HoneyDB runs a global network of honeypots and turns every probe, scan and exploit into structured threat intel — queryable from a simple /api endpoint.
Deploy a honeypot in minutes, or just consume the feed. Either way you tap the same enriched stream of attacker IPs, services and payloads.
Drop the lightweight HoneyDB Agent on any host. It impersonates SSH, RDP, HTTP, VNC and dozens of other services to lure and log attackers.
Every connection is captured, geolocated and classified — source, country, protocol and the service being targeted.
Pull bad hosts, trending services and the full event stream as JSON. Block, enrich or alert — wire it into whatever you already run.
A single binary turns any spare host into a multi-service honeypot. Your captures feed your private dashboard and the community feed you query.
Add hosts, CIDR ranges or asset names to a watchlist. If they appear anywhere in the honeypot network, HoneyDB alerts you — early warning that something is compromised or scanning.
Community is free for internal, non-commercial use. Enterprise tiers scale query volume and bundled Monitors for defending your own infrastructure. Embedding or redistributing HoneyDB data in a product? That’s Commercial / OEM.
Individual practitioners, researchers and in-house defenders using the data internally. Non-commercial use only.
Internal use only — monthly or annual billing.
Small teams defending their own systems. $490/year billed annually.
Teams needing higher query capacity. $990/year billed annually.
Internal use above 500,000 queries per month.
For vendors, MSSPs and SaaS platforms embedding or redistributing HoneyDB data. Annual licensing. Running an MSSP or building an AI SOC product? See how teams use HoneyDB.
Embed HoneyDB data in your product or service under a commercial license.
For higher volumes and SLA-backed, dedicated support — a step up from Commercial Silver.
Already subscribed? Manage your subscription — change plan, update card, or cancel.
All plans: geo, netinfo, ASN prefixes, CIDR expansion, and third-party threat list lookups don’t count toward your quota.
Not sure which plan applies? Contact us and we’ll guide you.
Grab an API key, drop in a curl, and you’re pulling live attacker intel in under five minutes.