~3m17:09Deploying an AI Honeypot with Beelzebub + OpenAI – Stop Attackers Smarter
Sep 29, 2025
Read: ~3m · You save: 14 min
Deploying an AI Honeypot with Beelzebub + OpenAI – Stop Attackers Smarter
Deploy an AI-powered honeypot with Beelzebub & OpenAI! Learn to lure attackers, simulate realistic behavior, and integrate logs with Wazu.
A novel honeypot solution, Beelzebub, has emerged, offering enhanced capabilities through integration with Artificial Intelligence (AI) and Large Language Models (LLMs), such as OpenAI. This approach allows honeypots to simulate more dynamic and realistic attacker interactions compared to traditional static responses. This article details the deployment of Beelzebub via Docker, its configuration, and integration with a Security Information and Event Management (SIEM) system for enhanced threat intelligence.
Understanding Honeypots and Beelzebub's AI Integration
A honeypot is a decoy system designed to attract and trap cyber attackers, enabling security professionals to observe their methods and gather intelligence without risking actual assets. Beelzebub distinguishes itself by supporting AI/LLM integration. Instead of relying on pre-scripted responses, it can connect to LLMs like OpenAI, allowing it to generate more intelligent and context-aware replies to simulated attacks. This dynamic response mechanism makes the honeypot a more convincing target for attackers.
Deployment via Docker
The deployment process for Beelzebub is demonstrated using Docker, which is presented as the most straightforward method for initial setup.
- Prerequisites: Ensure Docker is installed and running on the host system.
- Cloning the Repository: Navigate to the desired directory and clone the Beelzebub repository:
git clone <repository_url> cd beelzebub - Building the Docker Image: Beelzebub does not currently provide a public Docker image. Therefore, the image must be built locally:
docker compose build
Configuration and Services
Beelzebub utilizes YAML files for configuring various honeypot services, making customization user-friendly.
- Service Configuration: The
configuration/servicesdirectory contains YAML files that define different honeypot services. Examples include:- An MQTT server.
- A web server simulating WordPress over HTTP.
- A MySQL server on port 3306.
- An SSH server on port 2222.
- AI/LLM Integration: Beelzebub supports LLM providers, including OpenAI and local models like Ollama. This integration is configured within the service YAML files.
- Custom Prompts: Users can define custom prompts for the LLM. These prompts guide the AI's responses, allowing for specific instructions on how to format replies based on attacker input and the simulated terminal environment. For example, a prompt might instruct the LLM to act as a Linux terminal and enclose responses within a single code block.
- SSH Configuration Example: For the SSH service (port 2222), the configuration involves specifying:
- The LLM provider (e.g., OpenAI).
- The OpenAI API key.
- A custom prompt for the LLM.
- Valid passwords for root login (e.g., "root").
- Customizable server names and SSH versions.
Launching and Testing the Honeypot
After configuring the services, the Beelzebub honeypot can be launched using Docker Compose.
- Launching:
docker compose up -d- Port Conflict Resolution: If an error occurs due to port 22 being in use (typically by the host's SSH service), the port entry for SSH in the
docker-compose.ymlfile needs to be removed or modified. The Beelzebub SSH honeypot is configured to run on port 2222 by default.
- Port Conflict Resolution: If an error occurs due to port 22 being in use (typically by the host's SSH service), the port entry for SSH in the
- Monitoring Logs: Container logs can be followed using:
docker logs <container_id> -f - Connecting to the Honeypot: An SSH client can connect to the honeypot using the configured port (e.g.,
ssh root@<host_ip> -p 2222). - Simulating Attacks: Once connected, commands can be executed. These commands, along with the LLM's responses, are logged. The LLM can maintain session state, remembering previously created files or executed commands. For instance, creating a file (
test.txt) and then listing its contents will show the LLM's awareness of the file's existence and content.
Integrating with WAZU for Log Management
While Beelzebub captures logs, their direct analysis can be challenging. Integrating with a SIEM like WAZU enhances log management and analysis.
- Configuring Log Output:
- Edit the
configuration/bellsabove.yamlfile to specify a log file path for JSON logs. - Update the
docker-compose.ymlfile to mount this log directory as a volume to the host system. - Ensure the log directory is created on the host (
mkdir logs).
- Edit the
- Restarting Beelzebub: After configuring log output and volumes, restart Beelzebub using
docker compose up -d. - WAZU Agent Configuration:
- Log into the WAZU manager.
- Navigate to Endpoint Groups and modify the relevant group (e.g., "Linux Lab").
- In the Local File section, configure the WAZU agent to read JSON logs from the specified Beelzebub log file path. The configuration should specify
log_format=json.
- Creating WAZU Detection Rules:
- A new detection rule needs to be created in WAZU to capture Beelzebub events. A basic rule can be added to the WAZU rules repository, specifically targeting "SSH terminal session interaction."
- This rule should be added to the WAZU manager.
- Restart the WAZU agent on the endpoint.
Security Considerations and Further Development
- OpenAI API Costs: Utilizing OpenAI's API incurs costs. If the honeypot is exposed publicly and receives a high volume of requests, it could lead to significant expenses.
- Rule Customization: The provided WAZU rule is basic and primarily captures SSH interactions. For comprehensive monitoring, rules need to be developed to cover other simulated services (e.g., web traffic).
- Contribution: Users are encouraged to contribute to the WAZU rules repository with new detection rules.
Beelzebub offers a powerful and customizable honeypot solution, particularly with its AI integration. It can be deployed internally to detect malicious insiders or externally to gather intelligence on attacker methodologies. The ability to customize services and integrate with LLMs provides a sophisticated layer of realism to the honeypot's behavior.
Introduction to Beelzebub and Honeypots
Introduction to honeypots and the Beelzebub tool, highlighting its AI/LLM support for dynamic responses, contrasting it with static honeypots.
- Honeypots are decoy systems designed to lure and observe attackers.
- Beelzebub (Bellub) is a new honeypot with AI/LLM support.
- AI integration allows for more realistic and dynamic attacker interaction.
- The tutorial focuses on deploying Beelzebub via Docker.
Installation and Initial Setup via Docker
Step-by-step guide to installing Beelzebub using Docker, including cloning the repository, building the Docker image, and understanding the configuration files.
- Prerequisites: Docker installed and running.
- Clone the Beelzebub repository.
- Build the Docker image using
docker compose buildas there's no public image. - Configuration is managed via YAML files in the
configuration/servicesdirectory. - Supports various services like MCP, WordPress (HTTP), Apache (HTTP), SSH, and MySQL.
Configuring SSH with OpenAI Integration
Detailed configuration of the SSH service with OpenAI integration, including setting API keys, custom prompts for AI responses, and understanding the role of YAML files.
- SSH service configured on port 2222.
- Integration with OpenAI requires an API key.
- Custom prompts can guide the LLM's responses, making them more specific.
- Example prompt: 'You act as a human. You move to Linux terminal... Your responses must be contained within a single code block.'
- Supports other LLM providers like Ollama for local models.
Launching and Troubleshooting Beelzebub
Troubleshooting and launching the Beelzebub honeypot, addressing port conflicts and successfully starting the Docker containers.
- Initial launch error due to port 22 being in use by the SSH session.
- Solution: Modify
docker-compose.ymlto remove the conflicting port entry. - Successful launch using
docker compose up -d. - Verification using
docker psanddocker logs -f. - Beelzebub simulates services like WordPress (port 80), Apache (port 8080), SSH (port 2222), and MySQL (port 3306).
Simulating Attacks and AI Interaction
Demonstration of Beelzebub's functionality, including SSH login with custom credentials, capturing commands, and how the AI LLM processes and responds to them.
- SSH service allows login with default credentials (e.g., root/root).
- Commands entered by the attacker are logged.
- LLM (OpenAI) processes commands and generates responses, simulating realistic terminal output.
- The LLM maintains context, remembering created files (e.g., test.txt).
- Examples of captured commands:
who am I,ls,name ls,etc,wget malware.sh.
Log Integration with Wazu SIEM
Integrating Beelzebub logs with Wazu for centralized security monitoring, including configuring log file output and setting up the Wazu agent.
- Beelzebub logs are in JSON format, suitable for Wazu.
- Configure Beelzebub to write logs to a file (
bells_above.log) viabells_above.yaml. - Mount the log directory as a volume in
docker-compose.yml. - Configure the Wazu agent to collect JSON logs from the specified path.
- Create a Wazu detection rule to capture Beelzebub events (e.g., SSH terminal session interaction).
Customization, Benefits, and Considerations
Discussion on the customization, benefits, and potential costs of using Beelzebub with AI, and its applications in internal and external threat detection.
- Beelzebub offers high customization through YAML files.
- Can be used internally to detect malicious insiders or publicly to gather external threat intelligence.
- Warning: Using OpenAI API incurs costs based on usage.
- The tool is powerful for understanding attacker behavior and probing.
- Beelzebub is a valuable, customizable, and powerful honeypot solution.