home.social

#honeypots — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #honeypots, aggregated by home.social.

fetched live
  1. What Happens in the First 24 Hours After a New Asset Goes Live
    The First 24 Hours: A Technical Timeline
    T+5 to T+60 minutes: The scanners find it.
    T+1 to T+6 hours: Enumeration begins.
    T+6 to T+12 hours: Active probing.
    T+12 to T+24 hours: Compromise.
    They deployed 320 #honeypots across cloud providers (RDP, SSH, SMB, Postgres) to see what would happen. 80% were compromised within 24 hours.
    bleepingcomputer.com/news/secu
    #Security #ITSec #IT

  2. T-minus 10 days!!!

    In #CyberSecurity terms, I'm about to deliberately walk into an entirely new threat landscape with no local threat intel, a foreign language I'm still actively patching. The attack surface has changed. The adversaries are now cobblestones, bureaucratic Portuguese, and the very real possibility that I will confidently order the wrong thing at a restaurant and just go with it. Threat level: manageable. Vibes: elevated!!

    The honeypots aren't moving. They never do - that's the whole point. They stay scattered where they are, quietly doing their thing, collecting everything. The only thing changing is where the intel gets delivered. Starting April 29th, that's Porto.

    I'm a little concerned they're going to start sending it in #Portuguese. 🤷‍♀️

    Half my home lab is already there ahead of me. ZimaBoard, #opnsense the Pis - all running, all waiting, probably judging me for not arriving sooner. Home Assistant is next on the list once I land, which means I get to find out whether my automations survived the relocation or whether I'm about to have a very intimate conversation with Portuguese error messages. Could go either way.

    And yes, I'm leaving behind the Chicago "L". The L. An elevated rail system so charmingly held together by decades of deferred maintenance and sheer Chicagoan stubbornness that honestly, it's kind of a security metaphor. I'm going to miss the ambiance of a train that sounds like it's actively negotiating with physics.

    The Metro stop is literally across the street from my apartment. It's clean. It's modern. It's quiet. The trains run on time. I don't know how I'll cope. 👀

    @sashatheflamingo is excited but has concerns about the cobblestones hurting her feet. I told her she can ride on my shoulder. Problem solved. The flamingo adapts. 🦩

    And if you're in the security community and haven't looked at #BSidesPorto yet - June 26th and 27th - I don't know what to tell you except that you're going to miss an awesome event if you don't get your tickets - NOW! And come find me. I'll be the one who showed up 60 days before the conference and is still figuring out which bus/metro train goes where.

    The operation doesn't stop. It just changes coordinates. The #honeypots already know. They figured it out before I told them. (That's kind of their whole thing.)

  3. Not all threat intelligence tells the same story.

    🍯Honeypots show internet noise. Production telemetry shows what attackers actually do when real businesses are on the line.

    Understanding the difference is the key to actionable security.

    Learn more in our latest article 👉 crowdsec.net/blog/honeypots-vs

    #threatintelligence #honeypots #vulnerabilities #cybersecurity

  4. Some #honeypots are made, and some form themselves. The employee rosters of #ICE and #DHS have gathered the identifying information of many fascists for us to use when it is time to punish them.

    #antifa

  5. Honeypots, when set up correctly, can become sensors that reveal attacker behavior. Add that with Suricata's rules and tuning, and they can provide clear, named alerts that cut away the noise.

    Our Luke Davis set up a T-Pot with Suricata for 3 days, and it flagged probes for OpenSSH “regreSSHion” (CVE-2024-6387) and Treck TCP/IP (CVE-2020-11910), as well as highlighting cloud IP scanning.

    Honeypots can be great as an early detection method and a hands-on training tool for students, SOC analysts, and Blue Teams to practise detection and response in safe environments.

    📌Read the full blog here: pentestpartners.com/security-b

    #CyberSecurity #Honeypots #Suricata #ThreatDetection #BlueTeam

  6. 🦩🎤 @sashatheflamingo here: @bsidesedmonton Track One is now officially a flamingo zone this afternoon!

    At 1:30 Kat is unleashing her honeypot talk (spoiler: traps, tricks, and a few flamingo-sized surprises) — and I have insisted on emceeing that exact track because, let’s be honest, Kat needs supervision.

    So if you hear squawking from the stage, don’t panic — it’s just Sasha making sure Kat sticks to time and doesn’t start talking about dancing flamingos in RAID10 again. 😉

    Come flap with us at #BSidesEdmonton — Track One, 1:30pm.
    Quirky chaos guaranteed. 🦩🪂

    #cybersecurity #honeypots

  7. **Sasha's Honeypot Diary: Entry #47**

    *Sigh.* Another morning, another 125 idiots knocking on my digital door.

    Do these bots ever get tired? I've been watching the same IP addresses try "admin/password123" on my fake WordPress sites for OVER A YEAR. Like, guys... take a hint? I'm starting to feel bad for them. It's like watching someone repeatedly walk into a glass door.

    This week they discovered the username "support" and honestly? They're acting like they invented fire. 100+ attempts yesterday, 125 this morning. Such enthusiasm! Such determination! Such complete lack of learning ability!

    My favorite part is watching them cycle through usernames from a 20-year-old government breach like it's fresh intelligence. Fellas, that data is older than some of the smartphones you're probably using to run these attacks.

    But hey, keep it coming! My honeypots are hungry, my threat intelligence dashboard is beautiful, and my BSides presentation just got 125 more data points.

    🦩

    The persistence is almost admirable. Almost.

    #ThreatIntel #Honeypots #CyberSecurity #BotnetFails #PersistentButNotSmart

    P.S. - To the botnet hitting me from Singapore: your user-agent strings are hilariously obvious. Just saying.

  8. Any recommended #honeypots? I have a project with multiple honeypots running in Docker that I update every year for @defcon - does anyone have a honeypot they like or recommend? I have old ones, some are updated, some I'll need to find replacements for, so it's a WIP, but this will be up to date and ready for the con as always! #cancelled github.com/philcryer/prickly-p

  9. Well flap my wings and call me exhausted— @bsidespgh was a TOTAL BLAST! 🦩💥

    Over 1,000 amazing humans showed up, and I shook every feather I had meeting new friends, cheering on brilliant talks, and strutting through the best hallway track east of the Mississippi.

    My human @rnbwkat (you know, the clever one who wrangled the #CFP and gave that worldwide honeypot talk) absolutely crushed it. So many smart, quirky, and inspiring sessions—and not a single boring PowerPoint voice in sight.

    I made friends. I crashed photos. I may have stolen a pierogi.
    No regrets.

    Huge thanks to the organizers, speakers, volunteers, sponsors and all the wonderful folks who made BSidesPGH a sparkling success!! We’ll be dreaming of skyline bridges and cyber-magic until next time. 💖✨

    #BSidesPGH #CyberFlock #CyberSecurity #Honeypots
    #DEI #FlamingoUprising

  10. @bsidespgh 2025 is officially in the record books—and what a ride it was!

    Over 1,000 curious minds, incredible talks, hallway tracks that never quit, and a flamingo who may or may not have photobombed every other selfie!

    I had the honor of running the #cfp this year, and I’m beyond proud of the diverse, insightful, and thought-provoking sessions our speakers delivered. I also had the chance to share stories from around the globe—of honeypots, deception, and the strange things attackers do when they think no one’s watching.

    Sasha and I had an amazing time connecting with old friends and making plenty of new ones. From the badge hunt to after-party shenanigans (and yes, she did sneak a pierogi or two), this community continues to inspire us with its creativity and heart! ❤️

    Thanks to everyone who made this event a massive success. Pittsburgh, you brought the 🔥

    Until next time,
    🦩💻💖

    #BSidesPGH #Honeypots #Cybersecurity @sashatheflamingo

  11. 💻🦩✨ Today’s the day, darlings! ✨🦩💻

    I’ve landed in Leeds and I’m wired (literally) to share all the juicy details of my global honeypot escapades at #BSidesLeeds. With my human sidekick @rnbwkat doing the button-clicking, I’ll be flapping through stories of cyber traps, curious attackers, and the delicious chaos of deception done right. 💅🔥

    Massive feathery hugs to the @bsidesleeds crew—you’ve rolled out the pink carpet like absolute pros. 💜 You make this flamingo feel right at home.

    Let’s make some security magic today!
    — Sasha 🦩🕶️🌍

    #Honeypots #CyberSecurity #hacking

  12. 🎉 TODAY’S THE DAY! 🎉

    @sashatheflamingo has officially landed in Leeds—and guess what? She’s not just here to strut her stuff (though, let’s be real, the strutting is fabulous). With a little help from her human (that’s me! 😄), Sasha is taking the stage at #BSidesLeeds to talk about her global #honeypot mischief—er, network.

    Huge shoutout to the BSidesLeeds team for all the incredible work they’ve put in—this community is fierce, friendly, and fantastically nerdy. 💜

    Let’s do this, Leeds! 🦩✨ #SashaTheFlamingo #cybersecurity #honeypots @bsidesleeds

  13. Anyone who seeks for a well-written analysis of unsolicited #TCP traffic should give Decoding TCP SYN for Stronger Network Security a read. The blog post goes into TCP-procotol specifications. Recommended to every #networkengineer .

    Props go to @jtk for his strong analytical skills and excellent writing style.

    #honeypots #tcpflood #tcpsyn #networkanomaly #netsec #ddos

  14. Sometimes you have to scratch your head and wonder when you see 1000+ attempts at logins for "xtw183874b06" across a dozen of your #honeypots ???

    #CyberSecurity #interesting