Is Honeypotter Still the Best Tool for Tracking Scrapers and Bots? or How Effective Is Honeypotter at

16 Replies, 938 Views

"Anyone else using honeypotter for security monitoring? Thoughts?"

Hey folks,

So I’ve been running honeypotter for a few months now to catch sketchy traffic. It’s been solid, but I’m curious—how’s it working for y’all?

Like, does it still catch most of the bots/scrapers, or are there better tools now? I’ve seen a few slip through, but maybe I just need to tweak my setup.

Also, anyone using it alongside other tools? Wondering if it’s worth comboing or if honeypotter’s enough on its own.

Kinda love how low-maintenance it is tho. Just set it and forget it... mostly.

Thoughts? Am I missing something?

(Also, pls no "just use X instead" without explaining why lol.)
Honeypotter’s been a game-changer for me too! I’ve had it running for about a year, and it still catches most of the low-hanging fruit—bots, scrapers, script kiddies.

But yeah, some sneaky stuff slips through. I paired it with fail2ban to block repeat offenders, and that combo works like a charm.

If you’re looking for something extra, maybe check out CrowdSec. It’s like fail2ban but crowdsourced, so you get updates on new threats faster.

Kinda wish honeypotter had more logging options tho.
I’m kinda new to honeypotter, but so far, it’s doing its job. Not perfect, but what is?

Had a few false positives early on, but tweaking the sensitivity helped.

Anyone else notice it struggles with IPv6 traffic? Or is that just me?

For extra layers, I’m using it alongside Suricata. Overkill? Maybe. But I sleep better.
Honeypotter’s great for basic stuff, but if you’re dealing with advanced threats, you might wanna layer it with something like Ossec.

I’ve seen a few bots bypass it lately, especially the ones that rotate IPs like crazy.

Still, for the price (free!), it’s hard to complain. Just don’t rely on it alone if you’re a high-value target.
Man, I love honeypotter’s simplicity. Set it up once and it just... works.

But yeah, it’s not catching everything. I’ve started logging the misses and feeding them into a SIEM (Splunk, in my case). Adds some overhead, but now I get way better visibility.

If you’re not into SIEMs, maybe just add a simple IP blacklist updater?
Wow, thanks for all the insights! Didn’t expect so many replies.

Gonna try the fail2ban combo first—sounds like the easiest win.

Also, the IPv6 thing is interesting. I’ll test it on my GCP setup and see if I can spot the gaps.

Anyone got a link to those community rulesets? Might save me some time tweaking.

And yeah, T-Pot looks cool, but I’m not ready to ditch honeypotter yet. It’s just too easy.
Honeypotter’s decent, but tbh, I switched to T-Pot recently. It’s a whole honeypot suite with way more features.

Not saying honeypotter’s bad—it’s just kinda limited if you’re dealing with sophisticated attacks.

But if you’re happy with it, maybe just add some custom rules? The default ones are a bit outdated.
Anyone else using honeypotter on cloud instances? I’ve had mixed results.

On AWS, it’s golden. But on GCP, some traffic seems to slip past. No idea why.

For extra protection, I’m using Cloudflare’s firewall rules. Not free, but worth it if you’re getting hammered.
Honeypotter’s my go-to for quick and dirty monitoring. It’s not fancy, but it’s reliable.

If you’re seeing gaps, maybe check out the community rulesets? Some folks share custom configs that catch more stuff.

Also, +1 for pairing it with fail2ban. Makes a huge difference.



Users browsing this thread: 1 Guest(s)