Abracadabra Labs / resource directory

Software and data · 22 links

Things you can run or download

Repositories and datasets only. Language and licence are as shown on the repository page when I last checked it.

Neither star counts nor last-commit dates are recorded here. Both go stale within days, neither can be updated in bulk once it is written into prose, and a directory printing a stale number is worse than one telling you to go and look. Where a project was visibly dormant when I checked, the annotation says so.

The index

Tools (17)

Open-source software with a public repository.

  • 0x4D31/deception-as-detection

    Crosswalk from deception-based detections to ATT&CK techniques across Windows, Linux and macOS, with a worked deception story for each. MIT. Dormant for years, and nothing has replaced the mapping.

    datedliving
  • 0x4D31/galah

    LLM-powered web honeypot: generates a plausible HTTP response to whatever arrives instead of emulating fixed applications. Go, Apache-2.0.

    living
  • awesome-ai-agent-security

    Reading list built around the lethal trifecta framing: MCP CVEs, defensive tooling, documented incidents. A fork with almost no history, so treat the selection as one person's.

    living
  • beelzebub-labs/beelzebub

    Low-code deception runtime, Go, GPL-3.0. The interesting part is the MCP bait tooling: decoys aimed at AI agents rather than human intruders. A commercial product sits on top.

    livingvendor-authoredopen version
  • cage-challenge/CybORG

    The environment behind the multinational CAGE Challenges for autonomous cyber defence agents. MIT. Challenge 4 adds multi-agent RL.

    livingopen version
  • Canarytokens

    Hosted honeytoken generator, free: files, URLs, credentials, cloud keys that alert when touched.

    livingvendor-authored
  • cowrie/cowrie

    The default SSH and Telnet honeypot. Emulated shell, a proxy mode fronting a real host, an experimental LLM backend. Python, actively developed.

    livingopen version
  • microsoft/CyberBattleSim

    Abstract simulated network for agents moving laterally, built for reinforcement learning rather than realism. MIT. The abstraction is deliberate and it does limit transfer.

    livingopen version
  • mitre/engage

    The Engage matrix as machine-readable data, plus the site tooling. Apache-2.0.

    living
  • mushorg/conpot

    ICS/SCADA honeypot emulating industrial protocol stacks. Python, GPL-2.0. The usual starting point for OT deception.

    living
  • NVIDIA/garak

    NVIDIA's LLM vulnerability scanner. Prompt injection, jailbreaks, training-data leakage, glitch tokens. Apache-2.0.

    living
  • paralax/awesome-honeypots

    The long-running index of honeypot software by protocol and environment, with a section on anti-honeypot detection tools. Breadth over curation.

    living
  • pasquini-dario/project_mantis

    The Mantis decoys as running code: tarpitted FTP, deliberately vulnerable web apps, weak telnet, injection payloads, reverse-shell listeners.

    living
  • telekom-security/tpotce

    Around thirty honeypot daemons bundled with Elasticsearch, Kibana and Suricata behind one installer. GPL-3.0.

    living
  • thinkst/opencanary

    Multi-protocol honeypot daemon light enough for a Raspberry Pi. BSD-3-Clause. The open counterpart to Thinkst's commercial Canary.

    living
  • Threat-Actors-use-of-Artificial-Intelligence

    Documented threat-actor AI use mapped to ATT&CK, from Microsoft, OpenAI, Anthropic, GTIG and Kaspersky reporting. Narrower than it looks: attacks on AI systems and influence operations are excluded by design.

    living
  • UKGovernmentBEIS/inspect_ai

    The UK AI Security Institute's evaluation framework. CVE-Bench and several other cyber evals are written against it. MIT.

    livingopen version

Datasets and benchmarks (5)

Data and evaluation suites with a canonical landing page.