Plug in. Decoy. Log. Repeat.

HoneyBox is intentionally simple: a dedicated ESP32 device that looks interesting to scanners and boringly honest to you.

  1. Drop it on your LAN

    Power HoneyBox, connect it to your network, and reach the local web UI from any browser on the same LAN.

  2. Choose what to emulate

    Enable the services you want — SSH, RDP, SMB, and more — so scanners find a convincing decoy instead of silence.

  3. Collect evidence locally

    Attempts land on the SD card. Optional email alerts nudge you. The companion PWA keeps management in your pocket.

Not a VM you forget. Not a cloud sensor you rent.

DIY honeypots drift: outdated images, shared hosts, accidental exposure of real workloads. HoneyBox is purpose-built hardware with a clear job — attract, record, stay out of the way.

Attacker → HoneyBox → your SD card.

There is no “phone home” pipeline. No vendor dashboard mining your events. If you want alerts, you configure them. If you want exports, you own the files.

Ready to set one up?