Skip to content

Official Benchmark Scorecards

Auditors must publish results using the standard scorecard layout validated by schemas/scorecard.schema.json.

UHBS is vendor-neutral: decoy classes and protocols are the normative vocabulary. Named products appear only as evaluation proof (not requirements or endorsements).

Full artifacts (tutorials, methodology, SCORECARD.txt, report.json) live under Conformance lab reports.

CTI & blue team: start with How to read UHBS lab proof. Each scorecard page includes a module interpretation table (what A–F mean for sensors vs tarpits vs credential sinks).

Published scorecards (all)

Scorecard Class / protocol Full UHQS Grade
OpenCanary — FTP OpenCanary — FTP 61.5 D
OpenCanary — GIT OpenCanary — GIT 62.96 D
OpenCanary — HTTP OpenCanary — HTTP 66.02 D
OpenCanary — MYSQL OpenCanary — MYSQL 62.96 D
OpenCanary — NTP OpenCanary — NTP 47.42 F
OpenCanary — RDP OpenCanary — RDP 61.01 D
OpenCanary — REDIS OpenCanary — REDIS 53.72 D
OpenCanary — SIP OpenCanary — SIP 46.44 F
OpenCanary — SMB OpenCanary — SMB 57.72 D
OpenCanary — SNMP OpenCanary — SNMP 47.42 F
OpenCanary — SSH OpenCanary — SSH 35.64 F
OpenCanary — TELNET OpenCanary — TELNET 64.9 D
OpenCanary — TFTP OpenCanary — TFTP 47.42 F
OpenCanary — VNC OpenCanary — VNC 61.99 D
Beelzebub — HTTP :8080 Web-API · HTTP 66.02 D
Beelzebub — MCP :8000 Web-API (MCP v1) · MCP 42.93 F
Beelzebub — Redis :6379 Low-Interaction · Redis 61.01 D
Beelzebub — SSH :2222 Low-Interaction · SSH 59.88 D
Beelzebub — Telnet :23 Low-Interaction · Telnet 47.89 F
Cowrie — SSH :2222 Low-Interaction · SSH 61.37 D
Cowrie — Telnet :2223 Low-Interaction · Telnet 64.9 D
DataTrap — HTTP :8080 Web-API · HTTP 65.85 D
DataTrap — MYSQL :3306 Low-Interaction · MYSQL 50.65 D
DataTrap — PostgreSQL :5432 Low-Interaction · PostgreSQL 57.94 D
DataTrap — REDIS :6379 Low-Interaction · REDIS 60.85 D
DataTrap — SSH :2222 Low-Interaction · SSH 55.61 D
DataTrap — TELNET :2323 Low-Interaction · TELNET 59.88 D
Dionaea — FTP :21 Low-Interaction · FTP 57.96 D
Dionaea — HTTP :80 Web-API · HTTP 51.14 D
Dionaea — SMB :445 Low-Interaction · SMB 54.07 D
elastichoney — http Web-API · http 45.73 F
express-honeypot — http Web-API · http 45.73 F
genaipot — pop3 Low-Interaction · pop3 44.13 F
genaipot — smtp Low-Interaction · smtp 30.78 F
HellPot — http Web-API · http 43.87 F
HoneyWire — http Web-API · http 45.84 F
heralding — ftp Low-Interaction · ftp 35.85 F
heralding — smtp Low-Interaction · smtp 45.07 F
owasp-python-honeypot — http Web-API · http 43.98 F
owa-honeypot — http Web-API · http 41.71 F
honeyup — http Web-API · http 50.91 D
modpot — http Web-API · http 50.91 D
Krawl — http Web-API · http 50.91 D
flux — http Web-API · http 50.91 D
fortigate-vpn-ssl — http Web-API · http 46.78 F
honeytrap — ssh Low-Interaction · ssh 44.38 F
portlurker — generic Low-Interaction · generic 39.84 F
sticky_elephant — postgres Low-Interaction · postgres 38.06 F
kippo — ssh Low-Interaction · ssh 35.64 F
nosqlpot — redis Low-Interaction · redis 40.08 F
pyRDP — rdp Low-Interaction · rdp 33.93 F
Artillery — generic Low-Interaction · generic 37.55 F
heralding — ssh Low-Interaction · ssh 44.18 F
HoneyAgents — SSH :2222 Low-Interaction · SSH 65.24 D
honeyhttpd — http Web-API · http 45.73 F
HoneyMCP — MCP :8080 Web-API (MCP v1) · MCP 42.93 F
honeypot-ftp — ftp Low-Interaction · ftp 42.6 F
ICS-SCADA / Modbus decoy (Conpot proof) Scorecard: ICS-SCADA / Modbus decoy (Conpot proof)
LLM Honeypot (Palisade) — SSH :2222 Low-Interaction · SSH 61.17 D
LLMPot — HTTP (WAGO WBM) :8080 Web-API · HTTP 63.11 D
LLMPot — Modbus TCP :5020 ICS-SCADA · Modbus TCP 55.24 D
LLMPot — S7comm :102 ICS-SCADA · S7comm 65.41 D
Log4Pot — http Web-API · http 38.0 F
Low-Interaction / PJL decoy (miniprint proof) Scorecard: Low-Interaction / PJL decoy (miniprint proof)
Low-Interaction / SSH tarpit (Endlessh proof) Scorecard: Low-Interaction / SSH tarpit (Endlessh proof)
mailoney — smtp Low-Interaction · smtp 38.69 F
mockssh — ssh Low-Interaction · ssh 59.0 D
mysql-honeypotd — mysql Low-Interaction · mysql 37.94 F
node-ftp-honeypot — ftp Low-Interaction · ftp 35.85 F
pghoney — postgres Low-Interaction · postgres 43.61 F
qeeqbox/honeypots — ftp Low-Interaction · ftp 40.31 F
qeeqbox/honeypots — http Web-API · http 45.73 F
qeeqbox/honeypots — mysql Database · mysql 34.27 F
qeeqbox/honeypots — pop3 Low-Interaction · pop3 30.94 F
qeeqbox/honeypots — postgres Database · postgres 34.27 F
qeeqbox/honeypots — redis Low-Interaction · redis 34.5 F
qeeqbox/honeypots — smtp Low-Interaction · smtp 30.78 F
qeeqbox/honeypots — ssh Low-Interaction · ssh 59.68 D
qeeqbox/honeypots — telnet Low-Interaction · telnet 29.77 F
qeeqbox/honeypots — vnc Low-Interaction · vnc 32.81 F
sentrypeer — sip Low-Interaction · sip 43.38 F
shiva — smtp Low-Interaction · smtp 44.96 F
ssh-auth-logger — ssh Low-Interaction · ssh 44.38 F
ssh-honeypotd — ssh Low-Interaction · ssh 44.38 F
sshesame — ssh Low-Interaction · ssh 61.06 D
Trapster Community — FTP :2121 Low-Interaction · FTP 51.78 D
Trapster Community — HTTP :8080 Web-API · HTTP 63.33 D
Trapster Community — SSH :2222 Low-Interaction · SSH 44.38 F
Trapster Community — Telnet :2323 Low-Interaction · Telnet 64.9 D
Web-API / HTTP decoy (ESPot proof) Scorecard: Web-API / HTTP decoy (ESPot proof)
wordpot — http Web-API · http 41.6 F

Synthetic layout sample (not a lab run)

Badge Snippets

After an official evaluation, maintainers can embed:

![UHBS v4.5.1 Grade A](https://img.shields.io/badge/UHBS%20v4.5.1-Grade%20A-brightgreen)
![UHBS v4.5.1 Grade B](https://img.shields.io/badge/UHBS%20v4.5.1-Grade%20B-yellowgreen)
![UHBS v4.5.1 Grade C](https://img.shields.io/badge/UHBS%20v4.5.1-Grade%20C-yellow)
![UHBS v4.5.1 Grade D](https://img.shields.io/badge/UHBS%20v4.5.1-Grade%20D-orange)
![UHBS v4.5.1 Grade F](https://img.shields.io/badge/UHBS%20v4.5.1-Grade%20F-red)

Submitting a Scorecard

  1. Complete a TPS profile.yaml
  2. Run the five-phase audit
  3. Emit a scorecard conforming to the schema
  4. Open a PR or issue using the Profile / Scorecard Submission template

Validate a published fixture locally:

uhbs validate-scorecard docs/conformance/fixtures/espot-web-api.scorecard.json --strict