awesome-repositories.com
Blog
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
hacklcx avatar

hacklcx/HFish

0
View on GitHub↗
4,517 stars·675 forks·3 viewshfish.net↗

HFish

HFish is a distributed honeypot system and network intrusion detection tool designed to deploy decoy services and nodes to detect and analyze attacker behavior. It functions as a deceptive asset orchestrator that simulates enterprise services and configures custom baits to lure network intruders.

The system utilizes a server-client architecture to manage distributed nodes across different platforms, allowing for centralized control of telemetry collection and decoy deployment. It incorporates cloud-based traffic routing to redirect suspicious network activity into managed decoy environments for centralized threat capture and analysis.

The platform provides capabilities for network scanning detection across open ports and the simulation of various network services, including IoT devices and CRM systems. It includes a threat telemetry manager and a pluggable alert dispatcher that routes security notifications through email, webhooks, syslog, and enterprise messaging platforms.

Features

  • Honeypot Management - Provides a comprehensive platform for deploying and controlling multiple decoy nodes from a centralized server.
  • Honeypots and Deception - Deploys decoy services and nodes to detect and analyze attacker behavior across a distributed network.
  • Deceptive Service Mocks - Emulates specific network protocols and services, such as IoT devices and CRM systems, to mislead attackers.
  • Scanning Detection - Tracks activity across all open network ports to identify reconnaissance and unauthorized scanning patterns.
  • Network Scanning Detection - Tracks network ports to identify reconnaissance activities and alert on unauthorized scanning attempts.
  • Deceptive Asset Orchestrators - Functions as an orchestrator for configuring custom baits and simulating enterprise services to lure intruders.
  • Deceptive Bait Configurations - Provides a way to define specific asset profiles and deceptive settings to lure network intruders.
  • Honeypot Node Management - Controls remote telemetry collection points via a centralized server that coordinates deployment and data gathering.
  • Network Deception Technologies - Creates fake network services and assets to lure attackers and detect unauthorized activity.
  • Network Intrusion Detection - Monitors network traffic for suspicious patterns and reconnaissance attempts to alert administrators of potential intrusions.
  • Threat Telemetry Collection - Collects interaction data from remote nodes using a server-client architecture to manage threat telemetry.
  • Web Honeypots - Builds specialized web-based deceptive environments to lure attackers and capture interaction data.
  • Traffic Routing - Implements mechanisms for directing suspicious network traffic to isolated decoy environments for centralized analysis.
  • Decoy Redirections - Provides cloud-based traffic routing to redirect suspicious activity into managed decoy environments for centralized analysis.
  • Threat Notification Systems - Sends real-time security notifications to administrators via webhooks, email, or messaging platforms.
  • Notification Dispatchers - Dispatches threat alerts via email, syslog, webhooks, and enterprise messaging platforms.
  • Distributed Node Lifecycles - Manages the deployment and supervision of remote decoy nodes across different platforms.
  • Multi-Channel Alerting - Routes security notifications through multiple external channels including email, webhooks, and enterprise messaging systems.
  • Honeypots - Deploys high-interaction honeypots for threat intelligence.

Star history

Star history chart for hacklcx/hfishStar history chart for hacklcx/hfish

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to HFish

Similar open-source projects, ranked by how many features they share with HFish.
  • telekom-security/tpotcetelekom-security avatar

    telekom-security/tpotce

    9,298View on GitHub↗

    T-Pot is a multi-honeypot platform and threat intelligence framework that deploys a collection of containerized decoy services to capture attacker behavior and network telemetry. It functions as a Docker-based deception system, simulating vulnerable network environments to gather intelligence on threat actors. The system features a distributed sensor network using a hub-and-spoke architecture, allowing remote sensors to transmit logs back to a central management hub. It integrates large language models to create a dynamic deception engine capable of adaptive interactions with attackers. The

    Shelldeceptiondockerelk
    View on GitHub↗9,298
  • thinkst/opencanarythinkst avatar

    thinkst/opencanary

    2,776View on GitHub↗

    OpenCanary is a network service simulator and honeypot designed for network intrusion detection. It functions as a security decoy that creates fake server personalities and open ports to identify unauthorized users scanning a private network. The system uses deception technology to mimic various server protocols, luring attackers into revealing their presence and activity. When a simulated service is accessed, it acts as an intrusion alerting gateway, transmitting notifications via email or webhooks. The project covers internal network monitoring and intrusion source tracking to identify the

    Python
    View on GitHub↗2,776
  • cloudflare/cloudflare-docscloudflare avatar

    cloudflare/cloudflare-docs

    4,859View on GitHub↗

    This repository is a technical documentation site and a collection of guides and references for implementing networking, security, and cloud infrastructure services. It functions as a static-site generated portal and a headless content platform, separating source files from the presentation layer to enable flexible rendering. The project utilizes markdown-based documentation stored in a version-controlled Git repository. It provides specialized technical content including an AI platform documentation for building agents and managing inference, a cloud infrastructure guide for DNS and CDN conf

    MDXcloudflaredocshacktoberfest
    View on GitHub↗4,859
  • awesome-selfhosted/awesome-selfhostedawesome-selfhosted avatar

    awesome-selfhosted/awesome-selfhosted

    299,516View on GitHub↗

    This project is a community-curated directory of open-source software designed for deployment in private server environments and home labs. It serves as a comprehensive resource for discovering independent, self-hosted alternatives to mainstream cloud services, enabling users to maintain full data ownership and control over their digital infrastructure. The directory is structured through a hierarchical taxonomy that organizes a vast collection of applications into logical categories, ranging from media management and data analytics to private communication and team productivity tools. It dis

    awesomeawesome-listcloud
    View on GitHub↗299,516
See all 30 alternatives to HFish→

Frequently asked questions

What does hacklcx/hfish do?

HFish is a distributed honeypot system and network intrusion detection tool designed to deploy decoy services and nodes to detect and analyze attacker behavior. It functions as a deceptive asset orchestrator that simulates enterprise services and configures custom baits to lure network intruders.

What are the main features of hacklcx/hfish?

The main features of hacklcx/hfish are: Honeypot Management, Honeypots and Deception, Deceptive Service Mocks, Scanning Detection, Network Scanning Detection, Deceptive Asset Orchestrators, Deceptive Bait Configurations, Honeypot Node Management.

What are some open-source alternatives to hacklcx/hfish?

Open-source alternatives to hacklcx/hfish include: telekom-security/tpotce — T-Pot is a multi-honeypot platform and threat intelligence framework that deploys a collection of containerized decoy… thinkst/opencanary — OpenCanary is a network service simulator and honeypot designed for network intrusion detection. It functions as a… cloudflare/cloudflare-docs — This repository is a technical documentation site and a collection of guides and references for implementing… awesome-selfhosted/awesome-selfhosted — This project is a community-curated directory of open-source software designed for deployment in private server… paralax/awesome-honeypots — an awesome list of honeypot resources. stamparm/maltrail — Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network…