They came for a backdoor. They found a trapdoor.

Traphive is an open-source honeypot network. Run a cell on any Linux box and it poses as an easy target. Every bot that breaks in is recorded and shared, so every server using the Traphive feed can block it before it arrives.

Free and open source. A cell runs on any Linux machine with 512 MB of RAM.

Watch a bot fall for it.

A typical break-in, replayed. On the left is the root shell the bot thinks it has taken over. On the right is everything your Traphive cell writes down while it happens.

Bait, record, confirm, block.

Every cell runs the same four steps around the clock, against scripts and AI agents alike. You install it once. The bots do the rest.

  1. Bait

    Your cell opens decoys of what bots hunt for: SSH logins, admin panels, open databases, exposed Docker APIs, unpatched VPN gateways and AI-agent endpoints. None of it is real.

  2. Record

    Bots get in and find exactly what they wanted. Every keystroke, password, download and dropped file is captured inside a sandbox, walled off from your real services.

  3. Confirm

    Your cell signs its report and sends it to the hive. An attacker is only published once cells on other networks have seen it too, so nobody can poison the feed.

  4. Block

    The bot’s addresses, tools and fingerprints land in the Traphive feed. Firewalls, proxies and apps that use it drop that bot before it reaches them.

One cell is a trap. Thousands are a hive.

A lone honeypot can wait half a day for a scanner to stumble into it. Spread the same software across thousands of machines, and a new botnet walks into a cell within seconds of its first sweep. Everyone else is warned before it gets to them.

Drag the slider to see what each new cell buys the rest of us.

{{nodesLabel}}
100 100,000
{{firstN}} {{firstU}}

until a new botnet walks into its first cell

{{blockN}} {{blockU}}

until it’s confirmed and blocked on every server using the Traphive feed

For comparison, a lone honeypot waits about 13 hours. The model assumes one botnet probing random IPv4 addresses at 80,000 per second, three independent sightings to confirm and two seconds to publish.

Put the Traphive feed between bots and your servers.

The Traphive feed is free for everyone, including commercial use. Pull it into your firewall, your reverse proxy or your app, and confirmed attackers stream in seconds after they’re caught.

Get it as plain-text blocklists, JSON, or STIX 2.1 over TAXII. Every entry carries the evidence behind it:

Confidence
A score from 0 to 100, set by how many independent cells saw it.
Sightings
When it was first and last seen, and by how many cells.
Techniques
Everything it tried, mapped to MITRE ATT&CK.
Fingerprints
JA4 and HASSH signatures, plus hashes of every file it dropped.
Read the feed documentation
# keeps a set of confirmed attackers fresh, every 60 seconds
$ sudo traphive-sync nftables --min-confidence 90
table inet traphive {
set attackers { type ipv4_addr; flags timeout; }
chain input {
type filter hook input priority -10;
ip saddr @attackers drop
}
}
# /etc/nginx/conf.d/traphive.conf
# traphive-sync rewrites the deny list every minute
include /etc/traphive/deny.conf;
# /etc/traphive/deny.conf, a few lines of it
deny 203.0.113.77; # ssh brute force, cryptominer
deny 198.51.100.7; # malware download host
from traphive import Feed
feed = Feed() # free, no API key needed
@app.middleware("http")
async def drop_known_attackers(request, call_next):
if feed.is_hostile(request.client.host, min_confidence=90):
return Response(status_code=403)
return await call_next(request)
$ curl https://api.traphive.com/v1/ip/203.0.113.77
{
"ip": "203.0.113.77",
"confidence": 97,
"seen_by_cells": 3,
"first_seen": "2026-10-01T03:12:44Z",
"techniques": ["T1110.001", "T1552.001", "T1105", "T1496"],
"tags": ["ssh-bruteforce", "cryptominer"]
}

Fair questions.

What people ask before they put a honeypot on the internet.

Is it legal to run a honeypot?

In most places, yes. A honeypot is your own machine answering traffic that strangers send to it, and Traphive never scans, attacks or hacks back. Some hosting providers want to know you’re running one, so check their terms, and your local law if you’re unsure.

Will it make my server a target?

Every public IP address is already being scanned, all day long. Traphive’s decoys run in sandboxes on ports you aren’t using, walled off from your real services. For extra distance, run your cell on a cheap VPS or a Raspberry Pi on its own network.

What does my cell send to the hive?

Only what attackers send to your decoys: their IP addresses, the commands they typed, the passwords they tried, the files they dropped and their network fingerprints. Never your own traffic, files or logs.

Can someone poison the feed with fake reports?

Every report is signed by the cell that made it. An address is only published once cells on different networks have seen it independently, cells earn trust over time, and entries expire when the activity stops.

Is the feed really free?

Yes, for individuals and companies alike. Organizations that depend on it heavily are asked to sponsor the project. That’s what keeps it free for everyone else.

Your spare Linux box is a trap waiting to happen.

Any 64-bit Linux machine with one CPU core and 512 MB of RAM will do: a small VPS, a Raspberry Pi, the old PC under your desk. Paste one line, and your cell starts catching bots within minutes.

{{installCmd}}

Works on Ubuntu, Debian, Fedora, Arch, Alpine and Raspberry Pi OS, on x86-64 and ARM64. Read the setup guide

Sandboxed

Every decoy runs in its own gVisor sandbox, on ports you aren’t using.

Private

Your cell never sees your real traffic, only what attackers send to its decoys.

Light

About 512 MB of RAM and a few gigabytes of traffic a month.

No investors. No ads. Paid for by the people it protects.

The servers that collect and publish the feed, the maintainers who review every change and the independent security audits are all funded by Traphive’s users. Every contribution and every expense is published in an open ledger.

Can’t run a cell? Funding the hive is the next best thing.

Backer

Keeps the feed online and free for everyone, month after month.

€10 a month Become a backer

Company sponsor

For teams whose products rely on the Traphive feed. Your company gets its own cell in the hive below.

€100 a month Sponsor Traphive

One-time gift

Any amount, whenever you like. It lands in the same open ledger.

Any amount Give once

The one ad spot that makes the internet safer.

Every company in the hive pays €100 a month to keep the Traphive feed free for everyone. In return, its name sits right here, in front of the developers and security teams who come to protect their servers. It’s marketing that leaves the internet safer than it found it.

Claim a cell €100 a month, listed for as long as you sponsor
Anthropic Brightmoss Dell Your name here Ember Rack Google HP Lindgren & Saar Your name here Microsoft Nordvik Data OpenAI Your name here Quillfeather Security Saltmarsh Cloud Your name here Your name here Your name here