Back to OWASP Foundation
GSoC 2026

OWASP Web Application Honeypot - Adaptive Intelligence Platform

The OWASP Web Application Honeypot is the only open community project focused on the HTTP application layer, but it currently sits as a dormant proof-of-concept with an outdated logging format, no fingerprint detection, and no path to push threat data into community platforms like MISP. This proposal evolves it into a production-ready, adaptive, and intelligence-grade platform. The solution is built around 8 interconnected deliverables: 1. Versioned JSON logging schema (v1.0) with GeoIP2 and MITRE ATT&CK enrichment 2. Automated CRS version management via nightly GitHub Actions 3. CRS 4.x honeytrap plugin with hot-reload daemon (no container restart required) 4. Shodan Honeyscore-triggered chameleon engine for automatic persona rotation 5. Vulnerable application fingerprint library with 4 personas (Apache, IIS, phpMyAdmin, WordPress) 6. Multi-region AWS deployment framework using Terraform with centralised Kibana 7. MISP and STIX 2.1 threat intelligence exporters with optional TAXII push 8. Industry segment profiles for education, financial, and general deployments switchable via a single environment variable Each deliverable has measurable success criteria and risk mitigation. Built on prior production work in DICOMHawk, GreedyBear, and IntelOwl where identical problems were already solved. Total effort is 350 hours across 13 weeks.

Project details

Contributor

R1sh0bh

Mentors

Not available

Technologies

Not listed in the archive