🚀 TG4G
DirectorySecurityhonoki.net
🛡 Security 📍 HQ: Unknown
H

honoki.net

Overall Rating
★★★☆☆ 6.0/10
China Access
★★★ China direct-connect friendly
Quick Check
Data source
ai_crawl · Last updated 2026-06-08

⚡ Score breakdown

5-dim weighted · /10
Performance25% 6.0
Value20% 6.0
China access20% 10.0
Reputation20% 5.6
Support15% 5.5

Dimension scores are derived from public data and fields; weighted into the composite. Reference only.

Editorial Highlights

Includes Bug Bounty, CVE, and security tool content.

In-Depth Review TG4G Review ·2026-06-08 · For reference only

What It Is

honoki.net is a personal blog focused on web security research, hands-on Bug Bounty work, and open-source tools. The article mainly highlights two tools: WILSON Cloud Respwnder and BBRF. The former is used for self-hosted DNS/HTTP interaction logging and notifications, serving as a long-term, controllable alternative to tools like Burp Collaborator or Interactsh. The latter is the Bug Bounty Reconnaissance Framework, designed to organize reconnaissance data such as domains, IPs, and program scope.

Core Capabilities

In terms of protection category, this is not a WAF, EDR, or vulnerability-scanning SaaS product. It is more of an offensive-security and vulnerability-verification aid. WILSON can log DNS and HTTP requests in real time, retain full HTTP requests including POST bodies, and send alerts to Slack or Discord. It can also customize content and DNS records via NGINX, PHP Web Server, and bind9. BBRF uses CouchDB as a central JSON document store, with a Python CLI for managing programs, inscope/outscope assets, domains, and IPs, and can be integrated into pipelines with tools such as subfinder.

Deployment, Pricing, and Integrations

Deployment is mainly self-hosted. WILSON requires a domain name, docker-compose, and a notification Webhook. BBRF can be deployed on a cloud server, local Docker, and also supports AWS Lambda/Serverless scenarios. The article does not mention commercial pricing or paid plans; only a comment notes that an AWS t3a.small costs about $13.5/month, while local deployment can reduce costs. Integrations are fairly open, relying on HTTP APIs, JSON, command-line pipelines, Slack/Discord Webhooks, NGINX, and bind9, making it suitable for building personal or small-team security testing workflows.

Pros and Cons

The strengths are closely aligned with real Bug Bounty pain points: WILSON addresses the limited time window of OOB interaction monitoring, while BBRF solves the problem of reconnaissance results being scattered across multiple tools and hard to reuse. The tools are open, self-hosted, and extensible. The downsides are also clear: there is no information on enterprise-grade compliance certifications, SLA, access governance, or commercial support. Deployment requires experience with DNS, Docker, CouchDB, and cloud services. BBRF also explicitly does not support URLs, ports, services, or IPv6, so its data model has limited coverage.

Who It’s For and Access from China

It is suitable for security researchers, bug bounty hunters, penetration testers, and small teams that want to build their own reconnaissance data warehouse or OOB callback monitoring service. It is not a good fit for large enterprises expecting an out-of-the-box product, procurement compliance, and unified reporting. The article does not discuss access from China. Dependencies such as GitHub, Slack, Discord, and AWS may involve network or payment uncertainty in mainland China. In practice, users could consider local Docker deployment, self-hosted notification channels, or alternative tool combinations such as Burp Collaborator, Interactsh, Amass, ffuf, and massdns.

⚠ This review is compiled from public sources and does not constitute a purchase recommendation. Verify all facts on the vendor's official site. Verify on honoki.net official site.

About this entry

honoki.net is an Unknown Security provider. TG4G tracks its product information, an overall rating of 6.0/10, and a China-accessibility score of China direct-connect friendly. Click "Visit Official Site" to reach honoki.net directly.

Get Started

Price not disclosed
Visit honoki.net official site →
External link · prices subject to vendor site

Frequently Asked Questions

What is honoki.net?
honoki.net is a Unknown-based Security provider. Includes Bug Bounty, CVE, and security tool content.
Is honoki.net good? Is it worth it?
honoki.net scores 6.0/10 on TG4G — a solid rating, based in 未知. See the in-depth review below for pros, cons and China accessibility.
Is honoki.net usable in China?
honoki.net offers good direct-connect performance in mainland China and works in most regions without a proxy. The provider is headquartered in Unknown and primarily serves overseas markets.
How do I sign up for honoki.net?
Visit the honoki.net official site to complete sign-up. Registration typically requires an email (Gmail/Outlook recommended) and a payment method. Most overseas services accept credit card / PayPal / crypto. See the "Visit Official Site" button on this page for the direct link.

Browse Other Categories

View the full directory →