Back to updates
New releaseJul 27, 2026

SentryPeer v4.0.5

Distributed SIP honeypot that detects and shares fraud data on VoIP attacks. Collects bad actor IPs and phone numbers via peer-to-peer network, with REST API and WebHook integration for real-time threat intelligence.

Share

Protect your SIP Servers from bad actors

SentryPeer Logo

Stability: Active GitHub release (latest SemVer) Docker Hub Coverity Scan Build Status Build and Test CodeQL Clang Static Analysis CII Best Practices gitleaks

Special thanks to Deutsche Telekom Security GmbH for sponsoring us! Very kind!

Why not give us a star and follow us on Twitter!

Table of Contents

Introduction

SentryPeer® is a fraud detection tool. It lets bad actors try to make phone calls and saves the IP address they came from and number they tried to call. Those details can then be used to raise notifications at the service providers network and the next time a user/customer tries to call a collected number, you can act anyway you see fit.

For example:

Let's say you are running your own VoIP PBX on site. What SentryPeer will allow you to do in this context, is dip into the list of phone numbers (using the RESTful API) when your users are making outbound calls. If you get a hit, you'll get a heads-up that potentially a device within your network is trying to call known probing phone numbers that have either been:

  1. Numbers collected by SentryPeer nodes you are running yourself
  2. Numbers seen by other SentryPeer nodes which have been replicated to your node via the peer to peer network

This would allow you to generate a notification from your monitoring systems before you rack up any expensive calls or something worse happens.

What would lead to this scenario?

  1. Potential voicemail fraud. This can happen if you allow calling an inbound number (your DID/DDI) to get to your voicemail system, then prompt for a PIN. This PIN is weak and the voicemail system allows you to press '*' to call back the Caller ID that left a voicemail. The attacker has left a voicemail, and they then guess your PIN and call it back. The CLI is a known number that SentryPeer has seen. You can alert on it.
  2. A device has been hijacked and/or a softphone or similar is using the credentials they stole off the phone's GUI and is trying to register to your system and make calls to a number seen by SentryPeer.
  3. An innocent user is calling a phishing number or known expensive number etc. that SentryPeer has seen before.

Traditionally, this data is shipped to a central place, so you don't own the data you've collected. This project is all about Peer to Peer sharing of that data. The user owning the data and various Service Provider / Network Provider related feeds of the data is the key bit for me. I'm sick of all the services out there that keep it and sell it. If you've collected it, you should have the choice to keep it and/or opt in to share it with other SentryPeer community members via p2p methods.

Overview

SentryPeer Node

Here we are using Mermaid Sequence diagrams to show the flow of data from a SentryPeer node to SentryPeerHQ.

sequenceDiagram
    actor A as Attacker
    participant S as SentryPeer Node
    participant DS as Data Store
    participant W as WebHook <br/>Endpoint
    Note over DS: sqlite/json log/syslog <br/>(if enabled)
    Note over W: if enabled
    A->>S: SIP probe OPTIONS/REGISTER/etc
    S->>DS: Save event
    S->>W: Send event
    W->>S: 200 OK
    S->>A: 200 OK
    A->>S: INVITE sip:00046500729221@

SentryPeer Node to SentryPeerHQ

sequenceDiagram
    actor A as Attacker
    participant S as SentryPeer Node
    participant DS as Data Store
    participant HQ as SentryPeerHQ
    Note over DS: sqlite/json log/syslog (if enabled)
    Note over HQ: OAuth2 creds required.<br/> if using https://sentrypeer.com
    A->>S: SIP probe OPTIONS/REGISTER/etc
    S->>DS: Save event
    S->>HQ: Send event
    HQ->>S: 201 Created
    S->>A: 200 OK
    A->>S: INVITE sip:00046500729221@

Using the SentryPeer Node and SentryPeerHQ API

sequenceDiagram
    Actor U as User
    participant S as SentryPeer Node/HQ API
    Note over S: if enabled
    U->>S: GET /numbers
    S->>U: 200 OK Return all Phone numbers seen in database

Integrating with your own systems

sequenceDiagram
    participant D as Device
    participant P as PBX/ITSP/Carrier
    participant HQ as SentryPeer Node/HQ API
    participant N as NOC
    Note over P: Integration with <br/>SentryPeer needed
    Note over N: Consumes alerts
    Note over HQ: OAuth2 creds required<br/> if using SentryPeerHQ
    Note over P,HQ: API rate limiting if using SentryPeerHQ
    D->>P: SIP INVITE
    P->>HQ: Have you seen attackers call this number?
    HQ->>P: Yes, this has been seen on SentryPeer Nodes
    HQ->>N: WebHook/Email/Slack
    Note over HQ,N: Only if using SentryPeerHQ
    P->>D: I'm blocking this call. Sorry

🚧 Features

Categories