SSH Honeypot Intelligence

HoneySEC

Open blacklist intelligence from distributed honeypot telemetry, designed for operators who need a clean corporate-grade security feed.

Operational blacklist intelligence for enterprise perimeter defense.

HoneySEC aggregates IP addresses observed across distributed honeypots and publishes them as immediately consumable blocklists for security teams, labs, and managed environments.

Choose your feed output

Select a format to copy the production URL directly to the clipboard.

HoneySEC hosts and publishes an aggregated blacklist of IP addresses gathered from a distributed network of honeypots. We collect only raw source IP data from login and connection attempts attracted to decoy nodes, then consolidate those IPs into a simple public feed for blocking and research use.

The objective is direct: give administrators and security teams a lightweight way to block repeat offenders, reduce log noise, and harden perimeter controls without complex telemetry pipelines or expensive enrichment dependencies.