
Ein sicheres Low-Code-Deception-Runtime-Framework, das KI für die Systemvirtualisierung nutzt.
Deception-Laufzeit-Framework
Beelzebub ist eine Open-Source-Deception-Laufzeitumgebung, die adaptive, auf LLM basierende Täuschungsdienste über SSH-, HTTP-, TCP-, TELNET- und MCP-Protokolle bereitstellt. Sie geht über passive Honeypots hinaus, indem sie Angreifer aktiv in realistische Interaktionen verwickelt, hochwertige Threat Intelligence sammelt und Prompt-Injection-Angriffe auf KI-Agenten erkennt.

CommandPlugin- oder HTTPPlugin-Interface und registrieren Sie es über init() keine Kernänderungen erforderlich.
./install.sh # asks local or Docker, checks prerequisites, and starts it
Nicht-interaktiv: `./install.sh --local` oder `./install.sh --docker`. Verwenden Sie `./install.sh --local --no-run`, um zu installieren und zu bauen, ohne die lokale Laufzeit zu starten. Auf Nicht-Root-Hosts startet die lokale Installation nicht automatisch, wenn die Standardkonfiguration privilegierte Ports enthält.
### Lokal (Go)```bash
make start # installs any declared plugins, compiles them in, and runs
make docker # builds an image with declared plugins baked in, then runs it
### Helm verwenden (Kubernetes)```bash
helm install beelzebub ./beelzebub-chart
# Upgrade:
helm upgrade beelzebub ./beelzebub-chart
Beelzebub wird mit einer strukturierten CLI ausgeliefert. Führen Sie beelzebub --help aus, um alle verfügbaren Befehle anzuzeigen.
beelzebub runStartet alle konfigurierten Täuschungsdienste.```bash beelzebub run [flags]
Flags: -c, --conf-core string Path to core configuration file (default "./configurations/beelzebub.yaml") -s, --conf-services string Path to services configuration directory (default "./configurations/services/") -m, --mem-limit-mib int Memory limit in MiB, -1 to disable (default 100)
### `beelzebub validate`
Parst und validiert alle Konfigurationsdateien, ohne Dienste zu starten. Nützlich in CI-Pipelines. Siehe [Konfigurationsvalidierung](https://github.com/beelzebub-labs/beelzebub/blob/main/docs/configuration-validation.md) für die Validierungsarchitektur und die Regelreferenz.```bash
beelzebub validate --conf-core ./configurations/beelzebub.yaml --conf-services ./configurations/services/
beelzebub pluginInstallieren, auflisten und entfernen von Plugins, die von GitHub abgerufen werden. Siehe Plugin-System.```bash beelzebub plugin install github.com/your-org/beelzebub-myplugin beelzebub plugin list beelzebub plugin remove myplugin
### `beelzebub version`
Gibt Version, Commit-SHA, Build-Datum und Go-Runtime-Informationen aus.```bash
beelzebub version
Beelzebub stellt ein stabiles öffentliches SDK unter pkg/plugin bereit, um die Deception-Laufzeitumgebung zu erweitern, ohne den Kerncode zu modifizieren.
// CommandPlugin generates text responses for SSH, TCP, TELNET, and HTTP services. type CommandPlugin interface { Metadata() Metadata Execute(ctx context.Context, req CommandRequest) (string, error) }
// HTTPPlugin generates full HTTP responses with status code, headers, and body. type HTTPPlugin interface { Metadata() Metadata HandleHTTP(r *http.Request) HTTPResponse }
### Ein Plugin schreiben```go
package myplugin
import (
"context"
"github.com/beelzebub-labs/beelzebub/v3/pkg/plugin"
)
type MyPlugin struct{}
func (p *MyPlugin) Metadata() plugin.Metadata {
return plugin.Metadata{
Name: "MyPlugin",
Description: "Custom deception response generator",
Version: "1.0.0",
Author: "your-name",
}
}
func (p *MyPlugin) Execute(_ context.Context, req plugin.CommandRequest) (string, error) {
return "simulated response to: " + req.Command, nil
}
func init() {
plugin.Register(&MyPlugin{})
}
beelzebub plugin install github.com/your-org/myplugin # also appends to the config