HoneySAP: SAP Low-interaction honeypot
Version 0.2.0
Overview
HoneySAP is a low-interaction research-focused honeypot specific for SAP services. It's aimed at learn the techniques and motivations behind attacks against SAP systems.
Features
- low-interaction honeypot for SAP services
- YAML and JSON-based configuration
- pluggable datastore backend
- modular services system
- modular feeds system
- console logging
- SAP RFC Gateway emulation with full NWRFC SDK handshake support
- RFM and DDIC catalog-driven responses for realistic function module interface replies
- Credential capture (SAP logon user, client, descrambled password, OS user, IP)
- XML parameter extraction and logging for all RFC business function calls
- CVE-2025-42957 (
/SLOAE/DEPLOY) exploit detection and ABAP code capture
Installation
To install HoneySAP, simply download the sources and run:
$ python -m pip install .
A more complete guidance on how to install HoneySAP on different environments is provided in the documentation.
Documentation
Documentation is available at Read the Docs.
License
This tool is distributed under the GPLv2 license. Check the COPYING file for more details.
Authors
The tool was initially designed and developed by Martin Gallo wile working at SecureAuth's Innovation Labs team, with the help of many contributors. The code was then contributed by SecureAuth to the OWASP CBAS Project in October 2022.
Disclaimer
The spirit of this Open Source initiative is to help security researchers, and the community, speed up research and educational activities related to the implementation of networking protocols and stacks.
The information in this repository is for research and educational purposes and not meant to be used in production environments and/or as part of commercial products.
If you desire to use this code or some part of it for your own uses, we recommend applying proper security development life cycle and secure coding practices, as well as generate and track the respective indicators of compromise according to your needs.
Contact Us
Whether you want to report a bug, send a patch, or give some suggestions on this package, drop a few lines to OWASP CBAS' project leaders.
For security-related questions check our security policy.
Metadata
Release files for honeysap 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| honeysap-0.2.0.tar.gz | 13.1 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| honeysap-0.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 13.2 MB
Release files / honeysap-0.2.0.tar.gz
| Download URL | honeysap-0.2.0.tar.gz |
|---|---|
| Size | 13.1 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a8a76c4deef06b42d2ba99b50420394093f333fb95f15a101966859dd40b7ad4
|
|
BLAKE2b-256 checksum How to use checksums |
126169db1da7910576a9e4dadd0d680f1464b8719ab9013bcb825dc3731e88bd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.15
|
Release files / honeysap-0.2.0-py3-none-any.whl
| Download URL | honeysap-0.2.0-py3-none-any.whl |
|---|---|
| Size | 165.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
1dda2d8ad0b804b5ed5d9450c942306977830abbbb2fea149e118e466bc97530
|
|
BLAKE2b-256 checksum How to use checksums |
f794769b048b45d5be7218334e99c0c867cf507a1855589ce500199a349952d0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.15
|