home.social

#honeypots — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #honeypots, aggregated by home.social.

fetched live
  1. I read CISA’s new report on using cyber decoys to strengthen detection and response, and it’s very philosophically aligned with the work I’ve done on Intrusion Detection Honeypots (IDHs).

    I’ve been beating this drum for years: properly deployed internal honeypots are one of the best bargains in detection.

    #DFIR #IDS #Honeypots

  2. What Happens in the First 24 Hours After a New Asset Goes Live
    The First 24 Hours: A Technical Timeline
    T+5 to T+60 minutes: The scanners find it.
    T+1 to T+6 hours: Enumeration begins.
    T+6 to T+12 hours: Active probing.
    T+12 to T+24 hours: Compromise.
    They deployed 320 #honeypots across cloud providers (RDP, SSH, SMB, Postgres) to see what would happen. 80% were compromised within 24 hours.
    bleepingcomputer.com/news/secu
    #Security #ITSec #IT

  3. T-minus 10 days!!!

    In #CyberSecurity terms, I'm about to deliberately walk into an entirely new threat landscape with no local threat intel, a foreign language I'm still actively patching. The attack surface has changed. The adversaries are now cobblestones, bureaucratic Portuguese, and the very real possibility that I will confidently order the wrong thing at a restaurant and just go with it. Threat level: manageable. Vibes: elevated!!

    The honeypots aren't moving. They never do - that's the whole point. They stay scattered where they are, quietly doing their thing, collecting everything. The only thing changing is where the intel gets delivered. Starting April 29th, that's Porto.

    I'm a little concerned they're going to start sending it in #Portuguese. 🤷‍♀️

    Half my home lab is already there ahead of me. ZimaBoard, #opnsense the Pis - all running, all waiting, probably judging me for not arriving sooner. Home Assistant is next on the list once I land, which means I get to find out whether my automations survived the relocation or whether I'm about to have a very intimate conversation with Portuguese error messages. Could go either way.

    And yes, I'm leaving behind the Chicago "L". The L. An elevated rail system so charmingly held together by decades of deferred maintenance and sheer Chicagoan stubbornness that honestly, it's kind of a security metaphor. I'm going to miss the ambiance of a train that sounds like it's actively negotiating with physics.

    The Metro stop is literally across the street from my apartment. It's clean. It's modern. It's quiet. The trains run on time. I don't know how I'll cope. 👀

    @sashatheflamingo is excited but has concerns about the cobblestones hurting her feet. I told her she can ride on my shoulder. Problem solved. The flamingo adapts. 🦩

    And if you're in the security community and haven't looked at #BSidesPorto yet - June 26th and 27th - I don't know what to tell you except that you're going to miss an awesome event if you don't get your tickets - NOW! And come find me. I'll be the one who showed up 60 days before the conference and is still figuring out which bus/metro train goes where.

    The operation doesn't stop. It just changes coordinates. The #honeypots already know. They figured it out before I told them. (That's kind of their whole thing.)

  4. It auto detects #fraud and punishes #reputation. It launches random #honeypots and does tests. Booyah. No free riders. But then everybody rides for free. You're going to understand me, sometime. 💃🏻💃🏻💃🏻

  5. ----------------

    🛠️ Tool
    ===================

    Executive summary: NeroSwarm Deception Lab is a lightweight collection of deception utilities aimed at surfacing intrusions early. The suite bundles a Smart HoneyTokens engine for document-based triggers, a Honeypots Code Generator that emits low-interaction honeypot scripts, and an IP Threat Reputation Checker tied to a tactical database.

    Technical details:
    • Smart HoneyTokens Engine: generates document artifacts that act as early-warning signals when accessed or modified. These artifacts can embed identifiable markers and metadata to attribute access events and trigger alerts.
    • Honeypots Code Generator: produces simple, low-interaction honeypot scripts intended for network-level observation. The generated artifacts focus on service emulation and basic protocol responses to capture connection attempts and probe behavior without full application emulation.
    • IP Threat Reputation Checker: queries an internal database to map IPs to observed tactics, techniques, and procedural indicators. Outputs are oriented toward threat classification and can enrich telemetry with contextual notes about actor behaviors.

    Implementation concepts:
    • Lightweight sandboxing emphasizes minimal host impact and quick deployment for experimentation rather than production-grade containment.
    • Document-based honeytokens rely on detectable file access patterns and metadata changes rather than deep behavioral simulation.
    • Low-interaction honeypots prioritize broad visibility and low resource consumption, trading fidelity for scale.

    Use cases:
    • Training SOC analysts on deception-based detection workflows.
    • Rapid proof-of-concept validation for detection logic using reproducible artifacts.
    • Enrichment of incident triage by correlating IP reputation metadata with observed interactions.

    Limitations and considerations:
    • Low-interaction honeypots inherently limit attacker engagement and may miss nuanced post-exploitation activity.
    • Document honeytokens can produce false positives if legitimate processes access the artifacts without appropriate tagging.
    • Reputation outputs depend on the coverage and freshness of the underlying database; gaps in telemetry can reduce usefulness.

    Final note: NeroSwarm positions itself as an experimentation and training sandbox for cyber deception techniques rather than a turnkey production deception platform. The suite provides practical primitives—honeytokens, basic honeypots, and IP context—that can inform detection rules and analyst workflows.

    🔹 deception #honeytokens #honeypots #ip_reputation #bookmark

    🔗 Source: lab.neroswarm.com/

  6. Not all threat intelligence tells the same story.

    🍯Honeypots show internet noise. Production telemetry shows what attackers actually do when real businesses are on the line.

    Understanding the difference is the key to actionable security.

    Learn more in our latest article 👉 crowdsec.net/blog/honeypots-vs

    #threatintelligence #honeypots #vulnerabilities #cybersecurity

  7. Some #honeypots are made, and some form themselves. The employee rosters of #ICE and #DHS have gathered the identifying information of many fascists for us to use when it is time to punish them.

    #antifa

  8. Dear Friends of Social Media,

    Decided not to use computers today and certainly no social media. Fail? Yes! [lobster hangs head in shame] :mastodondance:

    So whilst I am here some honey for the security nerds (probably bit out of date or known)
    honeynet.org/projects/

    Not sure if it is suitable for cyber apiary control as bees are scarce in our garden at the moment. Flowers all shivering. 🥶

    I hope everyone is as well as can bee. Yep a pun-full dad joke. :hearthands: 🦞 :ablobwave:

    #Honeypots #Security

  9. Honeypots, when set up correctly, can become sensors that reveal attacker behavior. Add that with Suricata's rules and tuning, and they can provide clear, named alerts that cut away the noise.

    Our Luke Davis set up a T-Pot with Suricata for 3 days, and it flagged probes for OpenSSH “regreSSHion” (CVE-2024-6387) and Treck TCP/IP (CVE-2020-11910), as well as highlighting cloud IP scanning.

    Honeypots can be great as an early detection method and a hands-on training tool for students, SOC analysts, and Blue Teams to practise detection and response in safe environments.

    📌Read the full blog here: pentestpartners.com/security-b

    #CyberSecurity #Honeypots #Suricata #ThreatDetection #BlueTeam

  10. 🦩🎤 @sashatheflamingo here: @bsidesedmonton Track One is now officially a flamingo zone this afternoon!

    At 1:30 Kat is unleashing her honeypot talk (spoiler: traps, tricks, and a few flamingo-sized surprises) — and I have insisted on emceeing that exact track because, let’s be honest, Kat needs supervision.

    So if you hear squawking from the stage, don’t panic — it’s just Sasha making sure Kat sticks to time and doesn’t start talking about dancing flamingos in RAID10 again. 😉

    Come flap with us at #BSidesEdmonton — Track One, 1:30pm.
    Quirky chaos guaranteed. 🦩🪂

    #cybersecurity #honeypots

  11. **Sasha's Honeypot Diary: Entry #47**

    *Sigh.* Another morning, another 125 idiots knocking on my digital door.

    Do these bots ever get tired? I've been watching the same IP addresses try "admin/password123" on my fake WordPress sites for OVER A YEAR. Like, guys... take a hint? I'm starting to feel bad for them. It's like watching someone repeatedly walk into a glass door.

    This week they discovered the username "support" and honestly? They're acting like they invented fire. 100+ attempts yesterday, 125 this morning. Such enthusiasm! Such determination! Such complete lack of learning ability!

    My favorite part is watching them cycle through usernames from a 20-year-old government breach like it's fresh intelligence. Fellas, that data is older than some of the smartphones you're probably using to run these attacks.

    But hey, keep it coming! My honeypots are hungry, my threat intelligence dashboard is beautiful, and my BSides presentation just got 125 more data points.

    🦩

    The persistence is almost admirable. Almost.

    #ThreatIntel #Honeypots #CyberSecurity #BotnetFails #PersistentButNotSmart

    P.S. - To the botnet hitting me from Singapore: your user-agent strings are hilariously obvious. Just saying.

  12. Any recommended #honeypots? I have a project with multiple honeypots running in Docker that I update every year for @defcon - does anyone have a honeypot they like or recommend? I have old ones, some are updated, some I'll need to find replacements for, so it's a WIP, but this will be up to date and ready for the con as always! #cancelled github.com/philcryer/prickly-p

  13. Well flap my wings and call me exhausted— @bsidespgh was a TOTAL BLAST! 🦩💥

    Over 1,000 amazing humans showed up, and I shook every feather I had meeting new friends, cheering on brilliant talks, and strutting through the best hallway track east of the Mississippi.

    My human @rnbwkat (you know, the clever one who wrangled the #CFP and gave that worldwide honeypot talk) absolutely crushed it. So many smart, quirky, and inspiring sessions—and not a single boring PowerPoint voice in sight.

    I made friends. I crashed photos. I may have stolen a pierogi.
    No regrets.

    Huge thanks to the organizers, speakers, volunteers, sponsors and all the wonderful folks who made BSidesPGH a sparkling success!! We’ll be dreaming of skyline bridges and cyber-magic until next time. 💖✨

    #BSidesPGH #CyberFlock #CyberSecurity #Honeypots
    #DEI #FlamingoUprising

  14. @bsidespgh 2025 is officially in the record books—and what a ride it was!

    Over 1,000 curious minds, incredible talks, hallway tracks that never quit, and a flamingo who may or may not have photobombed every other selfie!

    I had the honor of running the #cfp this year, and I’m beyond proud of the diverse, insightful, and thought-provoking sessions our speakers delivered. I also had the chance to share stories from around the globe—of honeypots, deception, and the strange things attackers do when they think no one’s watching.

    Sasha and I had an amazing time connecting with old friends and making plenty of new ones. From the badge hunt to after-party shenanigans (and yes, she did sneak a pierogi or two), this community continues to inspire us with its creativity and heart! ❤️

    Thanks to everyone who made this event a massive success. Pittsburgh, you brought the 🔥

    Until next time,
    🦩💻💖

    #BSidesPGH #Honeypots #Cybersecurity @sashatheflamingo

  15. Just listed a few hand-thrown ceramic honey jars in my glaze combination, "Sea Foam!"

    #pottery #ceramics #handmade #honeypots #giftsunder30

  16. 💻🦩✨ Today’s the day, darlings! ✨🦩💻

    I’ve landed in Leeds and I’m wired (literally) to share all the juicy details of my global honeypot escapades at #BSidesLeeds. With my human sidekick @rnbwkat doing the button-clicking, I’ll be flapping through stories of cyber traps, curious attackers, and the delicious chaos of deception done right. 💅🔥

    Massive feathery hugs to the @bsidesleeds crew—you’ve rolled out the pink carpet like absolute pros. 💜 You make this flamingo feel right at home.

    Let’s make some security magic today!
    — Sasha 🦩🕶️🌍

    #Honeypots #CyberSecurity #hacking

  17. 🎉 TODAY’S THE DAY! 🎉

    @sashatheflamingo has officially landed in Leeds—and guess what? She’s not just here to strut her stuff (though, let’s be real, the strutting is fabulous). With a little help from her human (that’s me! 😄), Sasha is taking the stage at #BSidesLeeds to talk about her global #honeypot mischief—er, network.

    Huge shoutout to the BSidesLeeds team for all the incredible work they’ve put in—this community is fierce, friendly, and fantastically nerdy. 💜

    Let’s do this, Leeds! 🦩✨ #SashaTheFlamingo #cybersecurity #honeypots @bsidesleeds

  18. Anyone who seeks for a well-written analysis of unsolicited #TCP traffic should give Decoding TCP SYN for Stronger Network Security a read. The blog post goes into TCP-procotol specifications. Recommended to every #networkengineer .

    Props go to @jtk for his strong analytical skills and excellent writing style.

    #honeypots #tcpflood #tcpsyn #networkanomaly #netsec #ddos

  19. Sometimes you have to scratch your head and wonder when you see 1000+ attempts at logins for "xtw183874b06" across a dozen of your #honeypots ???

    #CyberSecurity #interesting

  20. Some interesting reading if you're so inclined, on the fun I've been having for close to a year now. #honeypots #cybersecurity @sashatheflamingo

    bsideschicago.org/kat-skratche

  21. 🦩✨ Sasha’s Step 2: Now With Extra Chaos ✨🦩

    So, you built a #honeypot. You watched a few bots faceplant into your fake SSH server. You got a taste of deception and now you're craving MORE.

    Let me introduce you to your next obsession: ADHD (Active Defense Harbinger Distribution) from the fine humans at Black Hills InfoSec.

    💻 It’s a full Linux distro pre-loaded with tools for:
    🎣 Honeypots
    🚨 Honeytokens
    🪤 Tarpits
    🧃 Credential bait
    ⚠️ And general attacker frustration

    ADHD is like a honeypot buffet—with all the weird sauces already installed. Want to frustrate attackers with Endless SSH? Drop them in a Maze. Want to play with Kippo, Glastopf, or Artillery without building from scratch? ADHD says, “Come on in, the traps are fine.”

    BUT LISTEN: This is not something you drop on your public-facing VPS or neighbor’s Comcast router. This is #homelab territory only. Sandboxed. Segmented. Safe. (Or Sasha will give you The Look™.)

    Download it here:
    👉 blackhillsinfosec.com/tools/ad

    Flap wisely, my friends.
    #Honeypots #CyberDeception #SashaTheDancingFlamingo #InfosecFun @rnbwkat

  22. With our team at Stratosphere Laboratory AIC FEE CTU, we are organising this year's Honeynet Project Workshop 2025 in Prague!

    It will be a unique space to share your passion for deception technologies, honeypots, and cybersecurity with industry leaders and fellow researchers!

    🔔 We are looking for sponsors who want to support deception research!
    🔔 Early birds are still open until April 29th! Grab your tickets!
    🔔 Last days to submit your training and talks proposals!
    🔔 Students can apply for a Cédric Blancher Memorial Scholarship!

    This is the first time the conference is coming to Prague, with previous editions hosted in Copenhagen (2024), Innsbruck (2019), Taipei (2018), Canberra (2017), San Antonio (2016), Stavanger (2015), Warsaw (2014), Dubai (2013), San Francisco (2012), Paris (2011), Mexico City (2010) and Kuala Lumpur (2009).

    What a unique opportunity!

    🔗 prague2025.honeynet.org/

    Boost and help us spread the word! 👾

    #honeynet #cybersecurity #deception #honeypots #infosec #prague #praguetoday #SecurityConference #ThreatIntel #MalwareAnalysis #PragueEvents

  23. As I’ve tried to understand MCP, I am struck by something, and I am wondering if I’m somehow not finding crucial literature (or it's not prominently featured enough). The majority of what I read talks about orgs standing up a local MCP server in front of their various services. What I am barely seeing is guidance on how those MCP servers should be designed/deployed to securely protect the access credentials (API Keys, SSH Keys, or long-lived tokens) the MCP server will need to accomplish this. Am I missing something, or are we speedrunning towards a new #security nightmare?
    #NHI #API #Honeypots
    (On a related note, I highly encourage everyone to read Aaron Parecki's post about OAuth and MCP: aaronparecki.com/2025/04/03/15)

  24. Ars Technica: Cloudflare turns AI against itself with endless maze of irrelevant facts. “On Wednesday, web infrastructure provider Cloudflare announced a new feature called ‘AI Labyrinth’ that aims to combat unauthorized AI data scraping by serving fake AI-generated content to bots. The tool will attempt to thwart AI companies that crawl websites without permission to collect training data […]

    https://rbfirehose.com/2025/03/22/ars-technica-cloudflare-turns-ai-against-itself-with-endless-maze-of-irrelevant-facts/

  25. This paper from Reeves & Ashenden provides some insights on how attackers' awareness of deception technology can change and affect their decisions. 🍯

    Notably, simply announcing the use of deception technology or the attacker discovering it could lead them to seek easier targets or take more time. Both are useful for the defender.

    #DFIR #Honeypots #Detection

    scholarspace.manoa.hawaii.edu/

  26. Thanks to everyone who's been abusing my SSH host: "sshgw.stromberg.org". I've used you feedback and put another target up for your enjoyment: "steambox.stromberg.org"

    #LLM based #honeypots aren't terribly novel, but the real fun begins when you realize how much information #SSH clients leak. More to come!

    Source: github.com/tstromberg/confuSSH

  27. Ars Technica: How one YouTuber is trying to poison the AI bots stealing her content. “It’s not hard to find YouTubers complaining about a flood of these faceless channels stealing their embedded transcript files and running them through AI summarizers to generate their own instant knock-offs. But one YouTuber is trying to fight back, seeding her transcripts with junk data that is invisible to […]

    https://rbfirehose.com/2025/02/02/ars-technica-how-one-youtuber-is-trying-to-poison-the-ai-bots-stealing-her-content/

Share on Mastodon

Enter the server where you have an account.