Well, hello there

Hey there, data fan! 👋

We see you're interested in HoneyDB's honeypot data — that's fantastic, we love it.

You have great taste in threat intelligence

It looks like you (or your script) have been gathering data from HoneyDB's public pages. We get it — HoneyDB's real-time honeypot threat intelligence is genuinely useful stuff: live attacker activity, bad hosts, payloads, and session data collected from a global network of honeypots, updated continuously.

Here's the good news: there's a much better way to get this data than scraping HTML.

  • The HoneyDB API — structured, real-time access to honeypot threat data, with plans for every use case:
    • Community — free for individual practitioners and researchers using the data internally.
    • Enterprise (Bronze, Silver, Gold) — for organizations defending their own infrastructure, with higher query volumes and HoneyDB Monitors included.
    • Commercial / OEM — for vendors embedding or redistributing HoneyDB data in commercial products and services.
  • HoneyDB Monitors — get alerted when your IP addresses, ranges, ASNs, or brand terms trigger activity on HoneyDB's global honeypot network.

The API gives you clean JSON, documented endpoints, and query volumes that scale with your needs — no parsing, no guesswork, and data you can actually build on.

One small ask: automated scraping of the HoneyDB website is against our Terms of Service. The API is faster, friendlier, and built for exactly what you're trying to do — we'd love to have you on board.

Get the data the right way

Pick a plan, grab an API key, and start pulling structured threat data in minutes.

See Subscription Plans → Start free with Community

Building a product with HoneyDB data? Contact us about commercial licensing.