⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | HoneyLabs |
| Support Tier | Community |
| Support Link | https://honeylabs.net |
| Categories | Security - Threat Intelligence |
| Version | 3.0.0 |
| Author | HoneyLabs - info@honeylabs.net |
| First Published | 2026-07-16 |
| Solution Folder | HoneyLabs |
The HoneyLabs solution for Microsoft Sentinel ingests threat intelligence generated by internet-facing honeypot sensors: source IPs observed running exploit or loader commands, and the malware infrastructure (loader and C2 URLs) extracted from the captured payloads. Indicators are evidence-backed rather than scan-derived, exclude known research scanners (Shadowserver, Censys and similar), and expire automatically as activity stops. Ingestion uses Microsoft Sentinel's built-in Threat Intelligence - TAXII data connector against the HoneyLabs TAXII 2.1 server; a free HoneyLabs API key is the only prerequisite. The solution also includes analytic rules that match the indicators against your own logs and a playbook that enriches incidents with the full HoneyLabs report for any IP entity.
Get a free API key | Integration guide | Methodology
This solution does not include data connectors.
This solution may contain other components such as analytics rules, workbooks, hunting queries, or playbooks.
This solution queries 3 table(s) from its content items:
| Table | Used By Content |
|---|---|
AADNonInteractiveUserSignInLogs |
Analytics |
CommonSecurityLog |
Analytics, Hunting, Workbooks |
SigninLogs |
Analytics |
The following 1 table(s) are used internally by this solution's content items:
| Table | Used By Content |
|---|---|
ThreatIntelIndicators |
Analytics, Hunting, Workbooks |
This solution includes 10 content item(s):
| Content Type | Count |
|---|---|
| Analytic Rules | 4 |
| Hunting Queries | 4 |
| Workbooks | 1 |
| Playbooks | 1 |
| Name | Severity | Tactics | Tables Used |
|---|---|---|---|
| HoneyLabs TI Map IP Entity to CommonSecurityLog | Medium | InitialAccess, CommandAndControl | CommonSecurityLogInternal use: ThreatIntelIndicators |
| HoneyLabs TI Map IP Entity to Network Session (ASIM) | Medium | InitialAccess, CommandAndControl | Internal use:ThreatIntelIndicators |
| HoneyLabs TI Map IP Entity to SigninLogs | Medium | InitialAccess, CredentialAccess | AADNonInteractiveUserSignInLogsSigninLogsInternal use: ThreatIntelIndicators |
| HoneyLabs TI Map URL Entity to CommonSecurityLog | High | CommandAndControl, Execution | CommonSecurityLogInternal use: ThreatIntelIndicators |
| Name | Tactics | Tables Used |
|---|---|---|
| Contact from a source probing a specific CVE | Reconnaissance, InitialAccess | CommonSecurityLogInternal use: ThreatIntelIndicators |
| HoneyLabs high-confidence indicator seen for the first time | InitialAccess | CommonSecurityLogInternal use: ThreatIntelIndicators |
| One HoneyLabs indicator contacting several internal hosts | Discovery | CommonSecurityLogInternal use: ThreatIntelIndicators |
| Outbound contact with a HoneyLabs malware loader or C2 URL | CommandAndControl | CommonSecurityLogInternal use: ThreatIntelIndicators |
| Name | Tables Used |
|---|---|
| HoneyLabsThreatIntelligence | CommonSecurityLogInternal use: ThreatIntelIndicators |
| Name | Description | Tables Used |
|---|---|---|
| HoneyLabs-EnrichIncident-IP | Enriches Microsoft Sentinel incidents with HoneyLabs honeypot intelligence. For every IP entity on t... | - |
📄 Source: HoneyLabs/README.md
HoneyLabs runs internet-facing honeypot sensors and publishes the resulting indicators over TAXII 2.1. Every indicator is evidence-backed: the IP ran an exploit or loader command against a sensor, or the URL was extracted from a payload those commands fetched. Known research scanners are excluded, and indicators expire on their own as activity stops.
This solution does not ship a data connector. Indicators arrive through Microsoft Sentinel's
built-in Threat Intelligence - TAXII connector, which polls the HoneyLabs TAXII server and
writes into the ThreatIntelIndicators table. The solution provides the content that sits on
top of that: a workbook, four analytic rules, four hunting queries and an enrichment playbook.
A free HoneyLabs API key is the only prerequisite.
Create an API key at honeylabs.net/dashboard. Accounts are free. The key is the password for the TAXII server.
If your workspace does not have the Threat Intelligence - TAXII connector, install the Threat Intelligence solution by Microsoft from the Content hub.
Open that connector, choose Add, and enter:
| Field | Value |
|---|---|
| Friendly name | HoneyLabs |
| API root URL | https://honeylabs.net/taxii2/api/ |
| Collection ID | 019bc26f-7216-562c-b110-16ccd9c553f6 |
| Username | taxii |
| Password | your HoneyLabs API key |
| Polling frequency | hourly |
Optionally add a second entry for malware infrastructure, the loader and command-and-control
URLs pulled out of captured payloads. Same API root URL and credentials, collection ID
e144c129-a19a-55c8-b926-dd2dfbbd8138. It is a smaller and different signal from the
attacker IPs and is kept separate so it does not dilute them.
Indicators appear in the Threat intelligence blade within a few minutes of the first poll,
with SourceSystem starting HoneyLabs. Until they do, the workbook shows these same steps in
place of its charts.
| Item | Purpose |
|---|---|
| HoneyLabs Threat Intelligence workbook | Indicator volume and freshness, confidence bands, source ASN and country, probed CVEs, and matches against your own logs |
| 4 analytic rules | Match indicators against CommonSecurityLog, ASIM network sessions and sign-in logs |
| 4 hunting queries | First contact with high-confidence indicators, CVE prober contact, loader URL contact, and repeated contact across hosts |
| Enrich Incident - IP playbook | Adds the full HoneyLabs report for any IP entity to the incident as a comment |
Confidence grades the evidence behind an indicator: 90 means 100 or more observed attacks, 60
means a single sighting. It is there so you can pick an alerting threshold rather than mute the
feed. Labels carry the source network (asn:ASxxxx), origin (country:XX) and the indicator
[Content truncated...]
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.0 | 14-08-2026 | Initial Solution Release. Includes the HoneyLabs Threat Intelligence workbook | v 1.0.0, four Analytic Rules matching HoneyLabs indicators against sign-in, CEF and normalised network logs | v 1.0.0, four Hunting Queries | v 1.0.0, and the HoneyLabs-EnrichIncident-IP playbook | v 1.0. Indicators are ingested with Microsoft Sentinel's built-in Threat Intelligence - TAXII data connector, so the solution does not ship a data connector of its own. Setup values are in the solution README and in the workbook. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊