Community Edition · Free

Run a honeypot. Watch the internet attack it.

This is the free Community Edition of the ThreatSpire Honeypot. Deploy it in minutes, see real attacks land on your own sensor, and join a global map of community honeypots.

No account. No API key. One command to install.

How it works

From zero to live sensor in three steps

  1. STEP 1

    Download & install

    One command. The installer registers a systemd unit and runs the sensor as a background service on your Linux host.

  2. STEP 2

    It listens

    The sensor emulates common services (SSH, RDP, SMB, HTTP, Telnet, and more) and records every connection, login attempt, and payload it sees.

  3. STEP 3

    You see attackers

    Your node's observations feed the community map. Attackers are geolocated and summarized by protocol and volume.

Download

Pick your architecture

Both builds are the same sensor, compiled for a different CPU. Free for personal use. Contact us for commercial use.

Linux x86-64 (amd64)

Intel / AMD servers, most cloud VMs.

file:
threatspire-honeypot-community-linux-amd64.zip
version:
v1.0.0
Download Linux x86-64 (amd64)

Requires: a Linux host with a public IP, systemd, and root to install.

Linux ARM64 (aarch64)

Graviton, Ampere, Raspberry Pi 4/5 class hosts.

file:
threatspire-honeypot-community-linux-arm64.zip
version:
v1.0.0
Download Linux ARM64 (aarch64)

Requires: a Linux host with a public IP, systemd, and root to install.

Install

Three commands, then it is live

Substitute the arm64 file name if you downloaded the ARM64 build.

  1. 1

    Unpack the archive

    unzip threatspire-honeypot-community-linux-amd64.zip && cd threatspire-honeypot-community
  2. 2

    Run the installer as root

    sudo ./install.sh
  3. 3

    Confirm the service is running

    sudo systemctl status threatspire-honeypot

No account or API key needed. The Community Edition build reports anonymously. Your node appears on the map only by its public IP's country or region.

Live community threat map

Every node makes the picture sharper

Aggregated from all reporting Community Edition sensors. Cached for about ten minutes and refreshed here every few minutes.

Total nodes

Total attacks observed

Countries covered

Loading community telemetry…

What it detects

IT protocol sensors, included

Each sensor logs the full connection: source, credentials attempted, and payload.

  • SSH (22)
  • RDP (3389)
  • SMB (445)
  • HTTP (80)
  • HTTPS (443)
  • Telnet (23)
  • FTP (21)
  • SIP (5060)
  • VNC (5900)
  • MySQL (3306)
  • PostgreSQL (5432)
  • MSSQL (1433)
  • Redis (6379)
  • MongoDB (27017)
  • SMTP (25)
  • Elasticsearch (9200)

Industrial/OT protocols (Modbus, DNP3, S7, IEC-104…) are available in the commercial edition.

Privacy

What we do with your node's data

  • Your honeypot's public IP is used only to place your node on the map by country and, in the US, by state.
  • The public map never shows raw IP addresses or city-level location.
  • The attack data your node sees is aggregated into the community picture.

Need more?

Community Edition vs Commercial

Community gives you a live sensor and the shared picture. Commercial gives you your own picture, with OT coverage and workflow.

CapabilityCommunityCommercial
IT protocol sensorsAll includedAll included
OT / SCADA sensorsNot includedModbus, DNP3, S7, IEC-104 and more
DeploymentsSingle anonymous nodeNamed multi-honeypot fleets
DashboardsPublic community mapPrivate tenant dashboards
AlertingNot includedReal-time alerting
InvestigationNot includedCase management and evidence timeline
Talk to us

Powered by ThreatSpire

IP geolocation by DB-IP (CC-BY-4.0).