HoneyLabs

Pricing

Pay for volume and reach, not for features

Every plan reaches the whole dataset through every interface we ship: REST, MCP, TAXII, MISP and the web. What changes is how much you can pull in a day and how far back you can look. Each step is ten times the credits for about three and a half times the price. Open research is free, with Pro volume and the full history, by application rather than by card.

Plan
 
Free
 
Solo
Most common
Pro
By application
Research
 
Team
Free
no card, no expiry
€29/mo
€290/yr, two months free
€99/mo
€990/yr, two months free
Free
open research, non-commercial
€349/mo
€3,490/yr, two months free
Enough to find out whether the data answers your question.Thirty days of history rather than seven, so a repeat visitor stops looking like a one-off. Ten times the budget, and alerts the same day.Ninety days, fifty thousand credits a day and payload search, for integrations other people depend on.Academic, independent, CERT or student work that will be published where anyone can read it.One budget across a team and everything it automates, with the full archive behind every question.
Daily credits15005,00050,00050,000500,000
Requests per minute10306060300
Query window27 days30 days90 daysFull historyFull history
Watchlists310251001001,000
Feed tokens per watchlist425101050
Alert subscriptions3102525200
Fastest alert cadenceWeeklyDailyDailyDailyHourly
Fastest feed digestDailyHourlyHourlyHourlyHourly
SupportCommunity, best effortEmailEmailEmailPriority, with onboarding help
Create a free accountApply for Research
1One credit is one row of data returned, so an enrichment lookup costs 1 and a 100-row list costs 100.
2How far back a query may reach. Full history means the whole dataset, with no window applied.
3A saved query, pullable as a token-gated feed.
4One per consumer, so a leaked URL can be revoked on its own.

Every number above is read from the same registry the quota middleware enforces, so this page cannot promise a limit the platform does not apply. Responses carry an X-HoneyLabs-Quota-Remaining header so an integration can watch its own budget.

Applying for research access

No cost, 12 months, renewable

The dataset exists because people run sensors and publish what they find. If your work is going to be public, we would rather have it built on real data than on a sample. Academic, independent, CERT and student work all count, and we do not ask for an institution.

You get Pro's volume with the full history, because depth is the limit that decides whether a piece of work is possible at all. A ninety day window cannot answer a question about a campaign that ran longer than ninety days, at any request rate.

What we ask in return
  • You publish openly. A paper, blog post, talk, dataset or repository that anyone can read without paying or signing up.
  • You credit HoneyLabs. A link back, using one of the snippets below. That is the whole payment.
  • You share findings, not the raw dataset. Aggregates, figures and the specific indicators your work discusses are all fine. Republishing bulk raw data as a competing feed is not.
  • It is not inside a commercial product. Research that later turns into something commercial is fine, just talk to us when it does.

Email info@honeylabs.net with what you are looking into and roughly where it will be published. Two sentences is plenty, and if the work is already out there just send the link.

Attribution, ready to paste

Any of these is fine. A plain link in the text works too.

Plain text
HoneyLabs, honeypot threat intelligence. https://honeylabs.net (accessed 2026-08-27).
Markdown
Data from [HoneyLabs](https://honeylabs.net)
BibTeX
@misc{honeylabs,
  title  = {HoneyLabs: honeypot threat intelligence},
  author = {{HoneyLabs}},
  year   = {2026},
  url    = {https://honeylabs.net},
  urldate = {2026-08-27}
}
Past Team, or want the data on your own terms

Bulk delivery to a bucket you own, an on-premise copy, or a redistribution licence if HoneyLabs data is going into something you sell. None of that fits a credit budget, so it is priced against what you actually need rather than a tier.

Talk to us

In every plan, including Free

  • Full lookup, search and payload search
  • CVE probing data and early-actor attribution
  • REST API, MCP endpoint and TAXII 2.1
  • MISP feeds and Microsoft Sentinel connector
  • IOC feeds for firewalls and SIEMs

Questions worth answering up front

What is a credit?

One row of data returned. An enrichment lookup costs one credit, a hundred-row list costs a hundred. The meter follows what you actually pulled, so a careful query stays cheap.

What happens when I run out?

Requests return a quota error until the day rolls over at midnight UTC. Nothing is charged automatically and no overage appears on an invoice. If you hit the ceiling often, the next plan up is cheaper than the time you spend working around it.

Why is the history window the interesting limit?

Volume decides how many questions you can ask. Reach decides which questions can be answered at all. Tracking a campaign, or showing that a CVE was probed before it was published, needs history no request rate can substitute for.

Can I put this in a product I sell?

Yes on Team, and talk to us first so we can size it properly. Redistributing the raw dataset as a competing feed is the one thing no plan covers.

Are the free MISP feeds going away?

No. The exploiter and malware-infrastructure feeds ship in MISP's own defaults and stay anonymous and unmetered. They are how most people meet us and they are not a trial.

Can I cancel?

Any time, from the dashboard. Monthly plans stop at the end of the period you have paid for. Annual plans are refunded pro rata for whole unused months.