>
Related Listings
- awesome-pcaptools Network Traffic Analysis
- awesome-malware-analysis Some overlap with the above, more focused on malware analysis
Honeypots
- Database Honeypots
- Delilah β An Elasticsearch honeypot written in Python
- ESPot β An Elasticsearch honeypot written in NodeJS for exploiting CVE-2014-3120
- Elastic honey β Simple Elasticsearch honeypot
- HoneyMysql β Simple Mysql honeypot
- MongoDB-HoneyProxy β MongoDB honeypot proxy
- MongoDB-HoneyProxyPy β A MongoDB honeypot proxy using Python 3
- NoSQLpot β NoSQL honeypot framework
- mysql-honeypotd β Low-interaction MySQL honeypot in C
- MysqlPot β MySQL honeypot
- pghoney β Low-interaction Postgres honeypot
- sticky_elephant β Medium-interaction PostgreSQL honeypot
- Web Honeypots
- HonnyPotter β WordPress login honeypot for collecting and analyzing failed login attempts
- HoneyPress β A Python-based WordPress honeypot in Docker container
- wp-smart-honeypot β WordPress plugin to reduce spam
- wordpot β WordPress honeypot
- Snare β Next-generation high-interaction honeypot
- Tanner β Evaluate SNARE events
- Bukkit Honeypot Honeypot β A plugin for Bukkit
- EoHoneypotBundle β Symfony2 type honeypot
- Glastopf β Web application honeypot
- Google Hack Honeypot β Designed to provide reconnaissance against attackers probing resources using search engines
- Laravel Application Honeypot β Honeypot β A simple spam prevention package for Laravel applications
- Nodepot β NodeJS web application honeypot
- Servletpot β Web application honeypot
- Shadow Daemon β Modular web application firewall/high-interaction honeypot for PHP, Perl, and Python
- StrutsHoneypot β Struts-based Apache 2 honeypot
- WebTrap β Designed to create deceptive web pages that redirect to real sites
- basic-auth-pot (bap) β HTTP Basic Authentication honeypot
- bwpot β Web application honeypot
- django-admin-honeypot β A fake Django admin login page to record unauthorized access attempts
- drupo β Drupal honeypot
- honeyhttpd β Tool for building a web server honeypot in Python
- phpmyadmin_honeypot β Simple and effective phpMyAdmin honeypot
- shockpot β Web application honeypot for detecting Shell Shock exploit attempts
- smart-honeypot β Intelligent honeypot written in PHP scripts
- Snare/Tanner β Successor to Glastopf
- stack-honeypot β Inserts traps for spam bots into responses
- tomcat-manager-honeypot β Tomcat honeypot. Logs requests and saves attackerβs WAR files
- WordPress honeypots
- Service Honeypots
- ADBHoney β Low-interaction honeypot for Android.
- AMTHoneypot β Honeypot for Intelβs AMT firmware vulnerability (CVE-2017-5689)
- Ensnare β Easily deployable Ruby honeypot
- HoneyPy β Low-interaction honeypot
- Honeygrove β Multipurpose, modular honeypot based on Twisted
- Honeyport β Simple honeyport written in Bash and Python
- Honeyprint β Printer honeypot
- Lyrebird β Modern high-interaction honeypot framework
- MICROS honeypot β Low-interaction honeypot for detecting CVE-2018-2636 in Oracle Hospitality Simphony
- RDPy β RDP honeypot implemented in Python
- SMB Honeypot β High-interaction SMB honeypot capable of catching malware like Wannacry
- Tomβs Honeypot β Low-interaction Python honeypot
- WebLogic honeypot β Low-interaction honeypot for detecting CVE-2017-10271 in Oracle WebLogic Server
- WhiteFace Honeypot β Honeypot against WhiteFace, developed on Twisted
- honeycomb_plugins β Repository for Honeycomb plugins, Cymmetriaβs honeypot framework
- honeyntp β NTP honeypot
- honeypot-camera β Camera honeypot
- honeypot-ftp β FTP honeypot
- honeytrap β Advanced honeypot framework written in Go, able to connect to other honeypots
- pyrdp β Python 3-man-in-the-middle library for RDP able to monitor connections
- troje β LXC container-based honeypot encapsulating connections for each service in individual LXC containers
- Distributed Honeypots
- DemonHunter β Low-interaction honeypot server
- Anti-Honeypot
- kippo_detect β Detect Kippo honeypots
- ICS/SCADA Honeypots
- Conpot β ICS/SCADA honeypot
- GasPot β Veeder Root Gaurdian AST, commonly found in oil and gas industries
- SCADA honeynet β Creating honeypots for industrial networks
- gridpot β Open-source honeypot mimicking a real grid
- scada-honeynet β Simulates popular PLC services to aid SCADA researchers in better understanding risks to exposed control system devices
- Others/Random
- DSHP β Simple honeypot with plugin support
- NOVA β Honeypot that looks like a complete system
- OpenFlow Honeypot (OFPot) β A POX-based OpenFlow honeypot redirecting traffic from unused IP addresses to honeypots
- OpenCanary β Modular, distributed honeypot
- ciscoasa_honeypot β Low-interaction honeypot for Cisco ASA detecting CVE-2018-0101 Remote Code Execution vulnerability
- miniprint β Medium-interaction honeypot for printers
- Botnet C&C Tools
- Hale β Botnet C&C Monitor
- dnsMole β Analyzes DNS traffic to detect potential botnet C&C servers and infected hosts
- IPv6 Attack Detection Tools
- ipv6-attack-detector β A Honeynet Project-supported Google Summer of Code 2012 project
- Dynamic Code Inspection Toolkit
- Frida β Injects JavaScript to explore apps on Windows, Mac, Linux, iOS, and Android
- Turn a Website into a Server Honeypot
- HIHAT β Converts any PHP page into a web-based high-interaction honeypot
- Malware Collection
- Kippo-Malware β Python script to download malicious files from URLs logged in the Kippo SSH honeypot database
- Distributed Sensor Deployment
- Modern Honey Network β Distributed management of Snort and honeypot sensors, employing virtual networks and minimal fingerprint SNORT installations, with servers offering stealth reconnaissance and centralized management
- Network Analysis Tools
- Tracexploit β Replay network packets
- Log Anonymization Tools
- LogAnon β Log anonymization library
- Low-interaction Honeypot (Router Backdoor)
- Honeypot-32764 β Router backdoor honeypot (TCP 32764).
- WAPot β Honeypot capable of observing traffic from home routers
- HTTPS Proxy
- mitmproxy β Intercept, inspect, modify, and replay traffic
- System Instrumentation
- Sysdig β Open-source system exploration tool for capturing Linux system state/activity, capable of saving, filtering, and analyzing
- Fibratus β Tool for exploring and tracing the Windows kernel
- Honeypot for Detecting USB Malware Spread
- Ghost-usb β Honeypot to detect malware spreading through USB storage devices
- Data Acquisition
- Kippo2MySQL β Extracts basic statistics from Kippo log files to insert into a database
- Kippo2ElasticSearch β Python script for transferring Kippo SSH honeypot data from a MySQL database to an ElasticSearch instance (server or cluster)
- Passive Network Audit Framework Analysis Tools
- Passive Network Audit Framework (pnaf) β Passive network audit framework
- Virtual Machine Monitoring Tools
- Antivmdetect β Script for creating VirtualBox VM templates that make virtual machine detection harder
- VMCloak β Automatic VM generation and cloaking for Cuckoo sandbox
- vmitools β C library with Python interface to easily monitor the low-level details of running VMs
- Binary Debugger
- Hexgolems β Pint Debugger Backend β A debugger backend with Pinβs Lua interface
- Hexgolems β Schem Debugger Frontend β A debugger frontend
- Mobile Application Analysis Tools
- Androguard β Reverse engineering tool for Android apps
- APKinspector β Android app analysis tool with a GUI
- Low-interaction Honeypots
- Honeyperl β Perl-based honeypot with many plugins
- T-Pot β Honeypot provided for telecom provider T-Mobile
- Honeypot Data Fusion
- HFlow2 β Data fusion tool for honeypot/network analysis
- Server
- Amun β Vulnerability simulation honeypot
- Artillery β Open-source blue team tool designed to protect Linux and Windows OS through various methods
- Bait and Switch β Honeypot redirecting malicious traffic to a production system image
- Bifrozt β Automated deployment with ansible for bifrozt
- Conpot β Low-interaction Industrial Control System honeypot
- Heralding β Credential capturing honeypot
- HoneyWRT β Low-interaction honeypot in Python, designed to mimic services or ports attackers might target
- Honeyd See more honeyd tools
- Honeysink β Open-source network sinkhole providing mechanisms to detect and stop malicious traffic on a specified network
- Hontel β Telnet honeypot
- KFSensor β Windows-based Intrusion Detection System honeypot
- LaBrea β Takes over unused IP addresses, creating virtual services attractive to worms and hackers
- MTPot β Open-source Telnet honeypot focusing on Mirai
- SIREN β Semi-intelligent honeypot network β a honeynet only virtual environment
- TelnetHoney β Simple telnet honeypot
- UDPot Honeypot β Simple UDP/DNS honeypot script
- Yet Another Fake Honeypot (YAFH) β Simple honeypot written in Go
- arctic-swallow β Low-interaction honeypot
- glutton β Feedable honeypot
- go-HoneyPot β Honeypot written in Go
- go-emulators β Go honeypot emulators
- honeymail β SMTP honeypot written in Go
- honeytrap β A low-interaction honeypot for capturing attacks against TCP and UDP services
- imap-honey β IMAP honeypot written in Go
- mwcollectd β Multifunctional malware collecting honeypot combining the best features of nepenthes and honeytrap
- potd β Low to medium-interaction SSH/TCP honeypot for OpenWrt/IoT devices built with Linux Namespaces, Seccomp, and Capabilities
- portlurker β Port listening tool/honeypot for protocol guessing and secure character display
- slipm-honeypot β Simple low-interaction port listening honeypot
- telnet-iot-honeypot β Telnet honeypot written in Python to capture botnet binaries
- telnetlogger β Telnet honeypot tracking Mirai
- vnclowpot β Low-interaction VNC honeypot
- IDS Signature Generation
- Honeycomb β Automatically create signatures using honeypots
- Find ASN and prefix for service providers
- CC2ASN β Simple query service
- Data Collection/Data Sharing
- HPFeeds β Lightweight authenticated subscription/publishing protocol
- Centralized Management Tools
- PHARM β Manage, statistic, analyze your distributed Nepenthes honeypots
- Network Connection Analysis Tools
- Impost β Network security auditing tool for forensic analysis of compromised/vulnerable daemons
- Honeypot Deployment
- Modern Honeynet Network β Simplifies the management and deployment of honeypots
- Wireshark Honeypot Extensions
- Whireshark Extensions β Supports applying Snort IDS rules and signatures against PCAP files
- Client-side Honeypots
- CWSandbox / GFI Sandbox
- Capture-HPC-Linux
- Capture-HPC-NG
- Capture-HPC β High-interaction client honeypot
- HoneyBOT
- HoneyC
- HoneySpider Network β A scalable system integrating multiple client honeypots to detect malicious websites
- HoneyWeb β Web interface developed for managing and remote sharing of Honeyclients resources
- Jsunpack-n
- MonkeySpider
- PhoneyC
- Pwnypot β High-interaction client honeypot
- Rumal
- Shelia
- Thug
- Thug Distributed Task Queuing
- Trigona
- URLQuery
- YALIH (Yet Another Low Interaction Honeyclient) β A low-interaction client honeypot aimed at detecting malicious websites through signature, anomaly, and pattern-matching techniques
- Honeypots
- Deception Toolkit
- IMHoneypot
- PDF Document Inspection Tools
- peepdf
- Hybrid Low/High Interaction Honeypots
- HoneyBrid
- SSH Honeypots
- Blacknet β SSH honeypot system
- Cowrie β Cowrie SSH honeypot (based on Kippo)
- DShield docker β Docker container with DShield output enabled
- HonSSH β Records all SSH communications between clients and servers
- HUDINX β Low-interaction SSH honeypot for brute-force logging, logs full shell interaction of attackers
- Kojoney
- Kojoney2 β Low-interaction SSH honeypot written in Python based on Kojoney
- Kippo β Medium-interaction SSH honeypot
- Kippo_JunOS β Kippo-based honeypot
- Kojoney2 β Low-interaction SSH honeypot written by Jose Antonio Coret based on Kojoney
- Kojoney β Python-based low-interaction honeypot using Twisted Conch to emulate SSH service
- LongTail Log Analysis @ Marist College β Analyzes SSH honeypot logs
- Malbait β TCP/UDP honeypot implemented in Perl
- MockSSH β SSH server supporting defined command set
- cowrie2neo β Parses cowrie honeypot logs into neo4j database
- go-sshoney β SSH honeypot
- go0r β Simple SSH honeypot written in Go
- gohoney β SSH honeypot in Go
- hived β Honeypot written in Go
- hnypots-agent β SSH server recording username and password combinations
- honeypot.go β SSH honeypot in Go
- honeyssh β SSH honeypot for dumping credentials
- hornet β Medium-interaction SSH honeypot with multi-virtual host support
- ssh-auth-logger β Low/zero interaction SSH honeypot
- ssh-honeypot β Fake SSHD logging IP addresses, usernames, and passwords
- ssh-honeypot β Modified OpenSSH DEAMON forwarding commands to Cowrie
- ssh-honeypotd β Low-interaction SSH honeypot in C
- sshForShits β High-interaction SSH honeypot framework
- sshesame β Fake SSH server logging login activities
- sshhipot β High-interaction SSH man-in-the-middle honeypot
- sshlowpot β Low-interaction SSH honeypot in Go
- sshsyrup β Simple SSH honeypot captures terminal activities and uploads to asciinema.org
- twisted-honeypots β Twisted-based SSH\FTP\Telnet honeypots
- Distributed Sensor Project
- DShield Web Honeypot Project
- PCAP Analysis Tools
- Honeysnap
- Network Traffic Redirection Tools
- Honeywall
- Hybrid Content Distributed Honeypot
- HoneyDrive
- Honeypot Sensors
- Honeeepi β Honeypot based on a custom Raspbian OS on a Raspberry Pi
- File Carving
- TestDisk & PhotoRec
- Behavior Analysis Tools for Windows
- Capture BAT
- Live CD
- DAVIX β DAVIX Released
- Spamtrap
- Shiva The Spam Honeypot Tips And Tricks For Getting It Up And Running
- Mail::SMTP::Honeypot β Perl module providing utilities for standard SMTP server
- Mailoney β SMTP honeypot written in Python, features open relay, credential recording, etc.
- SendMeSpamIDS.py β Simple SMTP that gets all IDS and analysis devices
- Shiva β Spam honeypot and smart analysis tool
- SpamHAT β Spam honeypot tool
- Spamhole
- honeypot β Unofficial PHP SDK for honeypot project group
- spamd
- Commercial Honeynet
- Cymmetria Mazerunner β Can lead attackers away from real targets and create attack trace tracking
- Server (Bluetooth)
- Bluepot
- Android Application Dynamic Analysis
- Droidbox
- Dockerized Low-interaction Honeypot
- Docker honeynet β Deploy several honeynet tools in Docker containers
- Dockerized Thug β Thug-based Docker honeypot for analyzing malicious web content
- Dockerpot β Honeypot based on Docker
- Manuka β Docker-based honeypot (Dionaea & Kippo).
- mhn-core-docker β Core elements of modern honeynet implemented in Docker
- Network Analysis
- Quechua
- SIP Server
- Artemnesia VoIP
- IOT Honeypot
- HoneyThing β TR-069 honeypot
- Kako β Honeypot for common vulnerabilities in embedded devices
- Honeytokens
- CanaryTokens β Honeytoken generator, Dashboard at CanaryTokens.org
- Honeybits β Aims to lure attackers into honeypots by spreading breadcrumbs and honeytokens in production servers and workstations
- HoneyΞ» (HoneyLambda) β Simple serverless app to create and monitor URL honeytokens atop AWS Lambda and Amazon API Gateway
- dcept β Deploy, detect Active Directory usage honeytokens
- honeyku β Heroku-based web honeypot
Honeyd Tools
- Honeyd Plugins
- Honeycomb
- Honeyd Visualization Tools
- Honeyview
- Honeyd and MySQL Connection
- Honeyd2MySQL
- Honeyd Visualization Scripts
- Honeyd-Viz
- Honeyd Statistics
- Honeydsum.pl
Network and Behavior Analysis
- Sandbox
- Argos β Emulator for capturing zero-day attacks
- COMODO automated sandbox
- Cuckoo β Leading open-source automated malware analysis system
- Pylibemu β Libemu Cython
- RFISandbox β Sandbox built on funcall using PHP 5.x scripts
- dorothy2 β Malware/botnet analysis framework in Ruby
- imalse β Integrated malware emulation and simulation tool
- libemu β Shellcode emulation library, highly useful for shellcode detection
- Sandbox as a Service
- Hybrid Analysis β Free malware analysis service by Payload Security leveraging its unique hybrid analysis technology to detect and analyze unknown threats
- Joebox Cloud β Determines the behavior of malicious files (including PE, PDF, DOC, PPT, XLS, APK, URL, and MachO) on Windows, Android, and Mac OS X, assessing for suspicious activities
- VirusTotal
- malwr.com β Offers free malware analysis services and community
Data Analysis Tools
- Frontend
- DionaeaFR β Dionaea honeypot frontend web
- Django-kippo β Django application for kippo SSH honeypot
- Shockpot-Frontend β Script for visualizing data from Shockpot honeypot
- Tango β Uses Splunk to process honeypot intelligence
- Wordpot-Frontend β Script for visualizing data from Wordpot honeypot
- honeyalarmg2 β Simplified UI for displaying honeypot data
- honeypotDisplay β Flask site for displaying SSH honeypot
- Visualization
- Acapulco β Automated attack group graph construction
- Afterglow Cloud
- Afterglow
- Glastopf Analytics β Simple honeypot statistics
- HoneyMalt β Maltego conversions mapping honeypot system
- HoneyMap β Display real-time SVG maps of Websocket streams
- HoneyStats β Statistical view of the honeynet
- HpfeedsHoneyGraph β Program for visualizing hpfeeds logs
- Kippo stats β Program for displaying data for the kippo SSH honeypot
- Kippo-Graph β Script for visualizing data from Kippo honeypot
- The Intelligent HoneyNet β Project to attempt the creation of actionable intelligence in the honeypot system
- ovizart β Visualization of network traffic analysis
Guide
-
- T-Pot: Multi-honeypot platform
- Honeypot (Dionaea and kippo) setup script
- Deployment
- Dionaea and EC2 in 20 Minutes β Tutorial on setting up Dionaea on EC2
- Using a Raspberry Pi honeypot to contribute data to DShield/ISC β A system based on Raspberry Pi can collect richer logs than firewall logs
- honeypotpi β Script for turning a Raspberry Pi into a HoneyPot Pi
- Research Papers
- Honeypot research papers β PDF of research papers on honeypots
- vEYE β Detection and analysis of self-propagating worm behavior traces
Download link: https://github.com/paralax/awesome-honeypots/blob/master/README_CN.md