attacks from logs and blocks malicious IPs using bouncers and community-curated threat intelligence.

Alternative to:
Fail2Ban
Fail2Ban
+10
Graylog

Graylog

Centralized log management and analysis platform

7.9k
1.1k
Last commit: 1d ago

Graylog is an open source platform for collecting, indexing, searching, and alerting on logs and machine data from many sources in one place.

Alternative to:
Graylog Cloud
Graylog Cloud
+11
OneUptime

OneUptime

Open-source monitoring, incident management, and observability platform

6.4k
307
Last commit: 20h ago

Self-hostable observability platform for uptime monitoring, alerting, incident management, on-call, status pages, logs, and APM in one integrated suite.

Alternative to:
OneUptime
OneUptime
+19