HoneyNet
- Company typePrivate
- Founded1999
- HeadquartersNaperville, United States
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
HoneyNet firmographics
Firmographics- Name
- HoneyNet
- Legal name
- The Honeynet Project
- Website
- https://honeynet.org
- Company type
- Private
- Founded year
- 1999
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Ownership category
- akta.pro rank
HoneyNet industry classification
Industry- Product category
- Open-Source Cybersecurity Tools
- NAICS
- Computer Systems Design and Related Services (5415)
- akta.pro primary industry
- Deception & Honeypot-Based Network Defense (HDADABAN)
- akta.pro secondary industries
- Deception / Honeypot Network Security Appliances (HDAFAFAL), Web Application Security (WAF, RASP) (HDADACAA), Managed OT Security Services (MSSP/MDR for ICS/OT) (HDADAJAN), Web Application Firewall (WAF) & Bot Management (ADC‑Integrated) (HDAFAHAG)
Keywords
Where HoneyNet is headquartered
LocationHeadquarters
- HQ city
- Naperville
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
HoneyNet business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Others
Revenue model
- Donations and Grants: As a 501(c)(3) non-profit organization, HoneyNet relies on donations and grants to fund operations and research activities.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Annual | Free open-source tools |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels5 records
HoneyNet product offering
Product offeringCore offering
The Honeynet Project (HoneyNet) is a 501(c)(3) non-profit security research organization that develops and distributes a portfolio of open-source security tools. Its core offerings include the IntelOwl OSINT threat intelligence platform with 100+ analyzers, BuffaLogs authentication anomaly detection, and a family of honeypots and malware analysis frameworks such as Dionaea, Glastopf, ConPot, Cuckoo Sandbox, Thug, and Mitmproxy.
Product overview
The Honeynet Project is a non-profit security research organization that develops and maintains a comprehensive portfolio of open-source security tools. The core offerings include IntelOwl (an OSINT threat intelligence platform with 100+ analyzers), BuffaLogs (authentication anomaly detection with alerting), and various honeypot technologies (Dionaea, Glastopf, ConPot, Thug). The project also includes analysis tools like Cuckoo Sandbox, DroidBox, and Dorothy2, as well as mobile and web honeypots (HosTaGe, SNARE/TANNER). Supporting tools include HoneyProxy for traffic analysis, PcapMonkey for network capture, Ochi for event filtering, and GreedyBear for threat intelligence. These tools are primarily developed through Google Summer of Code and are freely available as open-source software.
Differentiator
Problem solved
Functional benefit
Brands
- IntelOwl: Open Source Intelligence solution to get threat intelligence data about specific files, IPs, or domains from a single API at scale. Integrates 100+ analyzers.
- BuffaLogs
- GreedyBear
- SNARE/TANNER
- Glastopf
- Dionaea
- Cuckoo Sandbox
- Mitmproxy
- HosTaGe
- Dorothy2
- PcapMonkey
- HoneyProxy
Products and services
- IntelOwl Open Source Intelligence (OSINT) platform that aggregates threat intelligence data about files, domains, IPs, and other observables from 100+ integrated analyzers through a single unified API. Supports connectors for automated threat sharing with MISP, OpenCTI, and YETI platforms. Targets security analysts, researchers, and enterprise security teams.
- BuffaLogs Open-source authentication protection tool built with Django providing anomalous login detection, alerting, and log ingestion through a web-based dashboard. Includes BuffaCLI command-line interface and BuffaWatch real-time log monitoring components. Built for security teams monitoring authentication infrastructure.
- Dionaea Low-interaction honeypot designed to capture malware samples by emulating various network services and protocols. Used by security researchers and threat intelligence teams.
- Glastopf Web application honeypot that emulates vulnerabilities to attract and detect web-based attacks, including a PHP sandbox for code injection emulation. Used by security researchers and blue teams.
- ConPot ICS/SCADA honeypot designed to simulate industrial control system environments for detecting and analyzing attacks on critical infrastructure. Used by security teams protecting operational technology environments.
- Thug Client honeypot (low-interaction honeyclient) that analyzes malicious websites by emulating web browsers to detect drive-by download attacks. Used by security analysts.
- Cuckoo Sandbox Automated malware analysis system that executes suspicious files in isolated virtualized environments and analyzes their behavior. Used by malware analysts and incident responders.
- DroidBox Android dynamic analysis tool that provides sandboxed execution and behavioral analysis of Android applications for malware detection. Used by mobile security researchers.
- Mitmproxy Interactive HTTPS proxy for debugging, testing, and analyzing web traffic including HTTP/1, HTTP/2, WebSockets, and SSL/TLS protocols. Used by security researchers and penetration testers.
- Dorothy2 Ruby-based malware and botnet analysis framework that analyzes network behavior of suspicious executables in virtual machines with modular architecture and multiple concurrent analysis capabilities.
- HosTaGe Low-interaction mobile honeypot for Android devices that emulates modern protocols for on-the-go threat detection. Used by mobile security researchers.
- SNARE and TANNER Web application honeypot sensor (SNARE) that attracts malicious activity from the internet, paired with TANNER, a remote data analysis and classification service that evaluates HTTP requests and composes responses.
- GreedyBear Honeypot sensor network project to detect and track attacker infrastructure, providing additional intelligence feeds and detection capabilities for the security community.
- Ochi Event filtering tool that enables users to filter events using a DSL, persist filters, and share event data. Used by security analysts managing event streams.
Quantifiable outcome
- Tools used by businesses and government agencies worldwide
- +1 more outcomes
Companies that use HoneyNet
Customer profileNamed customers1 record
Segments3 records
Ideal customer profiles3 records
HoneyNet technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration12 records
AI capability4 records
Feature6 records
HoneyNet partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Google Summer of CodecoreHoneyNet has participated as a mentoring organization in Google Summer of Code since 2009, accelerating the creation of information- and cyber security-related open-source tools. Students work with mentors to develop security projects over 3-month periods.
Scale indicators4 records
Recent moves6 records
Expansion highlights5 records
HoneyNet competitors and assessment
Company assessmentBroad incumbents
- VirusTotal: Google-owned file and URL analysis platform aggregating 70+ antivirus engines and threat intelligence. Comparable to IntelOwl's file/observable analysis capabilities but delivered as a massive commercial platform.
- CrowdStrike: Endpoint detection and response leader that also offers threat intelligence and participates in honeypot/deception research. Collaborated with HoneyNet on the Kelihos.B botnet takedown in 2012 and is a broad incumbent across HoneyNet's threat intel and malware analysis domains.
- Kaspersky: Global cybersecurity vendor with threat intelligence, malware analysis, and ICS security portfolios overlapping with HoneyNet's products (ConPot for ICS, Cuckoo for malware). Also a Kelihos.B takedown collaborator.
Direct peers
- Cuckoo Sandbox Foundation: Open-source automated malware analysis system originally incubated by HoneyNet. Closely comparable to HoneyNet's Cuckoo Sandbox as a community-driven malware analysis project serving security researchers.
- Thinkst Canary: Commercial honeypot/deception technology vendor offering easy-to-deploy canary tokens and honeypots for enterprise threat detection. Directly comparable to HoneyNet's honeypot portfolio (Dionaea, ConPot, SNARE) but delivered as a polished, supported commercial product.
- OpenCTI: Open-source cyber threat intelligence platform. IntelOwl provides native OpenCTI connectors, positioning the two as complementary peers in the open-source threat intelligence stack.
- MISP Project: Open-source threat intelligence sharing platform. IntelOwl has a native MISP connector for automated indicator sharing, making it tightly coupled with MISP and a direct peer in the threat intelligence ecosystem.
Others
- MITRE ATT&CK / MITRE Caldera: MITRE's adversary tactics/techniques framework and Caldera automated adversary emulation platform. Comparable to HoneyNet's attacker research and forensic challenges, though positioned as a public framework rather than a tool portfolio.
Emerging players
- Security Onion Solutions: Open-source network security monitoring and log management platform combining IDS, full packet capture, and honeypot capabilities. Comparable to HoneyNet's network traffic analysis and honeypot deployment use cases.
- Certego: Managed security services provider that hosts and maintains BuffaLogs (an incubated HoneyNet project) as an open-source authentication protection tool. Direct peer in the open-source security tooling space with a tighter commercial model.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
HoneyNet social profiles
Digital presenceHoneyNet financial estimates
Financial estimateRevenue estimate
Valuation estimate
HoneyNet leadership team
Management profileNumber of profiles
Profiles3 records
HoneyNet funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
HoneyNet M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about HoneyNet
What does HoneyNet do?
The Honeynet Project (HoneyNet) is a 501(c)(3) non-profit security research organization that develops and distributes a portfolio of open-source security tools. Its core offerings include the IntelOwl OSINT threat intelligence platform with 100+ analyzers, BuffaLogs authentication anomaly detection, and a family of honeypots and malware analysis frameworks such as Dionaea, Glastopf, ConPot, Cuckoo Sandbox, Thug, and Mitmproxy.
Is HoneyNet a public or private company?
HoneyNet is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was HoneyNet founded?
HoneyNet was founded in 1999. It employs 51 to 100 people.
Where is HoneyNet based?
HoneyNet is headquartered in Naperville, United States, in the North America region.
How does HoneyNet make money?
One revenue line is on record: donations and Grants.
Who are HoneyNet's main competitors?
Broad incumbents on record are VirusTotal, CrowdStrike and Kaspersky. Direct peers are Cuckoo Sandbox Foundation, Thinkst Canary, OpenCTI and MISP Project. MITRE ATT&CK / MITRE Caldera is listed as an others. Emerging players are Security Onion Solutions and Certego.
Does HoneyNet have an API?
Yes. IntelOwl provides a public API for threat intelligence analysis. Organizations can host their own instance and query threat intelligence data about specific files or observables through the API. The API supports JWT authentication, file analysis endpoints (/api/analyze_file), observable analysis endpoints (/api/analyze_observable), and analyzer/connector management. PyIntelOwl is the official Python client/SDK for interacting with the IntelOwl API. Developer documentation is at intelowl.readthedocs.io.
What industry is HoneyNet in?
HoneyNet's product category is Open-Source Cybersecurity Tools. Its primary akta.pro industry code is HDADABAN, Deception & Honeypot-Based Network Defense, with a secondary code of HDAFAFAL, Deception / Honeypot Network Security Appliances. Its NAICS code is 5415.