Showing posts with label DFIR. Show all posts
Showing posts with label DFIR. Show all posts

Monday, March 3, 2014

Trial and error

To get things started I've started researching some of the current honeypot tools and live linux distros centered on being honeypots.  Some of the ones I've found so far include :


  • Valhala : Looks to be a easy to use Windows based honeypot with a few services
  • Honeeepi : This one is based on using a Raspberry Pi using Dionaea
  • ADHD : A linux distro based on Ubuntu 12.04 but has more focus on a "strike back" approach. Use with caution :)
  • Stratagem : Another Linux based honeypot distro but based off Linux Mint 14
  • HoneyDrive : Another Linux honeypot but distributed in an OVA that you can import direct into VM Workstation/Fusion
  • KFSensor : A windows based one that has a professional/standalone edition as well as an enterprise edition that allows for a centralized management and logging for multiple sensors.  I have installed a trial version of this one to begin my tests.
I will let KFSensor run for a day or so and then review the findings.  I am not doing anything to attempt to drive traffic to my honeypot and just observing the traffic that is already hitting my own IP/Subnet.


Sunday, March 2, 2014

Getting things rolling

I'm starting this blog to help track a new project of interest to me.  I am going to set up my own honeypot in order to create and collect random suspicious or malicious activity on the internet.  I plan to use this data to create my own incident response scenarios in a controlled environment, analyze current trends on cyber threats, and ultimately just to learn and have a little bit of fun.

Please feel free to send me any ideas or feedback based on your experience, research, or similar projects.

Happy hunting!