beelzebub
Honeypot framework designed to provide a highly secure environment for detecting and analyzing cyber attacks.
Maintained, but at a slower pace than the leaders in its category.
Commit activity more than 29% of tracked projects; popularity more than 51%. How this is calculated.
Commits, last 11 months
| Stars | 2.2k |
|---|---|
| Latest release | v3.9.2 · 23 Sept 2026 |
| Repo updated | 25 Sept 2026 |
| Licence | MIT |
| Built with | Docker, K8S, Go |
Is beelzebub actively maintained?
Over the last 11 months the project absorbed 95 commits, of which 33 arrived in the most recent quarter — roughly 11 commits a month.
The most recent tagged release, v3.9.2, shipped within the last month — a current, installable version exists today.
Note that beelzebub depends on a third-party service to work fully. It is self-hosted, but not self-contained: if that external service changes its terms or disappears, your instance is affected.
beelzebub ranks #5 of 11 in Network Utilities, placing it mid-table for maintenance activity.
What beelzebub actually does
Beelzebub is a honeypot framework written in Go and distributed under an MIT licence. It provides a controlled environment to detect and analyse cyber attacks targeting your network infrastructure. The project is packaged for containerised environments and is typically managed using Docker or Kubernetes.
Best fit: Security engineers and system administrators who want to deploy a customisable honeypot to monitor unauthorised network access attempts.
Worth knowing: Operating a honeypot carries inherent security risks if the container isolation is compromised, and the framework's moderate maintenance level means you should audit updates carefully.
Deployment notes
You will typically run this service inside a container using Docker or Kubernetes, ensuring that network traffic is properly routed and isolated from critical infrastructure.
Links
beelzebub as a replacement for
Alternatives to beelzebub
Projects in the same categories, ordered by health score.
All in one IP Toolbox. Easy to check what's your IPs, IP geolocation, check for DNS leaks, examine WebRTC connections, speed test, ping test, MTR test, check website availability and more.
Network intruder and presence detector. Scans for devices connected to your network and alerts you if new and unknown devices are found.
Monitor the performance and uptime of your internet connection.
A simple Wake on LAN (WOL) dashboard app. Wake up devices on your network and see current status.
WHOIS/RDAP query API for domains, IP addresses, CIDR prefixes and ASNs, with unified JSON output, caching, API key authentication, batch queries and MCP support for AI assistants.
Generates lightweight, embedded honeypot triggers called canary tokens for detecting unauthorized access.