Traphive is an open-source honeypot network. Run a cell on any Linux box and it poses as an easy target. Every bot that breaks in is recorded and shared, so every server using the Traphive feed can block it before it arrives.
Free and open source. A cell runs on any Linux machine with 512 MB of RAM.
A typical break-in, replayed. On the left is the root shell the bot thinks it has taken over. On the right is everything your Traphive cell writes down while it happens.
Every cell runs the same four steps around the clock, against scripts and AI agents alike. You install it once. The bots do the rest.
Your cell opens decoys of what bots hunt for: SSH logins, admin panels, open databases, exposed Docker APIs, unpatched VPN gateways and AI-agent endpoints. None of it is real.
Bots get in and find exactly what they wanted. Every keystroke, password, download and dropped file is captured inside a sandbox, walled off from your real services.
Your cell signs its report and sends it to the hive. An attacker is only published once cells on other networks have seen it too, so nobody can poison the feed.
The bot’s addresses, tools and fingerprints land in the Traphive feed. Firewalls, proxies and apps that use it drop that bot before it reaches them.
A lone honeypot can wait half a day for a scanner to stumble into it. Spread the same software across thousands of machines, and a new botnet walks into a cell within seconds of its first sweep. Everyone else is warned before it gets to them.
Drag the slider to see what each new cell buys the rest of us.
The Traphive feed is free for everyone, including commercial use. Pull it into your firewall, your reverse proxy or your app, and confirmed attackers stream in seconds after they’re caught.
Get it as plain-text blocklists, JSON, or STIX 2.1 over TAXII. Every entry carries the evidence behind it:
What people ask before they put a honeypot on the internet.
In most places, yes. A honeypot is your own machine answering traffic that strangers send to it, and Traphive never scans, attacks or hacks back. Some hosting providers want to know you’re running one, so check their terms, and your local law if you’re unsure.
Every public IP address is already being scanned, all day long. Traphive’s decoys run in sandboxes on ports you aren’t using, walled off from your real services. For extra distance, run your cell on a cheap VPS or a Raspberry Pi on its own network.
Only what attackers send to your decoys: their IP addresses, the commands they typed, the passwords they tried, the files they dropped and their network fingerprints. Never your own traffic, files or logs.
Every report is signed by the cell that made it. An address is only published once cells on different networks have seen it independently, cells earn trust over time, and entries expire when the activity stops.
Yes, for individuals and companies alike. Organizations that depend on it heavily are asked to sponsor the project. That’s what keeps it free for everyone else.
Any 64-bit Linux machine with one CPU core and 512 MB of RAM will do: a small VPS, a Raspberry Pi, the old PC under your desk. Paste one line, and your cell starts catching bots within minutes.
{{installCmd}}
Works on Ubuntu, Debian, Fedora, Arch, Alpine and Raspberry Pi OS, on x86-64 and ARM64. Read the setup guide
Every decoy runs in its own gVisor sandbox, on ports you aren’t using.
Your cell never sees your real traffic, only what attackers send to its decoys.
About 512 MB of RAM and a few gigabytes of traffic a month.
The servers that collect and publish the feed, the maintainers who review every change and the independent security audits are all funded by Traphive’s users. Every contribution and every expense is published in an open ledger.
Can’t run a cell? Funding the hive is the next best thing.
Keeps the feed online and free for everyone, month after month.
For teams whose products rely on the Traphive feed. Your company gets its own cell in the hive below.
Any amount, whenever you like. It lands in the same open ledger.