{"repo":"0x4D31/galah","free":true,"listed":false,"github":"https://github.com/0x4D31/galah","clone":"git clone https://github.com/0x4D31/galah.git","description":"Galah: An LLM-powered web honeypot.","language":"Go","stars":661,"topics":["golang","honeypot","llm","openai","openai-api","security","security-tools"],"license":"Apache-2.0","category":"ai-agents","readme_excerpt":"TL;DR: Galah (/ɡəˈlɑː/ - pronounced ‘guh-laa’) is an LLM-powered web honeypot designed to mimic various applications and dynamically respond to arbitrary HTTP requests. Galah supports major LLM providers, including OpenAI, GoogleAI, GCP's Vertex AI, Anthropic, Cohere, and Ollama. Unlike traditional web honeypots that manually emulate specific web applications or vulnerabilities, Galah dynamically crafts relevant responses—including HTTP headers and body content—to any HTTP request. Responses generated by the LLM are cached for a configurable period to prevent repetitive generation for identical requests, reducing API costs. The caching is port-specific, ensuring that responses generated for a particular port will not be reused for the same request on a different port. Galah can optionally inspect incoming HTTP requests against a set of Suricata rules, matching on various HTTP buffers including method, URI, headers, cookies, and request body (the current implementation doesn't support all Suricata keywords, and PCRE handling is limited). To enable and configure rule matching, see Suricata HTTP Rule Matching. The prompt configuration is key in this honeypot. While you can update the prompt in the configuration file, it is crucial to maintain the segment directing the LLM to produce responses in the specified JSON format. Note: Galah was developed as a fun weekend project to explore the capabilities of LLMs in crafting HTTP messages. The honeypot may be identifiable through vari","default_branch":null,"files":null,"tree":[],"storefront":"/r/0x4D31","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/0x4D31/galah/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}