Cloudflare Honeypot

Serverless Edge Security & Deception System

v1.1.0 ☁️ Cloudflare Workers ⚖️ MIT License GitHub
edge-monitor@honeypot:~

🔧 Configuration & Setup

1 Clone & Install

Download the repository and install dependencies.

git clone https://github.com/SecH0us3/honeypot.git
cd honeypot
npm i
2 Deploy to Cloudflare

Deploy the worker to Cloudflare's edge network using Wrangler.

npx wrangler deploy
3 Create API Token

Go to your Cloudflare Dashboard and create an API Token. You will need the following permissions to manage IP Lists automatically:

  • Account : Account WAF : Edit
  • Account : Account Filter Lists : Edit
  • Zone : Zone : Read
Cloudflare API Token Creation Demo
4 Initialize Config

Navigate to your worker's live URL (e.g., https://your-worker.workers.dev/install). Paste your generated API token, your Zone ID, and select the behavior mode.
(Zone ID can be found on the Overview page of your website in Cloudflare) The worker will automatically create an IP List named honeypot_ips and configure the WAF rule to block them.

🔄 Maintenance & Reinstallation

To re-run the setup flow (e.g., to update tokens or behavior) without clearing KV manually:

  1. Set a secret key via CLI:
    npx wrangler secret put REINSTALL_KEY
  2. Visit the protected install URL:
    /install?reinstall=YOUR_SECRET_KEY

🎯 Purpose & Architecture

Objective: Deploy an intelligent edge-level trap that simulates vulnerable infrastructure, absorbs scanning attempts, and automatically banishes attackers from your entire network using Cloudflare IP Lists.

Detailed Overview

Modern web infrastructure is constantly probed by automated scanners, botnets, and script kiddies searching for exposed .git directories, `.env` files, or vulnerable admin panels. This Honeypot is designed to intercept these probes directly at the CDN Edge before they ever reach your origin servers.

Instead of merely blocking the scanner, the Honeypot deceives it. It dynamically generates hyper-realistic fake responses—such as artificial Terraform state files, populated OpenAPI schemas, or convincing SQL dumps. This wastes the attacker's computational resources and provides rich telemetry on their attack patterns.

Key Mechanisms

Tech Stack

TypeScript Cloudflare Workers CF KV Storage CF Custom Lists WAF Rules

🧪 Demo Traps

Click endpoints to trigger simulated payloads in a preview window.