#honeypots — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #honeypots, aggregated by home.social.
-
I read CISA’s new report on using cyber decoys to strengthen detection and response, and it’s very philosophically aligned with the work I’ve done on Intrusion Detection Honeypots (IDHs).
I’ve been beating this drum for years: properly deployed internal honeypots are one of the best bargains in detection.
-
I read CISA’s new report on using cyber decoys to strengthen detection and response, and it’s very philosophically aligned with the work I’ve done on Intrusion Detection Honeypots (IDHs).
I’ve been beating this drum for years: properly deployed internal honeypots are one of the best bargains in detection.
-
I read CISA’s new report on using cyber decoys to strengthen detection and response, and it’s very philosophically aligned with the work I’ve done on Intrusion Detection Honeypots (IDHs).
I’ve been beating this drum for years: properly deployed internal honeypots are one of the best bargains in detection.
-
I read CISA’s new report on using cyber decoys to strengthen detection and response, and it’s very philosophically aligned with the work I’ve done on Intrusion Detection Honeypots (IDHs).
I’ve been beating this drum for years: properly deployed internal honeypots are one of the best bargains in detection.
-
I read CISA’s new report on using cyber decoys to strengthen detection and response, and it’s very philosophically aligned with the work I’ve done on Intrusion Detection Honeypots (IDHs).
I’ve been beating this drum for years: properly deployed internal honeypots are one of the best bargains in detection.
-
What Happens in the First 24 Hours After a New Asset Goes Live
The First 24 Hours: A Technical Timeline
T+5 to T+60 minutes: The scanners find it.
T+1 to T+6 hours: Enumeration begins.
T+6 to T+12 hours: Active probing.
T+12 to T+24 hours: Compromise.
They deployed 320 #honeypots across cloud providers (RDP, SSH, SMB, Postgres) to see what would happen. 80% were compromised within 24 hours.
https://www.bleepingcomputer.com/news/security/what-happens-in-the-first-24-hours-after-a-new-asset-goes-live/
#Security #ITSec #IT -
What Happens in the First 24 Hours After a New Asset Goes Live
The First 24 Hours: A Technical Timeline
T+5 to T+60 minutes: The scanners find it.
T+1 to T+6 hours: Enumeration begins.
T+6 to T+12 hours: Active probing.
T+12 to T+24 hours: Compromise.
They deployed 320 #honeypots across cloud providers (RDP, SSH, SMB, Postgres) to see what would happen. 80% were compromised within 24 hours.
https://www.bleepingcomputer.com/news/security/what-happens-in-the-first-24-hours-after-a-new-asset-goes-live/
#Security #ITSec #IT -
What Happens in the First 24 Hours After a New Asset Goes Live
The First 24 Hours: A Technical Timeline
T+5 to T+60 minutes: The scanners find it.
T+1 to T+6 hours: Enumeration begins.
T+6 to T+12 hours: Active probing.
T+12 to T+24 hours: Compromise.
They deployed 320 #honeypots across cloud providers (RDP, SSH, SMB, Postgres) to see what would happen. 80% were compromised within 24 hours.
https://www.bleepingcomputer.com/news/security/what-happens-in-the-first-24-hours-after-a-new-asset-goes-live/
#Security #ITSec #IT -
What Happens in the First 24 Hours After a New Asset Goes Live
The First 24 Hours: A Technical Timeline
T+5 to T+60 minutes: The scanners find it.
T+1 to T+6 hours: Enumeration begins.
T+6 to T+12 hours: Active probing.
T+12 to T+24 hours: Compromise.
They deployed 320 #honeypots across cloud providers (RDP, SSH, SMB, Postgres) to see what would happen. 80% were compromised within 24 hours.
https://www.bleepingcomputer.com/news/security/what-happens-in-the-first-24-hours-after-a-new-asset-goes-live/
#Security #ITSec #IT -
What Happens in the First 24 Hours After a New Asset Goes Live
The First 24 Hours: A Technical Timeline
T+5 to T+60 minutes: The scanners find it.
T+1 to T+6 hours: Enumeration begins.
T+6 to T+12 hours: Active probing.
T+12 to T+24 hours: Compromise.
They deployed 320 #honeypots across cloud providers (RDP, SSH, SMB, Postgres) to see what would happen. 80% were compromised within 24 hours.
https://www.bleepingcomputer.com/news/security/what-happens-in-the-first-24-hours-after-a-new-asset-goes-live/
#Security #ITSec #IT -
T-minus 10 days!!!
In #CyberSecurity terms, I'm about to deliberately walk into an entirely new threat landscape with no local threat intel, a foreign language I'm still actively patching. The attack surface has changed. The adversaries are now cobblestones, bureaucratic Portuguese, and the very real possibility that I will confidently order the wrong thing at a restaurant and just go with it. Threat level: manageable. Vibes: elevated!!
The honeypots aren't moving. They never do - that's the whole point. They stay scattered where they are, quietly doing their thing, collecting everything. The only thing changing is where the intel gets delivered. Starting April 29th, that's Porto.
I'm a little concerned they're going to start sending it in #Portuguese. 🤷♀️
Half my home lab is already there ahead of me. ZimaBoard, #opnsense the Pis - all running, all waiting, probably judging me for not arriving sooner. Home Assistant is next on the list once I land, which means I get to find out whether my automations survived the relocation or whether I'm about to have a very intimate conversation with Portuguese error messages. Could go either way.
And yes, I'm leaving behind the Chicago "L". The L. An elevated rail system so charmingly held together by decades of deferred maintenance and sheer Chicagoan stubbornness that honestly, it's kind of a security metaphor. I'm going to miss the ambiance of a train that sounds like it's actively negotiating with physics.
The Metro stop is literally across the street from my apartment. It's clean. It's modern. It's quiet. The trains run on time. I don't know how I'll cope. 👀
@sashatheflamingo is excited but has concerns about the cobblestones hurting her feet. I told her she can ride on my shoulder. Problem solved. The flamingo adapts. 🦩
And if you're in the security community and haven't looked at #BSidesPorto yet - June 26th and 27th - I don't know what to tell you except that you're going to miss an awesome event if you don't get your tickets - NOW! And come find me. I'll be the one who showed up 60 days before the conference and is still figuring out which bus/metro train goes where.
The operation doesn't stop. It just changes coordinates. The #honeypots already know. They figured it out before I told them. (That's kind of their whole thing.)
-
T-minus 10 days!!!
In #CyberSecurity terms, I'm about to deliberately walk into an entirely new threat landscape with no local threat intel, a foreign language I'm still actively patching. The attack surface has changed. The adversaries are now cobblestones, bureaucratic Portuguese, and the very real possibility that I will confidently order the wrong thing at a restaurant and just go with it. Threat level: manageable. Vibes: elevated!!
The honeypots aren't moving. They never do - that's the whole point. They stay scattered where they are, quietly doing their thing, collecting everything. The only thing changing is where the intel gets delivered. Starting April 29th, that's Porto.
I'm a little concerned they're going to start sending it in #Portuguese. 🤷♀️
Half my home lab is already there ahead of me. ZimaBoard, #opnsense the Pis - all running, all waiting, probably judging me for not arriving sooner. Home Assistant is next on the list once I land, which means I get to find out whether my automations survived the relocation or whether I'm about to have a very intimate conversation with Portuguese error messages. Could go either way.
And yes, I'm leaving behind the Chicago "L". The L. An elevated rail system so charmingly held together by decades of deferred maintenance and sheer Chicagoan stubbornness that honestly, it's kind of a security metaphor. I'm going to miss the ambiance of a train that sounds like it's actively negotiating with physics.
The Metro stop is literally across the street from my apartment. It's clean. It's modern. It's quiet. The trains run on time. I don't know how I'll cope. 👀
@sashatheflamingo is excited but has concerns about the cobblestones hurting her feet. I told her she can ride on my shoulder. Problem solved. The flamingo adapts. 🦩
And if you're in the security community and haven't looked at #BSidesPorto yet - June 26th and 27th - I don't know what to tell you except that you're going to miss an awesome event if you don't get your tickets - NOW! And come find me. I'll be the one who showed up 60 days before the conference and is still figuring out which bus/metro train goes where.
The operation doesn't stop. It just changes coordinates. The #honeypots already know. They figured it out before I told them. (That's kind of their whole thing.)
-
T-minus 10 days!!!
In #CyberSecurity terms, I'm about to deliberately walk into an entirely new threat landscape with no local threat intel, a foreign language I'm still actively patching. The attack surface has changed. The adversaries are now cobblestones, bureaucratic Portuguese, and the very real possibility that I will confidently order the wrong thing at a restaurant and just go with it. Threat level: manageable. Vibes: elevated!!
The honeypots aren't moving. They never do - that's the whole point. They stay scattered where they are, quietly doing their thing, collecting everything. The only thing changing is where the intel gets delivered. Starting April 29th, that's Porto.
I'm a little concerned they're going to start sending it in #Portuguese. 🤷♀️
Half my home lab is already there ahead of me. ZimaBoard, #opnsense the Pis - all running, all waiting, probably judging me for not arriving sooner. Home Assistant is next on the list once I land, which means I get to find out whether my automations survived the relocation or whether I'm about to have a very intimate conversation with Portuguese error messages. Could go either way.
And yes, I'm leaving behind the Chicago "L". The L. An elevated rail system so charmingly held together by decades of deferred maintenance and sheer Chicagoan stubbornness that honestly, it's kind of a security metaphor. I'm going to miss the ambiance of a train that sounds like it's actively negotiating with physics.
The Metro stop is literally across the street from my apartment. It's clean. It's modern. It's quiet. The trains run on time. I don't know how I'll cope. 👀
@sashatheflamingo is excited but has concerns about the cobblestones hurting her feet. I told her she can ride on my shoulder. Problem solved. The flamingo adapts. 🦩
And if you're in the security community and haven't looked at #BSidesPorto yet - June 26th and 27th - I don't know what to tell you except that you're going to miss an awesome event if you don't get your tickets - NOW! And come find me. I'll be the one who showed up 60 days before the conference and is still figuring out which bus/metro train goes where.
The operation doesn't stop. It just changes coordinates. The #honeypots already know. They figured it out before I told them. (That's kind of their whole thing.)
-
T-minus 10 days!!!
In #CyberSecurity terms, I'm about to deliberately walk into an entirely new threat landscape with no local threat intel, a foreign language I'm still actively patching. The attack surface has changed. The adversaries are now cobblestones, bureaucratic Portuguese, and the very real possibility that I will confidently order the wrong thing at a restaurant and just go with it. Threat level: manageable. Vibes: elevated!!
The honeypots aren't moving. They never do - that's the whole point. They stay scattered where they are, quietly doing their thing, collecting everything. The only thing changing is where the intel gets delivered. Starting April 29th, that's Porto.
I'm a little concerned they're going to start sending it in #Portuguese. 🤷♀️
Half my home lab is already there ahead of me. ZimaBoard, #opnsense the Pis - all running, all waiting, probably judging me for not arriving sooner. Home Assistant is next on the list once I land, which means I get to find out whether my automations survived the relocation or whether I'm about to have a very intimate conversation with Portuguese error messages. Could go either way.
And yes, I'm leaving behind the Chicago "L". The L. An elevated rail system so charmingly held together by decades of deferred maintenance and sheer Chicagoan stubbornness that honestly, it's kind of a security metaphor. I'm going to miss the ambiance of a train that sounds like it's actively negotiating with physics.
The Metro stop is literally across the street from my apartment. It's clean. It's modern. It's quiet. The trains run on time. I don't know how I'll cope. 👀
@sashatheflamingo is excited but has concerns about the cobblestones hurting her feet. I told her she can ride on my shoulder. Problem solved. The flamingo adapts. 🦩
And if you're in the security community and haven't looked at #BSidesPorto yet - June 26th and 27th - I don't know what to tell you except that you're going to miss an awesome event if you don't get your tickets - NOW! And come find me. I'll be the one who showed up 60 days before the conference and is still figuring out which bus/metro train goes where.
The operation doesn't stop. It just changes coordinates. The #honeypots already know. They figured it out before I told them. (That's kind of their whole thing.)
-
T-minus 10 days!!!
In #CyberSecurity terms, I'm about to deliberately walk into an entirely new threat landscape with no local threat intel, a foreign language I'm still actively patching. The attack surface has changed. The adversaries are now cobblestones, bureaucratic Portuguese, and the very real possibility that I will confidently order the wrong thing at a restaurant and just go with it. Threat level: manageable. Vibes: elevated!!
The honeypots aren't moving. They never do - that's the whole point. They stay scattered where they are, quietly doing their thing, collecting everything. The only thing changing is where the intel gets delivered. Starting April 29th, that's Porto.
I'm a little concerned they're going to start sending it in #Portuguese. 🤷♀️
Half my home lab is already there ahead of me. ZimaBoard, #opnsense the Pis - all running, all waiting, probably judging me for not arriving sooner. Home Assistant is next on the list once I land, which means I get to find out whether my automations survived the relocation or whether I'm about to have a very intimate conversation with Portuguese error messages. Could go either way.
And yes, I'm leaving behind the Chicago "L". The L. An elevated rail system so charmingly held together by decades of deferred maintenance and sheer Chicagoan stubbornness that honestly, it's kind of a security metaphor. I'm going to miss the ambiance of a train that sounds like it's actively negotiating with physics.
The Metro stop is literally across the street from my apartment. It's clean. It's modern. It's quiet. The trains run on time. I don't know how I'll cope. 👀
@sashatheflamingo is excited but has concerns about the cobblestones hurting her feet. I told her she can ride on my shoulder. Problem solved. The flamingo adapts. 🦩
And if you're in the security community and haven't looked at #BSidesPorto yet - June 26th and 27th - I don't know what to tell you except that you're going to miss an awesome event if you don't get your tickets - NOW! And come find me. I'll be the one who showed up 60 days before the conference and is still figuring out which bus/metro train goes where.
The operation doesn't stop. It just changes coordinates. The #honeypots already know. They figured it out before I told them. (That's kind of their whole thing.)
-
It auto detects #fraud and punishes #reputation. It launches random #honeypots and does tests. Booyah. No free riders. But then everybody rides for free. You're going to understand me, sometime. 💃🏻💃🏻💃🏻
-
----------------
🛠️ Tool
===================Executive summary: NeroSwarm Deception Lab is a lightweight collection of deception utilities aimed at surfacing intrusions early. The suite bundles a Smart HoneyTokens engine for document-based triggers, a Honeypots Code Generator that emits low-interaction honeypot scripts, and an IP Threat Reputation Checker tied to a tactical database.
Technical details:
• Smart HoneyTokens Engine: generates document artifacts that act as early-warning signals when accessed or modified. These artifacts can embed identifiable markers and metadata to attribute access events and trigger alerts.
• Honeypots Code Generator: produces simple, low-interaction honeypot scripts intended for network-level observation. The generated artifacts focus on service emulation and basic protocol responses to capture connection attempts and probe behavior without full application emulation.
• IP Threat Reputation Checker: queries an internal database to map IPs to observed tactics, techniques, and procedural indicators. Outputs are oriented toward threat classification and can enrich telemetry with contextual notes about actor behaviors.Implementation concepts:
• Lightweight sandboxing emphasizes minimal host impact and quick deployment for experimentation rather than production-grade containment.
• Document-based honeytokens rely on detectable file access patterns and metadata changes rather than deep behavioral simulation.
• Low-interaction honeypots prioritize broad visibility and low resource consumption, trading fidelity for scale.Use cases:
• Training SOC analysts on deception-based detection workflows.
• Rapid proof-of-concept validation for detection logic using reproducible artifacts.
• Enrichment of incident triage by correlating IP reputation metadata with observed interactions.Limitations and considerations:
• Low-interaction honeypots inherently limit attacker engagement and may miss nuanced post-exploitation activity.
• Document honeytokens can produce false positives if legitimate processes access the artifacts without appropriate tagging.
• Reputation outputs depend on the coverage and freshness of the underlying database; gaps in telemetry can reduce usefulness.Final note: NeroSwarm positions itself as an experimentation and training sandbox for cyber deception techniques rather than a turnkey production deception platform. The suite provides practical primitives—honeytokens, basic honeypots, and IP context—that can inform detection rules and analyst workflows.
🔹 deception #honeytokens #honeypots #ip_reputation #bookmark
🔗 Source: https://lab.neroswarm.com/
-
Not all threat intelligence tells the same story.
🍯Honeypots show internet noise. Production telemetry shows what attackers actually do when real businesses are on the line.
Understanding the difference is the key to actionable security.
Learn more in our latest article 👉 https://crowdsec.net/blog/honeypots-vs-production-telemetry-what-cisos-should-trust
#threatintelligence #honeypots #vulnerabilities #cybersecurity
-
Not all threat intelligence tells the same story.
🍯Honeypots show internet noise. Production telemetry shows what attackers actually do when real businesses are on the line.
Understanding the difference is the key to actionable security.
Learn more in our latest article 👉 https://crowdsec.net/blog/honeypots-vs-production-telemetry-what-cisos-should-trust
#threatintelligence #honeypots #vulnerabilities #cybersecurity
-
Not all threat intelligence tells the same story.
🍯Honeypots show internet noise. Production telemetry shows what attackers actually do when real businesses are on the line.
Understanding the difference is the key to actionable security.
Learn more in our latest article 👉 https://crowdsec.net/blog/honeypots-vs-production-telemetry-what-cisos-should-trust
#threatintelligence #honeypots #vulnerabilities #cybersecurity
-
Not all threat intelligence tells the same story.
🍯Honeypots show internet noise. Production telemetry shows what attackers actually do when real businesses are on the line.
Understanding the difference is the key to actionable security.
Learn more in our latest article 👉 https://crowdsec.net/blog/honeypots-vs-production-telemetry-what-cisos-should-trust
#threatintelligence #honeypots #vulnerabilities #cybersecurity
-
Some #honeypots are made, and some form themselves. The employee rosters of #ICE and #DHS have gathered the identifying information of many fascists for us to use when it is time to punish them.
-
Some #honeypots are made, and some form themselves. The employee rosters of #ICE and #DHS have gathered the identifying information of many fascists for us to use when it is time to punish them.
-
Some #honeypots are made, and some form themselves. The employee rosters of #ICE and #DHS have gathered the identifying information of many fascists for us to use when it is time to punish them.
-
Some #honeypots are made, and some form themselves. The employee rosters of #ICE and #DHS have gathered the identifying information of many fascists for us to use when it is time to punish them.
-
Some #honeypots are made, and some form themselves. The employee rosters of #ICE and #DHS have gathered the identifying information of many fascists for us to use when it is time to punish them.
-
NCSC Tests Honeypots and Cyber Deception Tools https://thecyberexpress.com/ncsc-tests-honeypots-and-cyber-deception-tools/ #TheCyberExpressNews #cybersecuritytools #TheCyberExpress #deceptiontools #FirewallDaily #Cyberdefenses #cybersecurity #CyberNews #honeypots #NCSC
-
NCSC Tests Honeypots and Cyber Deception Tools https://thecyberexpress.com/ncsc-tests-honeypots-and-cyber-deception-tools/ #TheCyberExpressNews #cybersecuritytools #TheCyberExpress #deceptiontools #FirewallDaily #Cyberdefenses #cybersecurity #CyberNews #honeypots #NCSC
-
NCSC Tests Honeypots and Cyber Deception Tools https://thecyberexpress.com/ncsc-tests-honeypots-and-cyber-deception-tools/ #TheCyberExpressNews #cybersecuritytools #TheCyberExpress #deceptiontools #FirewallDaily #Cyberdefenses #cybersecurity #CyberNews #honeypots #NCSC
-
NCSC Tests Honeypots and Cyber Deception Tools https://thecyberexpress.com/ncsc-tests-honeypots-and-cyber-deception-tools/ #TheCyberExpressNews #cybersecuritytools #TheCyberExpress #deceptiontools #FirewallDaily #Cyberdefenses #cybersecurity #CyberNews #honeypots #NCSC
-
Dear Friends of Social Media,
Decided not to use computers today and certainly no social media. Fail? Yes! [lobster hangs head in shame] :mastodondance:
So whilst I am here some honey for the security nerds (probably bit out of date or known)
https://www.honeynet.org/projects/Not sure if it is suitable for cyber apiary control as bees are scarce in our garden at the moment. Flowers all shivering. 🥶
I hope everyone is as well as can bee. Yep a pun-full dad joke. :hearthands: 🦞 :ablobwave:
-
Dear Friends of Social Media,
Decided not to use computers today and certainly no social media. Fail? Yes! [lobster hangs head in shame] :mastodondance:
So whilst I am here some honey for the security nerds (probably bit out of date or known)
https://www.honeynet.org/projects/Not sure if it is suitable for cyber apiary control as bees are scarce in our garden at the moment. Flowers all shivering. 🥶
I hope everyone is as well as can bee. Yep a pun-full dad joke. :hearthands: 🦞 :ablobwave:
-
Dear Friends of Social Media,
Decided not to use computers today and certainly no social media. Fail? Yes! [lobster hangs head in shame] :mastodondance:
So whilst I am here some honey for the security nerds (probably bit out of date or known)
https://www.honeynet.org/projects/Not sure if it is suitable for cyber apiary control as bees are scarce in our garden at the moment. Flowers all shivering. 🥶
I hope everyone is as well as can bee. Yep a pun-full dad joke. :hearthands: 🦞 :ablobwave:
-
TwoNet just hacked a decoy water plant, disabling SCADA controls in under 26 hours. Could this be the new normal for critical infrastructure threats?
-
TwoNet just hacked a decoy water plant, disabling SCADA controls in under 26 hours. Could this be the new normal for critical infrastructure threats?
-
TwoNet just hacked a decoy water plant, disabling SCADA controls in under 26 hours. Could this be the new normal for critical infrastructure threats?
-
TwoNet just hacked a decoy water plant, disabling SCADA controls in under 26 hours. Could this be the new normal for critical infrastructure threats?
-
Honeypots, when set up correctly, can become sensors that reveal attacker behavior. Add that with Suricata's rules and tuning, and they can provide clear, named alerts that cut away the noise.
Our Luke Davis set up a T-Pot with Suricata for 3 days, and it flagged probes for OpenSSH “regreSSHion” (CVE-2024-6387) and Treck TCP/IP (CVE-2020-11910), as well as highlighting cloud IP scanning.
Honeypots can be great as an early detection method and a hands-on training tool for students, SOC analysts, and Blue Teams to practise detection and response in safe environments.
📌Read the full blog here: https://www.pentestpartners.com/security-blog/spot-trouble-early-with-honeypots-and-suricata/
#CyberSecurity #Honeypots #Suricata #ThreatDetection #BlueTeam
-
Honeypots, when set up correctly, can become sensors that reveal attacker behavior. Add that with Suricata's rules and tuning, and they can provide clear, named alerts that cut away the noise.
Our Luke Davis set up a T-Pot with Suricata for 3 days, and it flagged probes for OpenSSH “regreSSHion” (CVE-2024-6387) and Treck TCP/IP (CVE-2020-11910), as well as highlighting cloud IP scanning.
Honeypots can be great as an early detection method and a hands-on training tool for students, SOC analysts, and Blue Teams to practise detection and response in safe environments.
📌Read the full blog here: https://www.pentestpartners.com/security-blog/spot-trouble-early-with-honeypots-and-suricata/
#CyberSecurity #Honeypots #Suricata #ThreatDetection #BlueTeam
-
Honeypots, when set up correctly, can become sensors that reveal attacker behavior. Add that with Suricata's rules and tuning, and they can provide clear, named alerts that cut away the noise.
Our Luke Davis set up a T-Pot with Suricata for 3 days, and it flagged probes for OpenSSH “regreSSHion” (CVE-2024-6387) and Treck TCP/IP (CVE-2020-11910), as well as highlighting cloud IP scanning.
Honeypots can be great as an early detection method and a hands-on training tool for students, SOC analysts, and Blue Teams to practise detection and response in safe environments.
📌Read the full blog here: https://www.pentestpartners.com/security-blog/spot-trouble-early-with-honeypots-and-suricata/
#CyberSecurity #Honeypots #Suricata #ThreatDetection #BlueTeam
-
Honeypots, when set up correctly, can become sensors that reveal attacker behavior. Add that with Suricata's rules and tuning, and they can provide clear, named alerts that cut away the noise.
Our Luke Davis set up a T-Pot with Suricata for 3 days, and it flagged probes for OpenSSH “regreSSHion” (CVE-2024-6387) and Treck TCP/IP (CVE-2020-11910), as well as highlighting cloud IP scanning.
Honeypots can be great as an early detection method and a hands-on training tool for students, SOC analysts, and Blue Teams to practise detection and response in safe environments.
📌Read the full blog here: https://www.pentestpartners.com/security-blog/spot-trouble-early-with-honeypots-and-suricata/
#CyberSecurity #Honeypots #Suricata #ThreatDetection #BlueTeam
-
Honeypots, when set up correctly, can become sensors that reveal attacker behavior. Add that with Suricata's rules and tuning, and they can provide clear, named alerts that cut away the noise.
Our Luke Davis set up a T-Pot with Suricata for 3 days, and it flagged probes for OpenSSH “regreSSHion” (CVE-2024-6387) and Treck TCP/IP (CVE-2020-11910), as well as highlighting cloud IP scanning.
Honeypots can be great as an early detection method and a hands-on training tool for students, SOC analysts, and Blue Teams to practise detection and response in safe environments.
📌Read the full blog here: https://www.pentestpartners.com/security-blog/spot-trouble-early-with-honeypots-and-suricata/
#CyberSecurity #Honeypots #Suricata #ThreatDetection #BlueTeam
-
🦩🎤 @sashatheflamingo here: @bsidesedmonton Track One is now officially a flamingo zone this afternoon!
At 1:30 Kat is unleashing her honeypot talk (spoiler: traps, tricks, and a few flamingo-sized surprises) — and I have insisted on emceeing that exact track because, let’s be honest, Kat needs supervision.
So if you hear squawking from the stage, don’t panic — it’s just Sasha making sure Kat sticks to time and doesn’t start talking about dancing flamingos in RAID10 again. 😉
Come flap with us at #BSidesEdmonton — Track One, 1:30pm.
Quirky chaos guaranteed. 🦩🪂 -
🦩🎤 @sashatheflamingo here: @bsidesedmonton Track One is now officially a flamingo zone this afternoon!
At 1:30 Kat is unleashing her honeypot talk (spoiler: traps, tricks, and a few flamingo-sized surprises) — and I have insisted on emceeing that exact track because, let’s be honest, Kat needs supervision.
So if you hear squawking from the stage, don’t panic — it’s just Sasha making sure Kat sticks to time and doesn’t start talking about dancing flamingos in RAID10 again. 😉
Come flap with us at #BSidesEdmonton — Track One, 1:30pm.
Quirky chaos guaranteed. 🦩🪂 -
🦩🎤 @sashatheflamingo here: @bsidesedmonton Track One is now officially a flamingo zone this afternoon!
At 1:30 Kat is unleashing her honeypot talk (spoiler: traps, tricks, and a few flamingo-sized surprises) — and I have insisted on emceeing that exact track because, let’s be honest, Kat needs supervision.
So if you hear squawking from the stage, don’t panic — it’s just Sasha making sure Kat sticks to time and doesn’t start talking about dancing flamingos in RAID10 again. 😉
Come flap with us at #BSidesEdmonton — Track One, 1:30pm.
Quirky chaos guaranteed. 🦩🪂 -
🦩🎤 @sashatheflamingo here: @bsidesedmonton Track One is now officially a flamingo zone this afternoon!
At 1:30 Kat is unleashing her honeypot talk (spoiler: traps, tricks, and a few flamingo-sized surprises) — and I have insisted on emceeing that exact track because, let’s be honest, Kat needs supervision.
So if you hear squawking from the stage, don’t panic — it’s just Sasha making sure Kat sticks to time and doesn’t start talking about dancing flamingos in RAID10 again. 😉
Come flap with us at #BSidesEdmonton — Track One, 1:30pm.
Quirky chaos guaranteed. 🦩🪂 -
🦩🎤 @sashatheflamingo here: @bsidesedmonton Track One is now officially a flamingo zone this afternoon!
At 1:30 Kat is unleashing her honeypot talk (spoiler: traps, tricks, and a few flamingo-sized surprises) — and I have insisted on emceeing that exact track because, let’s be honest, Kat needs supervision.
So if you hear squawking from the stage, don’t panic — it’s just Sasha making sure Kat sticks to time and doesn’t start talking about dancing flamingos in RAID10 again. 😉
Come flap with us at #BSidesEdmonton — Track One, 1:30pm.
Quirky chaos guaranteed. 🦩🪂 -
How a fake ICS network can reveal real cyberattacks https://www.helpnetsecurity.com/2025/09/17/icslure-ics-threat-detection/ #criticalinfrastructure #cybersecurity #Don'tmiss #honeypots #ICS/SCADA #Features #Hotstuff #research #strategy #BforeAI #News #tips
-
How a fake ICS network can reveal real cyberattacks https://www.helpnetsecurity.com/2025/09/17/icslure-ics-threat-detection/ #criticalinfrastructure #cybersecurity #Don'tmiss #honeypots #ICS/SCADA #Features #Hotstuff #research #strategy #BforeAI #News #tips
-
How a fake ICS network can reveal real cyberattacks https://www.helpnetsecurity.com/2025/09/17/icslure-ics-threat-detection/ #criticalinfrastructure #cybersecurity #Don'tmiss #honeypots #ICS/SCADA #Features #Hotstuff #research #strategy #BforeAI #News #tips
-
How a fake ICS network can reveal real cyberattacks https://www.helpnetsecurity.com/2025/09/17/icslure-ics-threat-detection/ #criticalinfrastructure #cybersecurity #Don'tmiss #honeypots #ICS/SCADA #Features #Hotstuff #research #strategy #BforeAI #News #tips
-
**Sasha's Honeypot Diary: Entry #47**
*Sigh.* Another morning, another 125 idiots knocking on my digital door.
Do these bots ever get tired? I've been watching the same IP addresses try "admin/password123" on my fake WordPress sites for OVER A YEAR. Like, guys... take a hint? I'm starting to feel bad for them. It's like watching someone repeatedly walk into a glass door.
This week they discovered the username "support" and honestly? They're acting like they invented fire. 100+ attempts yesterday, 125 this morning. Such enthusiasm! Such determination! Such complete lack of learning ability!
My favorite part is watching them cycle through usernames from a 20-year-old government breach like it's fresh intelligence. Fellas, that data is older than some of the smartphones you're probably using to run these attacks.
But hey, keep it coming! My honeypots are hungry, my threat intelligence dashboard is beautiful, and my BSides presentation just got 125 more data points.
🦩
The persistence is almost admirable. Almost.
#ThreatIntel #Honeypots #CyberSecurity #BotnetFails #PersistentButNotSmart
P.S. - To the botnet hitting me from Singapore: your user-agent strings are hilariously obvious. Just saying.
-
**Sasha's Honeypot Diary: Entry #47**
*Sigh.* Another morning, another 125 idiots knocking on my digital door.
Do these bots ever get tired? I've been watching the same IP addresses try "admin/password123" on my fake WordPress sites for OVER A YEAR. Like, guys... take a hint? I'm starting to feel bad for them. It's like watching someone repeatedly walk into a glass door.
This week they discovered the username "support" and honestly? They're acting like they invented fire. 100+ attempts yesterday, 125 this morning. Such enthusiasm! Such determination! Such complete lack of learning ability!
My favorite part is watching them cycle through usernames from a 20-year-old government breach like it's fresh intelligence. Fellas, that data is older than some of the smartphones you're probably using to run these attacks.
But hey, keep it coming! My honeypots are hungry, my threat intelligence dashboard is beautiful, and my BSides presentation just got 125 more data points.
🦩
The persistence is almost admirable. Almost.
#ThreatIntel #Honeypots #CyberSecurity #BotnetFails #PersistentButNotSmart
P.S. - To the botnet hitting me from Singapore: your user-agent strings are hilariously obvious. Just saying.
-
**Sasha's Honeypot Diary: Entry #47**
*Sigh.* Another morning, another 125 idiots knocking on my digital door.
Do these bots ever get tired? I've been watching the same IP addresses try "admin/password123" on my fake WordPress sites for OVER A YEAR. Like, guys... take a hint? I'm starting to feel bad for them. It's like watching someone repeatedly walk into a glass door.
This week they discovered the username "support" and honestly? They're acting like they invented fire. 100+ attempts yesterday, 125 this morning. Such enthusiasm! Such determination! Such complete lack of learning ability!
My favorite part is watching them cycle through usernames from a 20-year-old government breach like it's fresh intelligence. Fellas, that data is older than some of the smartphones you're probably using to run these attacks.
But hey, keep it coming! My honeypots are hungry, my threat intelligence dashboard is beautiful, and my BSides presentation just got 125 more data points.
🦩
The persistence is almost admirable. Almost.
#ThreatIntel #Honeypots #CyberSecurity #BotnetFails #PersistentButNotSmart
P.S. - To the botnet hitting me from Singapore: your user-agent strings are hilariously obvious. Just saying.
-
**Sasha's Honeypot Diary: Entry #47**
*Sigh.* Another morning, another 125 idiots knocking on my digital door.
Do these bots ever get tired? I've been watching the same IP addresses try "admin/password123" on my fake WordPress sites for OVER A YEAR. Like, guys... take a hint? I'm starting to feel bad for them. It's like watching someone repeatedly walk into a glass door.
This week they discovered the username "support" and honestly? They're acting like they invented fire. 100+ attempts yesterday, 125 this morning. Such enthusiasm! Such determination! Such complete lack of learning ability!
My favorite part is watching them cycle through usernames from a 20-year-old government breach like it's fresh intelligence. Fellas, that data is older than some of the smartphones you're probably using to run these attacks.
But hey, keep it coming! My honeypots are hungry, my threat intelligence dashboard is beautiful, and my BSides presentation just got 125 more data points.
🦩
The persistence is almost admirable. Almost.
#ThreatIntel #Honeypots #CyberSecurity #BotnetFails #PersistentButNotSmart
P.S. - To the botnet hitting me from Singapore: your user-agent strings are hilariously obvious. Just saying.
-
Any recommended #honeypots? I have a project with multiple honeypots running in Docker that I update every year for @defcon - does anyone have a honeypot they like or recommend? I have old ones, some are updated, some I'll need to find replacements for, so it's a WIP, but this will be up to date and ready for the con as always! #cancelled https://github.com/philcryer/prickly-pete
-
Any recommended #honeypots? I have a project with multiple honeypots running in Docker that I update every year for @defcon - does anyone have a honeypot they like or recommend? I have old ones, some are updated, some I'll need to find replacements for, so it's a WIP, but this will be up to date and ready for the con as always! #cancelled https://github.com/philcryer/prickly-pete
-
Any recommended #honeypots? I have a project with multiple honeypots running in Docker that I update every year for @defcon - does anyone have a honeypot they like or recommend? I have old ones, some are updated, some I'll need to find replacements for, so it's a WIP, but this will be up to date and ready for the con as always! #cancelled https://github.com/philcryer/prickly-pete
-
Any recommended #honeypots? I have a project with multiple honeypots running in Docker that I update every year for @defcon - does anyone have a honeypot they like or recommend? I have old ones, some are updated, some I'll need to find replacements for, so it's a WIP, but this will be up to date and ready for the con as always! #cancelled https://github.com/philcryer/prickly-pete
-
Any recommended #honeypots? I have a project with multiple honeypots running in Docker that I update every year for @defcon - does anyone have a honeypot they like or recommend? I have old ones, some are updated, some I'll need to find replacements for, so it's a WIP, but this will be up to date and ready for the con as always! #cancelled https://github.com/philcryer/prickly-pete