Run a honeypot. Watch the internet attack it.
This is the free Community Edition of the ThreatSpire Honeypot. Deploy it in minutes, see real attacks land on your own sensor, and join a global map of community honeypots.
No account. No API key. One command to install.
How it works
From zero to live sensor in three steps
- STEP 1
Download & install
One command. The installer registers a systemd unit and runs the sensor as a background service on your Linux host.
- STEP 2
It listens
The sensor emulates common services (SSH, RDP, SMB, HTTP, Telnet, and more) and records every connection, login attempt, and payload it sees.
- STEP 3
You see attackers
Your node's observations feed the community map. Attackers are geolocated and summarized by protocol and volume.
Download
Pick your architecture
Both builds are the same sensor, compiled for a different CPU. Free for personal use. Contact us for commercial use.
Linux x86-64 (amd64)
Intel / AMD servers, most cloud VMs.
- file:
- threatspire-honeypot-community-linux-amd64.zip
- version:
- v1.0.0
Requires: a Linux host with a public IP, systemd, and root to install.
Linux ARM64 (aarch64)
Graviton, Ampere, Raspberry Pi 4/5 class hosts.
- file:
- threatspire-honeypot-community-linux-arm64.zip
- version:
- v1.0.0
Requires: a Linux host with a public IP, systemd, and root to install.
Install
Three commands, then it is live
Substitute the arm64 file name if you downloaded the ARM64 build.
- 1
Unpack the archive
unzip threatspire-honeypot-community-linux-amd64.zip && cd threatspire-honeypot-community - 2
Run the installer as root
sudo ./install.sh - 3
Confirm the service is running
sudo systemctl status threatspire-honeypot
No account or API key needed. The Community Edition build reports anonymously. Your node appears on the map only by its public IP's country or region.
Live community threat map
Every node makes the picture sharper
Aggregated from all reporting Community Edition sensors. Cached for about ten minutes and refreshed here every few minutes.
…
…
…
Loading community telemetry…
What it detects
IT protocol sensors, included
Each sensor logs the full connection: source, credentials attempted, and payload.
- SSH (22)
- RDP (3389)
- SMB (445)
- HTTP (80)
- HTTPS (443)
- Telnet (23)
- FTP (21)
- SIP (5060)
- VNC (5900)
- MySQL (3306)
- PostgreSQL (5432)
- MSSQL (1433)
- Redis (6379)
- MongoDB (27017)
- SMTP (25)
- Elasticsearch (9200)
Industrial/OT protocols (Modbus, DNP3, S7, IEC-104…) are available in the commercial edition.
Privacy
What we do with your node's data
- Your honeypot's public IP is used only to place your node on the map by country and, in the US, by state.
- The public map never shows raw IP addresses or city-level location.
- The attack data your node sees is aggregated into the community picture.
Need more?
Community Edition vs Commercial
Community gives you a live sensor and the shared picture. Commercial gives you your own picture, with OT coverage and workflow.
| Capability | Community | Commercial |
|---|---|---|
| IT protocol sensors | All included | All included |
| OT / SCADA sensors | Not included | Modbus, DNP3, S7, IEC-104 and more |
| Deployments | Single anonymous node | Named multi-honeypot fleets |
| Dashboards | Public community map | Private tenant dashboards |
| Alerting | Not included | Real-time alerting |
| Investigation | Not included | Case management and evidence timeline |
