Skip to content

beelzebub

Forensics & Incident Response

Open‑source deception runtime that deploys adaptive, LLM‑powered decoy services across SSH, HTTP, TCP, TELNET and MCP to engage attackers and collect high‑fidelity threat intelligence

Go Latest v3.8.0 · 1d ago Security brief →

Features

  • Adaptive LLM‑driven responses (OpenAI, Ollama) for realistic attacker engagement
  • Low‑code YAML service definitions with regex command matching – no custom code needed
  • Multi‑protocol coverage: SSH, HTTP, TCP, TELNET and MCP deception services
  • Extensible plugin system via `CommandPlugin` and `HTTPPlugin` interfaces
  • Full observability: Prometheus metrics and RabbitMQ event streaming

Recent releases

View all 21 releases →
No immediate action
v3.8.0 New feature

Preserve TCP raw bytes

No immediate action
v3.7.3 New feature

validate flag

Review required
v3.7.2 Bug fix
Dependencies

HistoryCleaner leak fix

v3.7.1 New feature
Notable features
  • Add realClientAddr configuration option
  • Improve CLI functionality and increase code coverage
Full changelog

What's Changed

  • Feat: Add realClientAddr by @mariocandela in https://github.com/beelzebub-labs/beelzebub/pull/301
  • Feat: Improve cli and code coverage by @mariocandela in https://github.com/beelzebub-labs/beelzebub/pull/303

Full Changelog: https://github.com/beelzebub-labs/beelzebub/compare/v3.7.0...v3.7.1

v3.7.0 New feature
Notable features
  • Brand new plugin system
  • Redesigned plugin architecture
Full changelog

What's Changed

  • feat: implement brand new plugin system by @mariocandela in https://github.com/beelzebub-labs/beelzebub/pull/294
  • Build(deps): Bump golang.org/x/term from 0.40.0 to 0.42.0 by @dependabot[bot] in https://github.com/beelzebub-labs/beelzebub/pull/297
  • ci: run deploy only on tag by @airscripts in https://github.com/beelzebub-labs/beelzebub/pull/299

New Contributors

  • @airscripts made their first contribution in https://github.com/beelzebub-labs/beelzebub/pull/299

Full Changelog: https://github.com/beelzebub-labs/beelzebub/compare/v3.6.10...v3.7.0

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
2,030
Forks
198
Languages
Go Go Template Makefile

Install & Platforms

Install via
docker-compose go helm

Beta — feedback welcome: [email protected]