Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
IfritProxy — IFRIT is an AI-powered reverse proxy that intercepts incoming requests in real time, classifying each one as legitimate or malicious. Legitimate traffic is forwarded to backend; malicious traffic receives a customized AI-generated honeypot response that mimics the requested resource with fabricated data, deceiving attackers into wasting time on it. | Kitploit
Tools/GitHubGitHub/0tsystemspublicrepos/ifritproxy
Defensive ToolsReconnaissanceWeb Proxies & InterceptionIDS/IPS EvasionInformation GatheringWeb SecurityThreat IntelligenceIncident ResponseAI Security

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Log Analysis
GitHub0tsystemspublicrepos/ifritproxy

IfritProxy

View RepositoryWebsite
11748 months agoNot yet reviewed

About

IFRIT is an AI-powered reverse proxy that intercepts incoming requests in real time, classifying each one as legitimate or malicious. Legitimate traffic is forwarded to backend; malicious traffic receives a customized AI-generated honeypot response that mimics the requested resource with fabricated data, deceiving attackers into wasting time on it.

Share
IFRIT Logo

🔥 AI-Powered Threat Deception & Intelligence Platform

Turn attackers into intelligence sources with adaptive honeypot responses

License: Apache 2.0 Version Go Multi-LLM Database

📦 Quick Start • ✨ Features • 🔄 How It Works • 📚 Docs • 🔌 API


Brought to the community by

0t.systems

🎯 What is IFRIT?

IFRIT is an intelligent reverse proxy that sits between the internet and your applications, analyzing every request in real-time. Legitimate traffic flows through seamlessly. Malicious traffic? It gets served AI-generated honeypot responses that waste attackers' time while you gather intelligence.

🏗️ System Architecture

🎨 Click here to expand the interactive Diagram
graph TB
    subgraph Internet
        A[👤 Attacker]
        L[✅ Legitimate User]
    end
    
    subgraph "IFRIT Proxy Layer"
        B[🛡️ IFRIT Proxy]
        
        subgraph "AI Detection Engine"
            C1[🤖 Claude Sonnet 4]
            C2[🤖 Gemini 2.0 Flash]
        end
        
        subgraph "Threat Intelligence"
            D1[📊 AbuseIPDB]
            D2[🦠 VirusTotal]
            D3[🌍 IPInfo]
        end
    end
    
    subgraph Backend
        E[🎯 Your Application]
    end
    
    subgraph "Attacker Receives"
        F[🍯 Fake Data<br/>Honeypot Response]
    end
    
    subgraph "User Receives"
        G[📦 Real Data<br/>Protected]
    end
    
    A -->|Malicious Request| B
    L -->|Normal Request| B
    
    B --> C1
    B --> C2
    
    B --> D1
    B --> D2
    B --> D3
    
    B -->|Attack Detected| F
    B -->|Legitimate| E
    E -->|Response| G
    
    F -.->|Wasted Time| A
    G -->|Secure Access| L
    
    style A fill:#ff6b6b,stroke:#c92a2a,stroke-width:2px,color:#fff
    style L fill:#51cf66,stroke:#2f9e44,stroke-width:2px,color:#fff
    style B fill:#4c6ef5,stroke:#364fc7,stroke-width:3px,color:#fff
    style C1 fill:#845ef7,stroke:#5f3dc4,stroke-width:2px,color:#fff
    style C2 fill:#845ef7,stroke:#5f3dc4,stroke-width:2px,color:#fff
    style D1 fill:#ff922b,stroke:#e8590c,stroke-width:2px,color:#fff
    style D2 fill:#ff922b,stroke:#e8590c,stroke-width:2px,color:#fff
    style D3 fill:#ff922b,stroke:#e8590c,stroke-width:2px,color:#fff
    style E fill:#20c997,stroke:#12b886,stroke-width:2px,color:#fff
    style F fill:#fa5252,stroke:#c92a2a,stroke-width:2px,color:#fff
    style G fill:#51cf66,stroke:#2f9e44,stroke-width:2px,color:#fff

Simplified flow:

IFRIT Simple Flow Diagram

🚀 Quick Start

Get up and running in under 2 minutes

📦 Installation

macOS (Apple Silicon)

curl -L -o ifrit-v0.3.2-darwin-arm64.tar.gz \
  https://github.com/0tSystemsPublicRepos/IfritProxy/releases/download/v0.3.2/ifrit-v0.3.2-darwin-arm64.tar.gz


tar -xzf ifrit-v0.3.2-darwin-arm64.tar.gz
cd ifrit-v0.3.2-darwin-arm64
./install.sh

Linux (x64)

curl -LO https://github.com/0tSystemsPublicRepos/\
IfritProxy/releases/download/v0.3.2/\
ifrit-v0.3.2-linux-amd64.tar.gz

tar -xzf ifrit-v0.3.2-linux-amd64.tar.gz
cd ifrit-v0.3.2-linux-amd64
./install.sh

Installation Demo

Installation in action - it's really that simple!

⚙️ Configuration (Quick Setup)

# 1. Copy template
cp config/default.json.example config/default.json

# 2. Add your API keys
nano config/default.json  # or use your favorite editor

Minimal configuration to get started:

{
  "llm": {
    "provider": "claude",  // 👈 Choose: "claude" or "gemini"
    "claude": {
      "api_key": "sk-ant-..."  // 🔑 Get from console.anthropic.com
    }
  },
  "proxy": {
    "listen_port": 8080,
    "backend_url": "http://localhost:3000"  // 🎯 Your app
  }
}

🎬 Launch

Build the source code or Install from the available binaries

# Build the binary
go build -o ifrit ./cmd/ifrit
(optional: build ifrit-cli as well)

# Start IFRIT (runs in background)
./ifrit &

# 🎉 You're protected! Access dashboard:
open http://localhost:8443

That's it! IFRIT is now protecting your application.


✨ What Makes IFRIT Different?

💎 Core Capabilities

🧠 Multi-AI Intelligence

Choose your AI provider or let IFRIT auto-fallback:

  • 🎯 Claude Sonnet 4 - Industry-leading security analysis
  • ⚡ Gemini 2.0 Flash - Cost-effective, lightning fast
  • 🔄 Auto Fallback - Seamless provider switching
  • 💰 90% Cost Reduction - Through intelligent caching
{
  "provider": "claude",  // or "gemini"
  "cache_ttl": 86400    // 24h learning
}

🗄️ Production-Grade Storage

Database flexibility for any scale:

  • 📦 SQLite - Zero-config, perfect for single servers
  • 🐘 PostgreSQL - Enterprise scale, clustered deployments
  • 🔌 Provider Abstraction - Switch with config only
  • 🛠️ Unified CLI - Same commands, any database
# Works with both!
./ifrit-cli attack list
./ifrit-cli pattern add sql_injection

🎭 Adaptive Deception Engine

Intelligent honeypot responses that learn:

  • 🎨 AI-Generated - Realistic fake data matching your app
  • 📚 Pattern Learning - First attack = 3s, next = 10ms
  • 🎯 Context-Aware - Mimics requested resources
  • ⏱️ Time Wasting - Keeps attackers busy with fake targets

Example: SQL injection gets fake user database, path traversal gets fake file listings.

🔍 Threat Intelligence Hub

Real-time enrichment from multiple sources:

  • 🚨 AbuseIPDB - IP reputation (0-100 score)
  • 🦠 VirusTotal - Malware & C2 detection
  • 🌍 IPInfo - Geolocation, VPN, Tor, hosting
  • ⚖️ Risk Scoring - Weighted formula → threat level
IP: 45.67.89.12
├─ AbuseIPDB: 87/100 (234 reports)
├─ VirusTotal: 3 malware hits
├─ IPInfo: Russia, Tor exit node
└─ Risk: 92 → 🔴 CRITICAL

📢 Smart Alert System

Multi-channel notifications with zero fatigue:

Download Tool