BoarNet is on hiatus while we restructure infrastructure and funding. Sponsor checkout is disabled and existing paid subscriptions have been paused (not canceled). The tier structure below reflects what will be available when the project resumes — use the “notify me” links to be emailed when subscriptions reopen.
Contribute, sponsor,
or license the dataset.
BoarNet is a research honeypot fleet. Host a sensor and the data is free; sponsor one and we host for you. ML teams, threat-intel vendors, and academic labs license raw event snapshots — the same data we use, cleaned, sampled, and citable. No SIEM integrations, no SOC marketing.
Paste an IP, get a verdict with confidence and tags. Enough to settle a question; not enough to automate. The tier serious researchers use to triage before committing.
Spare Pi, $5 VPS, old laptop in your closet. After 48h of valid telemetry your key is promoted: full fingerprints, per-sensor sightings, 90-day history. The fastest path to research-grade access.
Can't host? Sponsor one. Your subscription funds a Core honeypot whose data you use. Full fingerprints, 180-day history, 2,000 req/hr — the same surface as Contributor, no hardware.
Bulk CSV exports, ML-friendly paginated API, 2-year history, deterministic ordering for reproducible queries. Cite the dataset in published work — non-commercial use included.
Raw event-level snapshots, dataset DOI for citation, full history, streaming feed. Co-authored disclosure on aggregate findings. For organizations that need to train, license, or republish.
The full capability matrix.
Exact enforcement — these values drive the rate limiter and field redactor in real time, so marketing and the API can't drift.
| Capability | Observer | Contributor | Sponsor | Researcher | Institutional |
|---|---|---|---|---|---|
| Rate limit | 100 / day | 1,000 / hour | 2,000 / hour | 100,000 / hour | Unlimited |
| History window | 7 days | 90 days | 180 days | 2 years | Full |
| Data freshness | 1h delay | Real-time | Real-time | Real-time | Real-time |
| Single IP lookup | ✓ | ✓ | ✓ | ✓ | ✓ |
| Verdict + confidence | ✓ | ✓ | ✓ | ✓ | ✓ |
| High-level tags | ✓ | ✓ | ✓ | ✓ | ✓ |
| Sensor sighting totals | ✓ | ✓ | ✓ | ✓ | ✓ |
| JA3 / JA4 / SSH fingerprints | — | ✓ | ✓ | ✓ | ✓ |
| Per-sensor sighting list | — | ✓ | ✓ | ✓ | ✓ |
| Commands & payloads | — | ✓ | ✓ | ✓ | ✓ |
| Bulk CSV / dataset export | — | Capped | Capped | ✓ | ✓ |
| ML-friendly paginated API | — | — | — | ✓ | ✓ |
| Raw event-level snapshots | — | — | — | Sampled | Full |
| Citation rights / dataset DOI | — | ✓ | ✓ | ✓ | ✓ + DOI |
| Quarterly research reports | Public | Public | Public | Early access | Pre-print |
| Requires running a sensor | No | Yes | No | No | No |
Limits are enforced by middleware and announced in response headers. The same limiter drives X-RateLimit-* on every call.
$7,500 — a 2-week threat brief from the fleet.
Fixed-scope research engagement. Pick an industry, ASN, geography, or attack pattern. We mine 16M+ honeypot events, deliver a 15-page analyst report with charts and pivots, and hand you a CSV of every relevant IP. Used by AI-security teams qualifying detection models and by threat-intel vendors filling coverage gaps. Often a faster path to the data you need than a recurring license.
- · Scoped to your question, not a generic feed
- · Raw IP/CSV deliverable included
- · 2-week turnaround from kickoff
- · Credit toward an annual license if you sign one