↳ GitHub sourceSolution

HoneyLabs

Description

The [HoneyLabs](https://honeylabs.net) solution for Microsoft Sentinel ingests threat intelligence generated by internet-facing honeypot sensors: source IPs observed running exploit or loader commands, and the malware infrastructure (loader and C2 URLs) extracted from the captured payloads. Indicators are evidence-backed rather than scan-derived, exclude known research scanners (Shadowserver, Censys and similar), and expire automatically as activity stops. Ingestion uses Microsoft Sentinel's built-in **Threat Intelligence - TAXII** data connector against the HoneyLabs TAXII 2.1 server; a free HoneyLabs API key is the only prerequisite. The solution also includes analytic rules that match the indicators against your own logs and a playbook that enriches incidents with the full HoneyLabs report for any IP entity. [Get a free API key](https://honeylabs.net/dashboard?src=sentinel) | [Integration guide](https://honeylabs.net/integrations/sentinel) | [Methodology](https://honeylabs.net/methodology)
Version
3.0.0
Declared author / publisher
HoneyLabs - info@honeylabs.net
Support tier
Community

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
azure-sentinel-solution-honeylabs
Additional source files 2Solutions/HoneyLabs/Data/Solution_HoneyLabs.jsonsolution-manifest ↗Solutions/HoneyLabs/SolutionMetadata.jsonsolution-metadata ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.