Skip to content

Beelzebub (UHBS multi-protocol proof)

Status: Informative · evaluation proof
Upstream: https://github.com/beelzebub-labs/beelzebub · commit 80e1428d023d564481acede9e63eb49e1631bfec
Scope: Every UHBS-native protocol plugin that the lab container exposed was graded separately (quick + full).

Protocol Class / port Quick Full
HTTP Web-API · HTTP :8080 52.77 / D 66.02 / D
Redis Low-Interaction · Redis :6379 50.56 / D 61.01 / D
SSH Low-Interaction · SSH :2222 74.45 / C 59.88 / D
Telnet Low-Interaction · Telnet :23 39.16 / F 47.89 / F
MCP Web-API (MCP v1) · :8000 43.04 / F 42.93 / F

Named product is evaluation proof only — not a UHBS endorsement.

What this decoy is

Multi-protocol honeypot including SSH/HTTP/Telnet/Redis and MCP surfaces in UHBS labs.

For CTI analysts

  • Protocol mix supports correlating the same source IP across SSH and HTTP/MCP lures.
  • MCP grades are about decoy tool/JSON-RPC behavior — not endorsement of AI gateway products.

Primary signals: Per-protocol sessions; MCP tool/list and JSON-RPC exchanges when enabled.

For blue teams / detection engineering

  • Enable only needed listeners; review MCP tool allowlists carefully.
  • Use per-protocol report hubs when tuning detections.

Trust & limitations

  • Evaluation proof under UHBS 4.2.2 — not a certification or endorsement.
  • Prefer full/ over quick/ for decisions.
  • Reading guide: READING-UHQS.md.