Partner Tool
Share:

HFish

Free, open-source honeypot platform — 40+ deception environments, one console, native ThreatBook intelligence

Opens at hfish.net — external site, RECATOOLS doesn't host this tool.
Free tier available No signup to test APAC-based vendor
HFish logo
40+
Honeypot environments
4,000+
Companies deployed
Free
Open source · node limit lifted
Go
Cross-platform, multi-arch
What it does

Built for the agent-skills supply chain

HFish plants convincing fake services across your network so any interaction is a high-signal alert. 40+ honeypot environments, a central management console, and native ThreatBook intelligence — free and open source.

40+ honeypot environments

HTTP/S web traps, SSH, Telnet, FTP, SFTP, MySQL, Redis and more — with deep, customisable honeybait that blends into your real environment.

Management + node architecture

A B/S management console generates and controls lightweight nodes, then receives, analyses and displays everything the traps capture.

Intranet compromise detection

Honeypots on internal networks catch lateral movement early — a probing attacker or compromised host lights one up instantly.

Source traceability

A built-in, on-demand counter-attribution module helps trace and attribute the source of an attack — active defence most free honeypots lack.

Native ThreatBook intelligence

Free HFish.net honeypot intelligence base plus native integration with ThreatBook TIP — honeypot hits are enriched against real threat intel.

Free, open source, one-click

Golang, cross-platform and multi-architecture. Mixed deployment across physical, VM, cloud and IoT. Community edition node limit lifted.

Advertisement
After features · AD-W1 Responsive · Post-feature engagement
Detection Pipeline

How an HFish detection flows

A honeypot has no legitimate purpose, so any interaction is suspicious by definition — which is why these alerts carry almost no false positives.

STAGE 1
Deploy nodes
One-click install lightweight nodes across intranet + perimeter
STAGE 2
Stand up traps
Nodes run 40+ honeypot services — web, SSH, DB, FTP and more
STAGE 3
Attacker probes
A scanner or compromised host touches a honeypot service
STAGE 4
Capture interaction
Node records source IP, payloads, and behaviour; reports to management
STAGE 5
Enrich + alert
Source checked against ThreatBook intelligence; high-confidence alert raised
STAGE 6
Trace + respond
Traceability module attributes the attacker; the event becomes intelligence
Deployment

Three ways to get it running

Mode 02

With HFish.net intelligence

Enable free access to the HFish.net honeypot intelligence base to enrich captured attack sources.

  • Free honeypot intelligence base
  • Cloud real-time detection push
  • Customisable detection features
Mode 03

Native ThreatBook TIP

Optionally integrate with ThreatBook's Threat Intelligence Platform for deeper enrichment and attribution.

  • Native TIP integration
  • Verdict + APT context on hits
  • Feeds a wider SecOps ecosystem
Advertisement
After deployment · AD-W2 Responsive
Real catches

What it has found in the wild

Intranet compromise detection
Internal honeypots catch lateral movement early — a probing attacker or compromised host lights one up the instant it is touched.
External threat perception
Internet-facing honeypots reveal who is scanning and attacking your perimeter, and exactly how they are doing it.
Threat-intelligence production
Every interaction is captured attacker behaviour — feeding the HFish.net intelligence base and your own detections.
Active defence / traceability
The on-demand source-traceability module helps attribute the source of an attack, not just detect it.
Regional presence

APAC offices & coverage

Same-jurisdiction threat-intel for ASEAN and East Asian compliance frameworks.

🇸🇬 Singapore 🇭🇰 Hong Kong 🇨🇳 China 🇦🇪 United Arab Emirates
FAQ

Common questions

Is HFish really free?

Yes. HFish is a free, open-source honeypot platform from ThreatBook, and the community edition recently lifted its node limit. You self-host the management end and as many node ends as you need across physical machines, VMs, cloud, and IoT at no licence cost.

What is a honeypot and why are its alerts so reliable?

A honeypot is a decoy service with no legitimate business purpose — no real user or application should ever connect to it. Because of that, any interaction is suspicious by definition, which makes honeypot alerts some of the highest-fidelity, lowest-false-positive signals in security. HFish turns that principle into a deployable grid of 40+ fake services.

Which services can HFish emulate?

More than 40 honeypot environments, including HTTP/HTTPS web traps, SSH, Telnet, FTP, SFTP, MySQL, and Redis, among others. The honeybait is highly customisable, so you can tailor the traps to blend into your real environment rather than looking like an obvious decoy.

How does the management-end / node-end architecture work?

HFish uses a browser/server architecture. The management end is a web console that generates and controls the nodes and receives, analyses, and displays the data they capture. Each node end runs the actual honeypot services and reports interactions back. This split lets you place lightweight nodes anywhere while managing everything from one dashboard.

What does the source-traceability module do?

It is a built-in, on-demand counter-attribution feature that helps trace and attribute the source of an attack — moving from passive detection toward active defence. Most free honeypots only log the interaction; HFish adds tooling to help you identify who is behind it.

How does HFish use ThreatBook intelligence?

HFish offers free access to the HFish.net honeypot intelligence base and natively integrates with ThreatBook's Threat Intelligence Platform (TIP). When a honeypot is hit, the attacking source can be enriched against that intelligence automatically — turning "something touched the trap" into "a known-bad actor touched the trap." Cloud real-time detection features are pushed to deployments.

Where can HFish be deployed?

Across physical machines, virtual machines, cloud environments, and IoT — it is cross-platform and multi-architecture, written in Golang, with one-click deployment. That flexibility makes it suitable for on-prem, hybrid, and air-gapped or sovereign-cloud environments common in APAC government and finance.

Does RECATOOLS get paid to list HFish?

We earn no per-click fee for this listing and our editorial coverage is independent. For full disclosure: an affiliated RECASYS business is an authorised reseller of ThreatBook commercial products, so it earns revenue if you buy a commercial licence through it — the same relationship disclosed on our SafeSkill, Flocks, and CTI listings. HFish itself is free and open source, and stays free regardless of how you reach it.

Deep dive

The full story

What is HFish?

HFish is a free, open-source honeypot platform built by ThreatBook — deception technology that plants convincing fake services across your network so that the moment an attacker (or a compromised internal host) touches one, you get a high-signal alert with almost zero false positives. Written in Golang and built for the enterprise, it is deployed by 4,000+ companies and ships 40+ honeypot environments out of the box.

The core idea of deception: a honeypot has no legitimate business purpose, so any interaction with it is suspicious by definition. That makes honeypot alerts some of the highest-fidelity signals in all of security — the polar opposite of a noisy IDS.

What it's for

ThreatBook positions HFish around three use cases:

  • Intranet compromise detection — catch lateral movement early. An attacker who has breached one machine will scan and probe internally; HFish honeypots sitting on that internal network light up the instant they're touched.
  • External threat perception — internet-facing honeypots reveal who is scanning and attacking your perimeter, and how.
  • Threat-intelligence production — every interaction is captured attacker behaviour, feeding back into intelligence.

40+ honeypot environments

HFish goes well beyond a simple fake web page. It can stand up believable services across protocols, including:

Category Emulated services
Web HTTP / HTTPS application traps
Remote access SSH, Telnet
File transfer FTP, SFTP
Databases MySQL, Redis
…and more 40+ environments total, with deep / customisable templates

The "honeybait" is highly customisable — you tailor the traps so they blend into your environment rather than looking like an obvious decoy.

Architecture: management end + node end

HFish uses a B/S (browser/server) architecture with two roles:

  • Management end — the brain. Generates and manages node ends, and receives, analyses, and displays all the data the nodes return. This is the web dashboard your team works from.
  • Node end — the traps. Controlled by the management end, each node is responsible for actually running the honeypot services and capturing interactions.

This split is what lets HFish scale: deploy lightweight nodes anywhere — across physical machines, virtual machines, cloud environments, and IoT — all reporting back to one management console. It is cross-platform and multi-architecture, with one-click deployment.

Source traceability + threat intelligence

Two features lift HFish above a generic open-source honeypot:

Built-in source-traceability module. Enabled on demand, it helps trace and attribute the source of an attack — counter-attribution and active-defence capabilities that most free honeypots simply don't have.

Native ThreatBook intelligence. HFish offers free access to the HFish.net honeypot intelligence base, and natively integrates with ThreatBook's Threat Intelligence Platform (TIP). So when a honeypot is hit, the attacking IP can be enriched against ThreatBook's intelligence automatically — turning "something touched the trap" into "a known scanner / known-bad actor touched the trap." Cloud real-time detection features are pushed to deployments and can be flexibly customised.

How an HFish detection flows

  1. Deploy nodes across your intranet and perimeter via one-click install.
  2. Attacker or compromised host probes the network and hits a honeypot service.
  3. Node captures the interaction — source IP, payloads, behaviour — and reports to the management end.
  4. Management end enriches + alerts — the source is checked against ThreatBook intelligence, and a high-confidence alert is raised.
  5. Trace + respond — the source-traceability module helps attribute the attacker; the event becomes intelligence.

Why it's a strong free option

The honeypot space has excellent open-source projects, but HFish stands out for an enterprise audience: it's genuinely free (the community edition recently lifted its node limit), it's broad (40+ environments vs single-protocol tools), it has a real management console rather than raw logs, and — uniquely — it ships with first-party threat-intelligence enrichment from a serious CTI vendor. For an APAC enterprise already evaluating ThreatBook's intelligence, HFish is the no-cost on-ramp that feeds the same ecosystem.

Why APAC teams should care

HFish is built by an APAC-headquartered vendor (ThreatBook — Singapore, Hong Kong, China, UAE), and its native TIP integration means honeypot hits are enriched against intelligence with strong regional collection. For internal-threat detection programmes under MAS TRM (Singapore), HKMA cyber-resilience (Hong Kong), and PDPA frameworks across ASEAN, a free, self-hosted, on-prem-capable honeypot grid that produces audit-friendly high-fidelity alerts is an easy addition to a defence-in-depth story.

Pricing

  • Free + open source — community edition, node limit lifted. Self-host on physical, virtual, cloud, or IoT.
  • Free HFish.net intelligence base access for enrichment.
  • Native, optional integration with the paid ThreatBook TIP for teams that want deeper intelligence.

Download and deploy from hfish.net — one-click install, cross-platform, free.

Cybersecurity Honeypot Open Source Deception Blue Team APAC
Independently reviewed by RECATOOLS editorial on 04 Jun 2026. Listings are based on the vendor's public documentation; we don't accept payment for inclusion.
Disclosure: An affiliated RECASYS business is an authorised reseller of ThreatBook commercial products. Editorial coverage on RECATOOLS remains independent — we receive no per-click fee for this listing — but the affiliated business earns revenue when readers purchase a commercial licence through it. The free / open-source tier of this product remains free regardless of how you access it.

Deploy a free honeypot grid in minutes

Download HFish, one-click install the management console and nodes, and start catching attackers with near-zero false positives.

Get HFish — Free

Related News

You may be interested in these recent stories from our newsroom.

No related news yet for this tool. Our editorial team publishes new pieces every week.

Browse all news →