beelzebub-labs/beelzebub
An open-source deception runtime that deploys LLM-powered decoy services to engage attackers, collect threat intelligence, and detect AI agent attacks.

Beelzebub is a Go-based deception framework that deploys adaptive, LLM-powered decoy services across SSH, HTTP, TCP, TELNET, and MCP protocols. It actively engages attackers in realistic interactions to collect threat intelligence. The framework includes specific capabilities to detect prompt injection attacks against AI agents and provides MCP honeypot services to test AI agent security. The project integrates with Prometheus for metrics collection and supports a plugin architecture for extensibility.