Skip to main content

HoneySAP: SAP Low-interaction honeypot

Build and test HoneySAP Read the Docs Discord

Version 0.2.0

Overview

HoneySAP is a low-interaction research-focused honeypot specific for SAP services. It's aimed at learn the techniques and motivations behind attacks against SAP systems.

Features

  • low-interaction honeypot for SAP services
  • YAML and JSON-based configuration
  • pluggable datastore backend
  • modular services system
  • modular feeds system
  • console logging
  • SAP RFC Gateway emulation with full NWRFC SDK handshake support
  • RFM and DDIC catalog-driven responses for realistic function module interface replies
  • Credential capture (SAP logon user, client, descrambled password, OS user, IP)
  • XML parameter extraction and logging for all RFC business function calls
  • CVE-2025-42957 (/SLOAE/DEPLOY) exploit detection and ABAP code capture

Installation

To install HoneySAP, simply download the sources and run:

$ python -m pip install .

A more complete guidance on how to install HoneySAP on different environments is provided in the documentation.

Documentation

Documentation is available at Read the Docs.

License

This tool is distributed under the GPLv2 license. Check the COPYING file for more details.

Authors

The tool was initially designed and developed by Martin Gallo wile working at SecureAuth's Innovation Labs team, with the help of many contributors. The code was then contributed by SecureAuth to the OWASP CBAS Project in October 2022.

Disclaimer

The spirit of this Open Source initiative is to help security researchers, and the community, speed up research and educational activities related to the implementation of networking protocols and stacks.

The information in this repository is for research and educational purposes and not meant to be used in production environments and/or as part of commercial products.

If you desire to use this code or some part of it for your own uses, we recommend applying proper security development life cycle and secure coding practices, as well as generate and track the respective indicators of compromise according to your needs.

Contact Us

Whether you want to report a bug, send a patch, or give some suggestions on this package, drop a few lines to OWASP CBAS' project leaders.

For security-related questions check our security policy.

Metadata

Release files for honeysap 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for honeysap 0.2.0
File Size Uploaded
honeysap-0.2.0.tar.gz 13.1 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for honeysap 0.2.0
File Interpreter ABI Platform
honeysap-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 13.2 MB

Release files / honeysap-0.2.0.tar.gz

Download URL honeysap-0.2.0.tar.gz
Size 13.1 MB
Tags Source
SHA-256 checksum
How to use checksums
a8a76c4deef06b42d2ba99b50420394093f333fb95f15a101966859dd40b7ad4
BLAKE2b-256 checksum
How to use checksums
126169db1da7910576a9e4dadd0d680f1464b8719ab9013bcb825dc3731e88bd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.15

Release files / honeysap-0.2.0-py3-none-any.whl

Download URL honeysap-0.2.0-py3-none-any.whl
Size 165.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
1dda2d8ad0b804b5ed5d9450c942306977830abbbb2fea149e118e466bc97530
BLAKE2b-256 checksum
How to use checksums
f794769b048b45d5be7218334e99c0c867cf507a1855589ce500199a349952d0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.15

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page