SSH Honeypot Intelligence

HoneySEC

Open blacklist intelligence from distributed honeypot telemetry, designed for operators who need a clean corporate-grade security feed.

Research-grade threat intelligence with direct operational value.

HoneySEC is a research-driven project focused on improving network security through real-world data collected from multiple honeypots. Each honeypot monitors unauthorized login attempts and gathers the IP addresses of potential attackers across diverse regions and networks.

Provide administrators with simple, effective tools to block malicious traffic and strengthen infrastructure security without unnecessary complexity.

Transform observed attack activity into actionable datasets that can be consumed by firewalls, network controls, and analytical workflows.

HoneySEC was developed within a PhD research project exploring practical uses of honeypot data in automated threat mitigation and hardening.

Why the project exists

HoneySEC aims to make proactive defense more accessible, whether the user is protecting a home lab, a managed firewall stack, or enterprise perimeter infrastructure. The project stays intentionally transparent: the value is in a clean public blacklist derived from observed hostile behavior.

The design goal is not to overwhelm teams with telemetry. It is to deliver a dependable, production-friendly source of malicious IP indicators that can be applied quickly and reviewed easily.