Monday, March 3, 2014

Trial and error

To get things started I've started researching some of the current honeypot tools and live linux distros centered on being honeypots.  Some of the ones I've found so far include :


  • Valhala : Looks to be a easy to use Windows based honeypot with a few services
  • Honeeepi : This one is based on using a Raspberry Pi using Dionaea
  • ADHD : A linux distro based on Ubuntu 12.04 but has more focus on a "strike back" approach. Use with caution :)
  • Stratagem : Another Linux based honeypot distro but based off Linux Mint 14
  • HoneyDrive : Another Linux honeypot but distributed in an OVA that you can import direct into VM Workstation/Fusion
  • KFSensor : A windows based one that has a professional/standalone edition as well as an enterprise edition that allows for a centralized management and logging for multiple sensors.  I have installed a trial version of this one to begin my tests.
I will let KFSensor run for a day or so and then review the findings.  I am not doing anything to attempt to drive traffic to my honeypot and just observing the traffic that is already hitting my own IP/Subnet.


No comments:

Post a Comment