Most honeypots stop at logging connections. Echidra classifies them deterministic YAML rules turn each session into an actor label, risk score, MITRE ATT&CK tags, and a recommended fix, no opaque ML model deciding your risk score. It's also multi-protocol out of the box (SSH-shell, HTTP, FTP, Telnet) with a full self-hosted dashboard, not just a single-service logger. Fully open source, AGPLv3, nothing phones home — you own the data and can audit exactly why a session got its label.
Framer AI AgentsDesign and publish professional sites with AI
Promoted
Maker
📌
Hey PH 👋 — maintainer here.
Echidra started as an internal tool for watching what hits our exposed services before hardening them, and it grew into a full classification pipeline —> actor labels, risk scoring, MITRE ATT&CK tags, all deterministic and auditable (no opaque ML model deciding your risk score).
One thing I'd genuinely love feedback on: right now classification is a single label at the end of a session. A security researcher pointed out that's a real gap, attacker behavior isn't static, someone can start as a scanning bot and pivot mid-session into manual exploitation. We just filed this issue to make classification incremental with confidence scoring. If that's something you'd want, jump in on the thread.
Try it, break it, tell me what's missing.