Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
HoneyWire — Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services to detect intruders with instant forensics and push notifications. | Kitploit
Tools/GitHubGitHub/andreicscs/honeywire
Container SecurityNetwork SecurityDevSecOpsThreat IntelligenceIntrusion DetectionIncident Response
GitHubandreicscs/honeywire

HoneyWire

Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services to detect intruders with instant forensics and push notifications.

View Repository
1024231 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

HoneyWire Logo

HoneyWire

Latest Release License: GPLv3 Risky Bulletin Docker Native OpenSSF Best Practices

📋 Table of Contents

  • Overview
  • Showcase
  • The Universal Event Standard
  • Features
  • Architecture
  • Quick Start Guide
  • Security Notes
  • Tech Stack
  • Roadmap & Development
  • Versioning and API Reference

Overview

HoneyWire is a lightweight, Distributed High-Signal Security Early-Warning System Builder, designed for internal networks. It leverages its architecture and UX to make it incredibly easy to build a new Cyber Canary server or deploy HoneyWires on existing ones. Using deception technology, it replaces the "magnifying glass" approach of traditional SIEMs which often drown analysts in false positives by surveilling legitimate traffic with a High-Fidelity Tripwire model.

Place a sensor exactly where you want it. If it trips, you have an intruder.

  • Production Tripwires: Sound the alarm when active services are being poked in ways they shouldn't be. By placing a sensor on a sensitive file that should never be read or a service port that should never be accessed, you identify intruders by their deviation from the "authorized path."
  • Synthetic Deception: Deploy lures like the ICMP Canary or Network Scan Detector to act as decoys. Since these sensors provide no legitimate business value, 100% of their traffic is actionable intelligence.

Set up multiple and you start to have a pretty clear idea of the lateral movement of an intruder. No tuning, no noise, just instant forensics. If you have legitimate automated security scanners tripping HoneyWires just whitelist them from the Hub's settings.

Showcase

🔌 The Universal Event Standard (Bring Your Own Sensor)

Community Sensors

Note: If you build your sensor using the official HoneyWire SDKs, this JSON formatting and delivery is handled for you automatically.

The true power of HoneyWire is that the Hub and Wizard are completely sensor-agnostic. You are not limited to the included official sensors.

By adhering to the HoneyWire Event Standard V2.0, you can write a script in any language (Bash, Go, Rust, Python) to monitor anything, and the Sentinel UI will dynamically parse, syntax-highlight, and render your forensic data.

Whether it is a Deep Packet Inspection (DPI) engine, a DNS sinkhole, a Canary Token embedded in a PDF, an Email Honeypot, or a simple TCP Port Tripwire, just POST the Universal Event Standard JSON payload to the Hub.

View the full Event Data Contract here

Features

  • The Sentinel Hub UI: A fully responsive, Vue 3-powered dashboard featuring dynamic forensic payload inspection, Nodes and Sensors deployment and management, including sensor updates, directly from the UI.
    • Universal Push Notifications: Native, zero-dependency integration for routing critical alerts to Discord, Slack, Ntfy, and Gotify.
    • Enterprise SIEM Integration: Native RFC5424 Syslog forwarding (TCP/UDP) for seamlessly pushing structured telemetry to Splunk, Elastic, Wazuh, or Vector.
  • The Setup Wizard: A deployment and testing automation tool, developed explicitly to not be a 24/7 running agent. It is simply a TUI CLI tool that automates operator tasks like applying and reconciling the Hub's desired state for a given Node, automatically handling configuration, deployment, and rollbacks on failed deployments.
  • Suite of Official HoneyWires: Includes native TCP Tarpit, Web Router Decoy, File Canary (FIM), ICMP Canary, and Network Scan Detector.

Architecture

HoneyWire is split into four independent microservices:

  1. /Hub: The central brain. A pure Go binary running an embedded SQLite database and the Vue.js dashboard. It runs as a non-root user inside a Distroless container, safely mounting data to a dedicated volume.
  2. /Sensors: The decoy nodes. Statically-linked Go binaries that listen on vulnerable ports, trap attackers, and securely POST intrusion data back to the Hub.
  3. /SDKs: Official libraries (like sdk-go) that handle secure Hub communication so community developers can easily build new sensors.
  4. /wizard: Setup wizard cli tool to automate operator tasks such as discovery, deployment and testing of HoneyWires.

Check out the full architecture docs Read the User Operations Guide

🚀 Quick Start Guide

Deploying the HoneyWire Hub takes less than 60 seconds using our pre-built GitHub Container images.

1. Deploy the Hub

Create a new directory on your server, create a docker-compose.yml file, and paste the following:

services:
  # 1. THE PERMISSION FIXER: Runs once to ensure the Hub can write to the data volume
  permission-fixer:
    image: alpine:latest
    container_name: honeywire-permission-fixer
    command: sh -c "chown -R 65532:65532 /data"
    volumes:
      - ./honeywire_data:/data
Download Tool