How it works
Plug in. Decoy. Log. Repeat.
HoneyBox is intentionally simple: a dedicated ESP32 device that looks interesting to scanners and boringly honest to you.
-
Drop it on your LAN
Power HoneyBox, connect it to your network, and reach the local web UI from any browser on the same LAN.
-
Choose what to emulate
Enable the services you want — SSH, RDP, SMB, and more — so scanners find a convincing decoy instead of silence.
-
Collect evidence locally
Attempts land on the SD card. Optional email alerts nudge you. The companion PWA keeps management in your pocket.
Why a dedicated device
Not a VM you forget. Not a cloud sensor you rent.
DIY honeypots drift: outdated images, shared hosts, accidental exposure of real workloads. HoneyBox is purpose-built hardware with a clear job — attract, record, stay out of the way.
Data path
Attacker → HoneyBox → your SD card.
There is no “phone home” pipeline. No vendor dashboard mining your events. If you want alerts, you configure them. If you want exports, you own the files.