HoneyDB operates its own global honeypot network. Every scan, brute-force and exploit attempt against it becomes queryable context — so an IP hitting your customer’s edge today already has years of behavioural history behind it.
Watch every client’s address space at once, triage alerts against original sensor data, and cut the false positives eating your analysts’ shift.
Jump to the MSSP track → Track 02One REST call returns the full picture on an IP — network, reputation and observed behaviour — so your agent reasons over evidence instead of chaining six tools.
Jump to the AI SOC track →This is a real HoneyDB response. Six public and commercial reputation feeds return nothing on this address — no SANS, no CI Army, no ThreatFox. It isn’t Tor, isn’t a bogon, isn’t a known internet scanner.
And yet it has been hammering SSH across our honeypot network since April 2019. That gap — between “not on a list” and “we have watched it attack for six years” — is the reason to carry original sensor data.
Aggregated feeds tell you what someone else already published. A sensor network tells you what is actually happening right now, to infrastructure you control.
You are accountable for dozens of networks you don’t own. HoneyDB gives you a single source of attacker behaviour that applies across all of them — and tells you when one of your clients starts showing up in it.
Attackers sweep the internet in waves. Infrastructure that probes our honeypots today is often the same infrastructure that reaches your client’s edge tomorrow — giving you a window to block ahead of the attempt rather than after the alert.
The triage question that eats a shift. Instead of a reputation score with no provenance, your analyst sees what the address actually did: which services it attacked, how often, and for how long.
Behavioural evidence closes noisy alerts faster and with more confidence than a list membership. An address with no history is genuinely different from one with six years of brute-force behind it — and your queue should treat them differently.
Add each client’s ranges and assets as Monitors. If any of them appears anywhere in the honeypot network — a sign of compromise or an outbound scan — you get alerted before your customer notices.
Autonomous triage is only as good as the evidence it can reach. HoneyDB returns network, reputation and observed-behaviour context for an address in a single deterministic JSON response — a clean tool definition your agent can call, cite and reason over.
An unfamiliar source address trips a detection. The agent has an IP and nothing else to go on.
One request returns identity, reputation and years of first-hand behaviour — enough to separate a noisy neighbour from a persistent attacker.
The agent escalates or closes, and cites concrete observations — event counts, services and dates — instead of an opaque score.
Serving your own customers with HoneyDB intelligence — inside a portal, a product or an agent — falls under our Commercial / OEM license. Enterprise tiers cover defending your own infrastructure; OEM covers redistribution and resale.
Original honeypot telemetry, one endpoint, licensed for the way you actually use it.