Skip to main content

Install

Sundew is now running on http://localhost:8080 with a randomly generated persona.

Explore what’s running

Open a second terminal and see what AI agents would discover:
Every response is shaped by the persona. A different deployment would have completely different endpoints, company names, and data.

Query captured sessions

After traffic has flowed through:

Use with Claude (MCP)

Add Sundew as an MCP server to query your honeypot data directly from Claude:

Next steps

How it works

Understand the full architecture

Configuration

Customize traps, LLM, and storage

Custom personas

Build industry-specific personas

Deployment

Production deployment with Docker