Description
The [HoneyLabs](https://honeylabs.net) solution for Microsoft Sentinel ingests threat intelligence generated by internet-facing honeypot sensors: source IPs observed running exploit or loader commands, and the malware infrastructure (loader and C2 URLs) extracted from the captured payloads. Indicators are evidence-backed rather than scan-derived, exclude known research scanners (Shadowserver, Censys and similar), and expire automatically as activity stops. Ingestion uses Microsoft Sentinel's built-in **Threat Intelligence - TAXII** data connector against the HoneyLabs TAXII 2.1 server; a free HoneyLabs API key is the only prerequisite. The solution also includes analytic rules that match the indicators against your own logs and a playbook that enriches incidents with the full HoneyLabs report for any IP entity.
[Get a free API key](https://honeylabs.net/dashboard?src=sentinel) | [Integration guide](https://honeylabs.net/integrations/sentinel) | [Methodology](https://honeylabs.net/methodology)
- Version
- 3.0.0
- Declared author / publisher
- HoneyLabs - info@honeylabs.net
- Support tier
- Community
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
azure-sentinel-solution-honeylabs
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC