tokens&
For enterprises
tokens&

Find tools, check provider offers, save a build plan, and share your work when you’re ready.

For buildersFor enterprises

For builders

  • Startup credits and perks
  • Agent Skills
  • Publish a project

For enterprises

  • Start free company workspace
  • Submit a tool, product, or perk

Community

  • Community
  • Newsletter
  • Events
Xin

© 2026 tokensand, LLC. All rights reserved.

  • Terms
  • Privacy
  • Security
  • Data Processing
  • Status
  1. Hackathon
  2. Project gallery
  3. HoneyStack
Ian Tooabout 2 hours agoContributorJudging locked: Event build

HoneyStack

An AI agent that pretends to be a hacked server. The attacker's "reverse shell" is really an agent playing bash inside a fake company, nothing they type runs. It wastes their time with convincing dead-ends while every command goes to ClickHouse and a second agent writes an evidence-linked

Review the project

Start with the source code, then open the demo or video if available.

View GitHub repository
Visit project websiteWatch demo videoProject gallery
Demo video
Watch demo video
Project description
An AI agent that pretends to be a compromised server. When an attacker exploits our fake company (Hivewell, a smart-beehive startup) and pops a "reverse shell," their terminal connects to a real socket — but on the other end is an agent playing bash inside a consistent synthetic machine. Nothing they type is executed. The agent never breaks character. It keeps a stable fake filesystem, answers unknown commands in-world, and feeds tempting dead-ends — a fake .env, AWS keys, a database that times out — so the attacker burns time chasing loot that was never real. Meanwhile the control server logs every HTTP request and shell command to ClickHouse. A second agent reads the whole session and writes an evidence-linked attacker playbook: classification, kill-chain stages, and the exact commands that prove each one — shown on the HoneyStack Shield dashboard with a live timeline and a "time wasted" counter. Who it's for: blue teams, SOC and threat-intel analysts who want real attacker behavior instead of alert noise, and researchers studying how autonomous, agentic attackers operate. Built on our partners: Akash hosts the public trap; ClickHouse is the telemetry backbone behind the live replay and metrics; Guild AI runs both agents. Everything the attacker sees is invented; everything they do becomes evidence.
Project links
  • GitHub repository
  • Project website
  • Demo video
Tools used
  • Guild.ai logoGuild.ai
  • ClickHouse logoClickHouse
  • AAkash
Tools used
  • Guild.ai logoGuild.ai
  • ClickHouse logoClickHouse
  • AAkash