Introducing HoneyBee: How We Automate Honeypot Deployment for Threat Research
ID: 1c2d8581-b691-5e5c-8d70-eab4fa1a8bf6
STIX ID: report--1c2d8581-b691-5e5c-8d70-eab4fa1a8bf6
Feed Name: Wiz Blog
This post announces HoneyBee, an open-source framework that auto-generates intentionally insecure Docker/Compose setups and Nuclei templates to create realistic, observable honeypots for cloud applications. It details how Wiz uses HoneyBee to validate detection rules, orchestrate network-monitored honeypots, and conduct security research and training, highlighting observed real-world misuse such as JDWP-driven cryptomining deployments and attacks on weak PostgreSQL instances, all aimed at improving detections and defensive capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
