hacklcx/hfish

安全、可靠、简单、免费的企业级蜜罐

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 35 minutes ago
Added to GitGenius on September 15th, 2026
Created on August 7th, 2019
Open Issues & Pull Requests: 70 (+0)
GitHub issues: Enabled
Number of forks: 677
Total Stargazers: 4,551 (+0)
Total Subscribers: 23 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 24.8 days
Mean response time: 208.1 days
90th percentile: 1048.5 days
Tracked items: 18

Most active contributors

Sign in to see contributor activity.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 25
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 692 days
Stale 30+ days: 25
Stale 90+ days: 25

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

No label distribution available yet.

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

HFish is a honeypot system designed for enterprise security operations that detects internal network compromises, perceives external threats, and generates threat intelligence.

HFish addresses the challenge of detecting lateral movement, account compromise, and reconnaissance activity within enterprise networks by deploying lightweight, medium-interaction honeypot services across infrastructure. The system uses a distributed architecture with a management server that controls and monitors honeypot nodes deployed throughout the network. Nodes emulate over ninety types of services including basic network protocols, OA systems, CRM platforms, NAS storage, web servers, operational platforms, wireless access points, switches, routers, email systems, and IoT devices. The tool can redirect traffic to a free cloud honeypot network, detect full-port scanning activity, and accept customizable bait configurations. It supports one-click deployment across Linux and Windows platforms with multiple CPU architectures, including domestic Chinese processors.

Organizations should choose HFish if they operate small to medium-sized enterprises seeking low-cost threat detection and local threat intelligence production without vendor lock-in. The tool suits internal network monitoring, production environment protection, cloud network surveillance, and security awareness training scenarios. It integrates with existing security infrastructure through multiple alert channels including email, syslog, webhooks, and enterprise messaging platforms like WeChat Work, DingTalk, and Feishu, allowing integration with SIEM, NDR, XDR, and log analysis platforms. The project emphasizes minimal performance overhead and operational simplicity compared to traditional honeypot deployments.

The project maintains active community engagement with ongoing refinement based on user feedback. Development activity shows consistent attention to expanding service emulation capabilities and platform support across diverse hardware architectures. The tool has evolved from its initial release to a second-generation version incorporating accumulated operational experience and community contributions. Maintenance includes regular updates to detection mechanisms and alert delivery systems to support integration with modern security operations workflows.