⚠️ HoneyLabs

⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.

HoneyLabs Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index


Attribute Value
Publisher HoneyLabs
Support Tier Community
Support Link https://honeylabs.net
Categories Security - Threat Intelligence
Version 3.0.0
Author HoneyLabs - info@honeylabs.net
First Published 2026-07-16
Solution Folder HoneyLabs

The HoneyLabs solution for Microsoft Sentinel ingests threat intelligence generated by internet-facing honeypot sensors: source IPs observed running exploit or loader commands, and the malware infrastructure (loader and C2 URLs) extracted from the captured payloads. Indicators are evidence-backed rather than scan-derived, exclude known research scanners (Shadowserver, Censys and similar), and expire automatically as activity stops. Ingestion uses Microsoft Sentinel's built-in Threat Intelligence - TAXII data connector against the HoneyLabs TAXII 2.1 server; a free HoneyLabs API key is the only prerequisite. The solution also includes analytic rules that match the indicators against your own logs and a playbook that enriches incidents with the full HoneyLabs report for any IP entity.

Get a free API key | Integration guide | Methodology

Contents

Data Connectors

This solution does not include data connectors.

This solution may contain other components such as analytics rules, workbooks, hunting queries, or playbooks.

Tables Used

This solution queries 3 table(s) from its content items:

Table Used By Content
AADNonInteractiveUserSignInLogs Analytics
CommonSecurityLog Analytics, Hunting, Workbooks
SigninLogs Analytics

Internal Tables

The following 1 table(s) are used internally by this solution's content items:

Table Used By Content
ThreatIntelIndicators Analytics, Hunting, Workbooks

Content Items

This solution includes 10 content item(s):

Content Type Count
Analytic Rules 4
Hunting Queries 4
Workbooks 1
Playbooks 1

Analytic Rules

Name Severity Tactics Tables Used
HoneyLabs TI Map IP Entity to CommonSecurityLog Medium InitialAccess, CommandAndControl CommonSecurityLog
Internal use:
ThreatIntelIndicators
HoneyLabs TI Map IP Entity to Network Session (ASIM) Medium InitialAccess, CommandAndControl Internal use:
ThreatIntelIndicators
HoneyLabs TI Map IP Entity to SigninLogs Medium InitialAccess, CredentialAccess AADNonInteractiveUserSignInLogs
SigninLogs
Internal use:
ThreatIntelIndicators
HoneyLabs TI Map URL Entity to CommonSecurityLog High CommandAndControl, Execution CommonSecurityLog
Internal use:
ThreatIntelIndicators

Hunting Queries

Name Tactics Tables Used
Contact from a source probing a specific CVE Reconnaissance, InitialAccess CommonSecurityLog
Internal use:
ThreatIntelIndicators
HoneyLabs high-confidence indicator seen for the first time InitialAccess CommonSecurityLog
Internal use:
ThreatIntelIndicators
One HoneyLabs indicator contacting several internal hosts Discovery CommonSecurityLog
Internal use:
ThreatIntelIndicators
Outbound contact with a HoneyLabs malware loader or C2 URL CommandAndControl CommonSecurityLog
Internal use:
ThreatIntelIndicators

Workbooks

Name Tables Used
HoneyLabsThreatIntelligence CommonSecurityLog
Internal use:
ThreatIntelIndicators

Playbooks

Name Description Tables Used
HoneyLabs-EnrichIncident-IP Enriches Microsoft Sentinel incidents with HoneyLabs honeypot intelligence. For every IP entity on t... -

Additional Documentation

📄 Source: HoneyLabs/README.md

HoneyLabs for Microsoft Sentinel

HoneyLabs runs internet-facing honeypot sensors and publishes the resulting indicators over TAXII 2.1. Every indicator is evidence-backed: the IP ran an exploit or loader command against a sensor, or the URL was extracted from a payload those commands fetched. Known research scanners are excluded, and indicators expire on their own as activity stops.

How ingestion works

This solution does not ship a data connector. Indicators arrive through Microsoft Sentinel's built-in Threat Intelligence - TAXII connector, which polls the HoneyLabs TAXII server and writes into the ThreatIntelIndicators table. The solution provides the content that sits on top of that: a workbook, four analytic rules, four hunting queries and an enrichment playbook.

A free HoneyLabs API key is the only prerequisite.

Setup

  1. Create an API key at honeylabs.net/dashboard. Accounts are free. The key is the password for the TAXII server.

  2. If your workspace does not have the Threat Intelligence - TAXII connector, install the Threat Intelligence solution by Microsoft from the Content hub.

  3. Open that connector, choose Add, and enter:

    | Field | Value | |---|---| | Friendly name | HoneyLabs | | API root URL | https://honeylabs.net/taxii2/api/ | | Collection ID | 019bc26f-7216-562c-b110-16ccd9c553f6 | | Username | taxii | | Password | your HoneyLabs API key | | Polling frequency | hourly |

  4. Optionally add a second entry for malware infrastructure, the loader and command-and-control URLs pulled out of captured payloads. Same API root URL and credentials, collection ID e144c129-a19a-55c8-b926-dd2dfbbd8138. It is a smaller and different signal from the attacker IPs and is kept separate so it does not dilute them.

Indicators appear in the Threat intelligence blade within a few minutes of the first poll, with SourceSystem starting HoneyLabs. Until they do, the workbook shows these same steps in place of its charts.

What ships

Item Purpose
HoneyLabs Threat Intelligence workbook Indicator volume and freshness, confidence bands, source ASN and country, probed CVEs, and matches against your own logs
4 analytic rules Match indicators against CommonSecurityLog, ASIM network sessions and sign-in logs
4 hunting queries First contact with high-confidence indicators, CVE prober contact, loader URL contact, and repeated contact across hosts
Enrich Incident - IP playbook Adds the full HoneyLabs report for any IP entity to the incident as a comment

Fields on each indicator

Confidence grades the evidence behind an indicator: 90 means 100 or more observed attacks, 60 means a single sighting. It is there so you can pick an alerting threshold rather than mute the feed. Labels carry the source network (asn:ASxxxx), origin (country:XX) and the indicator

[Content truncated...]

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.0 14-08-2026 Initial Solution Release. Includes the HoneyLabs Threat Intelligence workbook | v 1.0.0, four Analytic Rules matching HoneyLabs indicators against sign-in, CEF and normalised network logs | v 1.0.0, four Hunting Queries | v 1.0.0, and the HoneyLabs-EnrichIncident-IP playbook | v 1.0. Indicators are ingested with Microsoft Sentinel's built-in Threat Intelligence - TAXII data connector, so the solution does not ship a data connector of its own. Setup values are in the solution README and in the workbook.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index