fleet-wide distributed honeypot mesh built on Hyperswarm and HyperDB
# Website: https://honeypeer.com
Today I am announcing the **public Alpha** of [**HoneyPeer**](https://honeypeer.com) — operated by **HoneyPeer, LLC**, a Georgia limited liability company formed in DeKalb County. After years of R&D and a full year of building, testing, and hardening a peer-to-peer honeypot platform from the ground up, I am inviting operators, homelab enthusiasts, and security-minded teams to join the mesh **at no cost** while I finish the product for general availability.
This is not a slide-deck honeypot. HoneyPeer is a **running system**: subscription-gated peers, a coordinator that ingests real attack telemetry, a detection engine that promotes IPs through reputation tiers, and **fleet-wide kernel firewall sync** so one probe anywhere can protect everyone. If you have ever wanted collective immunity against internet background radiation — SSH brute force, Redis scans, SMTP probes, credential stuffing against fake admin panels — this is what I built it for.
## The problem I set out to solve
Every server on the public internet is scanned constantly. Most of that traffic is automated: botnets mapping open ports, exploit kits checking for default credentials, and opportunistic attackers looking for the next foothold. Traditional defenses — perimeter firewalls, WAFs, rate limits — help, but they are **local**. Your blocklist does not automatically become your neighbor's blocklist. Your honeypot findings sit in a CSV until someone manually imports them.
HoneyPeer flips the model:
1. **Decoys attract** high-signal probes on real protocol handlers (SSH, HTTP, SMTP, databases, and more).
2. **Peers report** structured telemetry upstream over encrypted P2P transport.
3. **The coordinator scores** source IPs with sliding windows, reputation tiers, and subnet co-conspirator detection.
4. **Blocks replicate** through HyperDB to every licensed node and apply in the **kernel** (nftables, ipset, iptables, or macOS `pf`).
One attack seen anywhere can protect the entire fleet — often in under a second from report to fanout.
```mermaid
flowchart LR
subgraph internet [Internet scanners]
A[Attacker]
end
subgraph peer [Your peer]
H[Honeypots]
FW[Kernel firewall]
P[Embedded panel]
end
subgraph mesh [HoneyPeer mesh]
M[Coordinator]
DET[Detection engine]
DB[(HyperDB)]
end
A --> H
H -->|attack report| M
M --> DET
DET -->|block tier| DB
DB -->|replicate| FW
M -->|banIp fanout| FW
P --> H
```
## What HoneyPeer is (and what it is not)
**HoneyPeer is:**
- A **distributed honeypot SaaS** where each subscriber runs one or more **peer nodes** on infrastructure they control.
- A **Hyperswarm mesh** connecting licensed peers to a coordinator (master) for registration, attack ingest, block snapshots, and database replication.
- A **Bare-runtime peer binary** (single-file, cross-platform) with 25+ protocol-accurate honeypot listeners and an embedded operator panel.
- A **privacy-conscious** platform: marketing pages do not load third-party analytics; sensitive billing data stays in a master-local database that **never replicates** to peers.
**HoneyPeer is not:**
- A managed cloud honeypot you point DNS at (you run the peer).
- A replacement for your production WAF or IDS (it complements them with **shared threat signal**).
- A guarantee of zero false positives (tune detection via env vars; whitelist trusted IPs on each peer).
## Architecture at a glance
HoneyPeer-NG splits cleanly into three layers:
| Layer | Component | Role |
|-------|-----------|------|
| **Edge** | Peer honeypots | Listen on curated TCP/UDP ports; log interactions; optional tarpit |
| **Transport** | Hyperswarm + Protomux | Encrypted P2P: register, report attacks, replicate HyperDB, push `banIp` |
| **Control** | Master coordinator | Writable network DB, detection engine, Stripe licensing, admin UI |
### Two databases by design
Security and billing requirements forced a hard split:
| Database | Replicates to peers? | Contents |
|----------|----------------------|----------|
| **Network-replicated** | Yes | Attacks, IP blocks, peer blocks, peers, subscription metadata (non-sensitive) |
| **Local-customer** | **Never** | Sales, license keypairs, customer emails, Stripe IDs |
Your peer receives enough data to enforce blocks and prove subscription status. It never receives another customer's keypair or payment details.
### Ports you will interact with
| Surface | Default port | Purpose |
|---------|--------------|---------|
| Peer panel | 8888 | Local honeypot + firewall control on each node |
## Honeypots: high-signal decoys, not generic banners
Each peer ships a **registry of protocol handlers** implemented on the [Bare](https://github.com/holepunchto/bare) runtime — the same stack powering modern Holepunch peer infrastructure. Handlers speak enough of the real protocol to keep scanners engaged and produce rich `interactionData` for the detection pipeline.
Default known slots include:
| Port | Service | Port | Service |
|------|---------|------|---------|
| 22 | SSH | 443 | HTTPS |
| 23 | Telnet | 445 | SMB banner |
| 25 | SMTP | 1433 | MSSQL |
| 53 | DNS (UDP) | 1521 | Oracle TNS |
| 80 / 8080 | HTTP | 3306 | MySQL |
| 161 | SNMP | 3389 | RDP |
| 389 | LDAP | 5432 | PostgreSQL |
| — | — | 6379 | Redis (interactive RESP) |
| — | — | 27017 | MongoDB wire |
| — | — | 6443 | Kubernetes API |
| — | — | 9200 | Elasticsearch |
Peers also spin up **random high ports** with Iighted novel handlers and optional **tarpit** mode to slow scanners. Deception profiles, canary credentials, and HTTP personality switches let you tune how aggressive the fiction is — without npm protocol libraries on the hot path.
## From probe to fleet-wide block
Here is the attack lifecycle in plain language:
1. **Probe** — An IP connects to e.g. SSH :22 on your peer. The handler accepts, logs metadata, and may record credential attempts.
2. **Report** — The peer packages a structured attack record and sends it to the coordinator over the swarm link.
3. **Score** — Detection windows update IP reputation. Greylist tiers accumulate signal; **block** tier persists a global ban and triggers fanout.
4. **Replicate** — HyperDB pushes the block to every licensed peer's read-only replica.
5. **Enforce** — Each peer applies the ban in its kernel firewall backend. Whitelist entries always win.
Subnet **co-conspirator** logic groups activity from the same /24, so coordinated scan waves surface as related clusters in the dashboard — not isolated one-off events.
```mermaid
sequenceDiagram
participant S as Scanner
participant P as Peer honeypot
participant M as Coordinator
participant D as Detection
participant F as Fleet peers
S->>P: TCP probe / login attempt
P->>M: attack-report (Protomux)
M->>D: ingest + score IP
D->>M: promote to block tier
M->>F: banIp + HyperDB replicate
F->>F: nftables / pf apply
```
## Alpha program: free fleet access while I ship
**Alpha is open now.** I want real networks, real noise, and real feedback — not lab-only simulations.
| | Alpha (today) | Launch (forecast) |
|---|---------------|-------------------|
| **Price** | **$0.00/month** — any seat count 1–50 | From **$4.99/node/month** with volume discounts |
| **Features** | Full mesh: honeypots, detection, blocks, panel, viz | Same core platform |
| **Checkout** | Stripe **Test mode** (sandbox) | Stripe Live |
| **Keypairs** | One Noise keypair per seat, provisioned at checkout | Same licensing model |
### What Alpha checkout does
1. You choose **single-node** or **multi-node** (2–50 peers) on the [pricing page](https://honeypeer.com/pricing).
2. Stripe Hosted Checkout runs in **test mode** — use test card patterns only; do not enter real payment details during Alpha.
3. On success you receive a **subscription record** and downloadable **peer keypair(s)** — one per seat.
4. You download the peer binary for your platform and connect to the mesh.
**Important:** Sandbox subscriptions **do not carry over** to Stripe Live at launch. When paid billing begins, you will complete a **fresh checkout on the live network**. I will announce pricing in advance and give Alpha participants reasonable notice before any charge. Your Alpha keypairs remain valid during the free period.
Legal details: [Terms of Service — Alpha](https://honeypeer.com/legal/terms#alpha) · [Privacy Policy](https://honeypeer.com/legal/privacy) · [Peer EULA](https://honeypeer.com/legal/peer-eula).
## Getting started in four steps
```mermaid
flowchart TD
A[Visit honeypeer.com/pricing] --> B[Alpha checkout — pick seats]
B --> C[Download keypair + peer binary]
C --> D[Run peer with keypair]
D --> E[Open local panel :8888]
E --> F[Watch attacks on viz.honeypeer.com]
```
### Step 1 — Claim your Alpha license
Go to **[honeypeer.com/pricing](https://honeypeer.com/pricing)** and start checkout. Multi-node subscriptions provision **one keypair per seat** so each peer has a distinct identity in the mesh.
### Step 2 — Download the peer
Prebuilt single-file binaries ship for:
| Platform | Artifact |
|----------|----------|
| Linux x64 / arm64 | `honeypeer-peer-linux-*` |
| macOS (universal) | `honeypeer-peer-macos-universal` |
| Windows x64 / arm64 | `honeypeer-peer-windows-*.exe` |
Downloads: **[honeypeer.com/download](https://honeypeer.com/download)** and the [latest release](https://git.ssh.surf/snxraven/honeypeer-releases/releases/tag/latest) mirror.
### Step 3 — Run the peer
```bash
chmod +x honeypeer-peer-linux-x64
./honeypeer-peer-linux-x64 --keypair /path/to/your-keypair.json
```
Use **sudo** (or `CAP_NET_ADMIN` + `CAP_NET_RAW`) when you want kernel firewall enforcement. The embedded panel defaults to **http://localhost:8888**.
Peer configuration reference: [docs/peer/installation](https://docs.honeypeer.com/peer/installation) (operator docs).
### Step 4 — Observe the mesh
- **Live network map:** [viz.honeypeer.com](https://viz.honeypeer.com) — public attack activity (IPs cloaked for privacy).
- **Threat blog:** AI-assisted briefings on patterns I observe fleet-wide.
- **Discord:** [join.honeypeer.com](https://join.honeypeer.com) — community support and operator chat.
## Operator surfaces beyond the peer panel
HoneyPeer is a full operator platform, not just a background daemon.
### Customer support portal (`support.honeypeer.com`)
Subscribers can open tickets, browse docs, and manage their relationship with the operator without accessing the admin dashboard.
### Documentation (`docs.honeypeer.com`)
Installation, peer firewall backends, honeypot handler matrix, API reference, and architecture deep-dives for anyone self-hosting or auditing the stack.
## Built on peer-to-peer infrastructure
HoneyPeer stands on the Holepunch ecosystem:
- **Hyperswarm** for topic discovery and NAT-friendly connections
- **HyperDB / Hypercore** for replicated, append-only network state
- **Bare** for a lightIight peer runtime without Node.js on the edge
- **Protomux** for typed channels betIen coordinator and peers
I believe defensive tooling should inherit the same resilience properties as the open internet: no single vendor choke point, encrypted transport by default, and peers that can enforce policy even when they are only loosely coupled to the coordinator.
## Security and privacy commitments
- **Subscription-gated mesh** — only licensed keypairs register; peer public-key blocks can eject abusive nodes at the Hyperswarm firewall layer.
- **Split data plane** — billing secrets never replicate.
- **No third-party analytics** on marketing pages.
- **Whitelist wins** — your trusted IPs are never kernel-blocked by global bans.
## What I am looking for during Alpha
I am especially interested in feedback on:
- **Detection tuning** — false positives, missed scans, tier promotion timing
- **Firewall backends** — nftables vs ipset vs pf on your OS images
- **Honeypot fidelity** — protocols that attract noise but lack handler depth
- **Fleet scale** — replication lag and fanout behavior past dozens of peers
- **Operator UX** — dashboard workflows, docs gaps, checkout confusion
File issues, open support tickets, or talk to us on Discord. This mesh gets better when real operators stress it.
## A note on the company
**HoneyPeer, LLC** is a Georgia limited liability company formed in **DeKalb County, Georgia, United States**. I build and operate the HoneyPeer network as the licensor under our [Peer End User License Agreement](https://honeypeer.com/legal/peer-eula). Copyright © 2026 HoneyPeer, LLC.
## Join the Alpha today
If you operate servers, a homelab, or a small fleet that touches the public internet, you are already paying the "background radiation tax" in log noise and firewall rules. HoneyPeer lets you **convert that noise into shared immunity**.
**[Get free Alpha access →](https://honeypeer.com/pricing)**
Questions? **[support.honeypeer.com](https://support.honeypeer.com)** · **[join.honeypeer.com](https://join.honeypeer.com)** · **[docs.honeypeer.com](https://docs.honeypeer.com)**
---
*HoneyPeer Alpha is pre-release software. Features, pricing, and terms may change before general availability. Honeypots intentionally attract malicious traffic — deploy only on infrastructure you control and isolate appropriately.*