UHBS lab reports (evaluation proof)¶
Status: Informative
Purpose: Published, reproducible UHBS-Lab outputs for named honeypots / decoys so the community can audit, replicate, and compare grades — not so UHBS can endorse products.
UHBS is an open-source evaluation framework (v4.5.1).
Named products appear only underdocs/conformance/as evaluation proof.
A grade is not a certification, badge program, or consortium verdict.
How to use this directory¶
New here? Read How to read UHBS lab proof (CTI & blue team) before comparing grades.
- Open a honeypot folder (for example
espot/). - Read the tutorial (exact commands we ran).
- Compare
quick/vsfull/artifacts (scorecards,report.json, logs, SAST). - Recompute UHQS yourself with
uhbs validate-scorecard/uhbs score. - Optionally re-run the same Docker lab against a live target.
Index of published reports¶
| Honeypot (proof label) | Class | Protocol | Quick UHQS | Full UHQS | Tutorial |
|---|---|---|---|---|---|
| ESPot (mycert) | Web-API | HTTP :9200 |
49.34 / F | 63.33 / D | Step-by-step |
| miniprint (sa7mon) | Low-Interaction | PJL/raw :9100 |
41.83 / F | 50.43 / D | Step-by-step |
| Conpot (mushorg) | ICS-SCADA | Modbus :5020 |
44.55 / F | 55.4 / D | Step-by-step |
| Cowrie | Low-Interaction | SSH :2222 + Telnet :2223 (SFTP via SSH) |
see hub | see hub | Step-by-step |
| LLM Honeypot (Palisade) | Low-Interaction | SSH :2222 (Telnet off) |
67.94 / D | 61.17 / D | Step-by-step |
| HoneyAgents | Low-Interaction | SSH :2222 (Telnet mapped, not enabled) |
67.94 / D | 65.24 / D | Step-by-step |
| LLMPot (momalab) | multi | Modbus :5020 / S7comm :102 / HTTP :8080 |
see hub | see hub | Step-by-step |
| DataTrap (Thales) | multi | SSH / HTTP / MySQL / Redis / Telnet / PostgreSQL | see hub | see hub | Step-by-step |
| Endlessh (skeeto) | Low-Interaction | ssh_tarpit :2222 |
46.55 / F | 54.07 / D | Step-by-step |
| OpenCanary (thinkst) | multi | HTTP / FTP / SSH / Telnet / Redis / MySQL / RDP / SIP / SNMP / NTP / TFTP / VNC / Git / SMB | see hub | see hub | Step-by-step |
| Beelzebub | multi | SSH / HTTP / Telnet / Redis / MCP | see hub | see hub | Step-by-step |
| HoneyMCP | Web-API | MCP :8080 |
43.04 / F | 42.93 / F | Step-by-step |
| GenAIPot (ls1911) | Low-Interaction | SMTP :25 + POP3 :110 |
see hub | see hub | Step-by-step |
| Elastichoney | Web-API | HTTP ES :9200 |
45.84 / F | 45.73 / F | Step-by-step |
| honeypot-ftp (alexbredo) | Low-Interaction | FTP :21 |
42.71 / F | 42.6 / F | Step-by-step |
| qeeqbox/honeypots | multi | SSH/HTTP/FTP/Telnet/SMTP/POP3/MySQL/Postgres/Redis/VNC | see hub | see hub | Step-by-step |
| SentryPeer | Low-Interaction | SIP :5060 |
41.09 / F | 40.98 / F | Step-by-step |
| wordpot | Web-API | HTTP :8080 |
41.71 / F | 41.6 / F | Step-by-step |
| MockSSH | Low-Interaction | SSH :2222 |
59.2 / D | 59.0 / D | Step-by-step |
| Heralding | Low-Interaction | SSH :22 + FTP :21 |
see hub | see hub | Step-by-step |
| HoneyHTTPD | Web-API | HTTP :8080 |
45.84 / F | 45.73 / F | Step-by-step |
| SHIVA | Low-Interaction | SMTP :2525 |
45.07 / F | 44.96 / F | Step-by-step |
| Acra (skipped) | — | DB proxy / poison records (not a protocol honeypot) | — | — | Note |
| ssh-honeypot / droberson (skipped) | — | SSH (Docker base image unavailable) | — | — | Note |
| Ensnare (skipped) | — | Rails gem HTTP traps (not standalone) | — | — | Note |
| snare (skipped) | — | Needs Tanner + page clone | — | — | Note |
| Trapster Community | multi | SSH / HTTP / FTP / Telnet | see hub | see hub | Step-by-step |
| sshesame | Low-Interaction | SSH | 65.13 / D | 61.06 / D | Step-by-step |
| ssh-auth-logger | Low-Interaction | SSH | 44.38 / F | 44.38 / F | Step-by-step |
| ssh-honeypotd | Low-Interaction | SSH | 44.38 / F | 44.38 / F | Step-by-step |
| HellPot | Web-API | HTTP | 43.98 / F | 43.87 / F | Step-by-step |
| HoneyWire | Web-API | HTTP (WebRouterDecoy) | 45.84 / F | 45.84 / F | Step-by-step |
| express-honeypot | Web-API | HTTP | 45.84 / F | 45.73 / F | Step-by-step |
| mailoney | Low-Interaction | SMTP | 38.8 / F | 38.69 / F | Step-by-step |
| pghoney | Low-Interaction | PostgreSQL | 43.72 / F | 43.61 / F | Step-by-step |
| mysql-honeypotd | Low-Interaction | MySQL | 40.35 / F | 37.94 / F | Step-by-step |
| Log4Pot | Web-API | HTTP | 41.71 / F | 38.0 / F | Step-by-step |
| node-ftp-honeypot | Low-Interaction | FTP | 35.96 / F | 35.85 / F | Step-by-step |
| SentryPeer | Low-Interaction | SIP | 43.38 / F | 43.38 / F | Step-by-step |
| wordpot | Web-API | HTTP | 41.71 / F | 41.6 / F | Step-by-step |
| MockSSH | Low-Interaction | SSH | 59.2 / F | 59.0 / F | Step-by-step |
| Heralding | Low-Interaction | SSH + FTP | see hub | see hub | Step-by-step |
| HoneyHTTPD | Web-API | HTTP | 45.84 / F | 45.73 / F | Step-by-step |
| SHIVA | Low-Interaction | SMTP | 45.07 / F | 44.96 / F | Step-by-step |
| awesome-honeypots triage | — | grade_now / skip / deferred | — | — | Deferred protocols |
| Dionaea | multi | FTP / HTTP / SMB | see hub | see hub | Step-by-step |
Directory layout (per honeypot)¶
docs/conformance/reports/<honeypot>/
├── index.md # Summary, trust notes, links
├── TUTORIAL.md # Step-by-step replication
├── METHODOLOGY.md # Environment, versions, limitations
├── quick/ # UHBS_QUICK=1 / lighter Module E / often SAST skipped
│ ├── SCORECARD.txt
│ ├── report.json
│ ├── MANIFEST.json
│ ├── uhbs-run.log
│ └── run-meta.json
└── full/ # Formal TPS (e.g. 1000-sample A3), telemetry, SAST
├── SCORECARD.txt
├── report.json
├── MANIFEST.json
├── uhbs-run.log
├── run-meta.json
└── static/ # bandit / semgrep / … when enabled
Quick vs full (read this before comparing grades)¶
| quick/ | full/ | |
|---|---|---|
| Intent | Smoke / CI-speed demo | Most realistic grade the harness can produce in Docker |
UHBS_QUICK |
usually 1 |
unset |
| Module A timing | shortened (≤50) | formal (often 1000 samples) |
| RFC probes | yes | yes (strict_rfc_enforcement) |
| Source / Module F | optional | required (source-root) |
| SAST | often --skip-sast-tools |
bandit / semgrep (+ trivy when available) |
| Telemetry dir | often unset (optimistic C) | mounted real logs |
| Safety Gate | may be partial / attested | stricter evidence (gateway log, honest HTTP-only D) |
Do not treat a quick UHQS as production-ready evaluation. Prefer full/ for claims; use quick/ to show the pipeline works.
Trust & verification checklist¶
For every published run we aim to ship:
- [x] Human scorecard (
SCORECARD.txt) - [x] Machine report (
report.json) with per-check evidence - [x] SHA-256
MANIFEST.jsonover artifacts - [x] Console transcript (
uhbs-run.log) - [x] Provenance (
run-meta.json: UHBS version, image digests, dates, flags) - [x] Replication tutorial with exact commands
- [x] Explicit limitations (what was attested vs measured)
Verify locally:
# Integrity of the sanitized fixture (full ESPot)
uhbs validate-scorecard docs/conformance/fixtures/espot-web-api.scorecard.json --strict
# Spot-check manifest hashes for a published run
python - <<'PY'
import hashlib, json
from pathlib import Path
root = Path("docs/conformance/reports/espot/full")
man = json.loads((root / "MANIFEST.json").read_text())
for art in man["artifacts"]:
p = root / art["path"]
if not p.is_file():
print("MISSING", art["path"]); continue
h = hashlib.sha256(p.read_bytes()).hexdigest()
ok = h == art["sha256"]
print(("OK" if ok else "MISMATCH"), art["path"])
PY
Adding another honeypot report¶
- Create
docs/conformance/reports/<id>/withquick/andfull/. - Capture artifacts via
uhbs lab … --out docs/conformance/reports/<id>/<mode>. - Write
TUTORIAL.md+METHODOLOGY.md+run-meta.json. - Link the row in this index and in
../index.md. - Optionally add a sanitized fixture under
../fixtures/.