Beelzebub (UHBS multi-protocol proof)¶
Status: Informative · evaluation proof
Upstream: https://github.com/beelzebub-labs/beelzebub · commit 80e1428d023d564481acede9e63eb49e1631bfec
Scope: Every UHBS-native protocol plugin that the lab container exposed was graded separately (quick + full).
| Protocol | Class / port | Quick | Full |
|---|---|---|---|
| HTTP | Web-API · HTTP :8080 | 52.77 / D | 66.02 / D |
| Redis | Low-Interaction · Redis :6379 | 50.56 / D | 61.01 / D |
| SSH | Low-Interaction · SSH :2222 | 74.45 / C | 59.88 / D |
| Telnet | Low-Interaction · Telnet :23 | 39.16 / F | 47.89 / F |
| MCP | Web-API (MCP v1) · :8000 | 43.04 / F | 42.93 / F |
Named product is evaluation proof only — not a UHBS endorsement.
What this decoy is¶
Multi-protocol honeypot including SSH/HTTP/Telnet/Redis and MCP surfaces in UHBS labs.
For CTI analysts¶
- Protocol mix supports correlating the same source IP across SSH and HTTP/MCP lures.
- MCP grades are about decoy tool/JSON-RPC behavior — not endorsement of AI gateway products.
Primary signals: Per-protocol sessions; MCP tool/list and JSON-RPC exchanges when enabled.
For blue teams / detection engineering¶
- Enable only needed listeners; review MCP tool allowlists carefully.
- Use per-protocol report hubs when tuning detections.
Trust & limitations¶
- Evaluation proof under UHBS 4.2.2 — not a certification or endorsement.
- Prefer full/ over quick/ for decisions.
- Reading guide: READING-UHQS.md.