awesome-honeypots/README.md

485 lines
21 KiB
Markdown
Raw Normal View History

# Awesome Honeypots
[![Awesome Honeypots](https://cdn.rawgit.com/sindresorhus/awesome/d7305f38d29fed78fa85652e3a63e154dd8e8829/media/badge.svg)](https://github.com/sindresorhus/awesome)
2015-06-18 12:58:09 +00:00
A curated list of awesome honeypots, tools, components and much more. The list is divided into categories such as web, services, and others, focusing on open source projects.
There is no pre-established order of items in each category, the order is for contribution. If you want to contribute, please read the [guide](CONTRIBUTING.md).
Discover more awesome lists at [sindresorhus/awesome](https://github.com/sindresorhus/awesome).
2015-06-18 13:15:51 +00:00
2015-07-03 18:13:47 +00:00
### Sections
- [Honeypots](#honeypots)
- [Honeyd Tools](#honeyd)
- [Network and Artifact Analysis](#analysis)
- [Data Tools](#visualizers)
- [Guides](#guides)
2015-06-19 12:19:10 +00:00
## Related Lists
- [awesome-pcaptools](https://github.com/caesar0301/awesome-pcaptools), useful in network traffic analysis
- [awesome-malware-analysis](https://github.com/rshipp/awesome-malware-analysis), with some overlap here for artifact analysis
2015-06-18 12:58:09 +00:00
2015-06-19 11:19:39 +00:00
## <a name="honeypots"></a> Honeypots
2015-06-18 12:58:09 +00:00
- Database Honeypots
2015-06-19 20:10:29 +00:00
- [Elastic honey](https://github.com/jordan-wright/elastichoney) - A Simple Elasticsearch Honeypot
- [mysql](https://github.com/schmalle/MysqlPot) - A mysql honeypot, still very very early stage
- [A framework for nosql databases ( only redis for now)](https://github.com/torque59/nosqlpot) - The NoSQL Honeypot Framework
- [ESPot](https://github.com/mycert/ESPot) - ElasticSearch Honeypot
2015-06-18 12:58:09 +00:00
- Web honeypots
2015-06-19 20:10:29 +00:00
- [Glastopf](https://github.com/glastopf/glastopf) - Web Application Honeypot
- [phpmyadmin_honeypot](https://github.com/gfoss/phpmyadmin_honeypot) - - A simple and effective phpmyadmin honeypot
- [servlet](https://github.com/schmalle/Servletpot) - Webapplication Honeypot
- [Nodepot](https://github.com/schmalle/Nodepot) - A nodejs web application honeypot
- [basic-auth-pot](https://github.com/bjeborn/basic-auth-pot) bap - http Basic Authentication honeyPot
2015-08-19 11:14:25 +00:00
- [Shadow Daemon](https://shadowd.zecure.org) - A modular Web Application Firewall / High-Interaction Honeypot for PHP, Perl & Python apps
2015-06-19 20:10:29 +00:00
- [Servletpot](http://github.com/schmalle/servletpot) - Webapplication Honeypot
- [Google Hack Honeypot](http://ghh.sourceforge.net) - designed to provide reconaissance against attackers that use search engines as a hacking tool against your resources.
2015-06-19 20:10:29 +00:00
- [smart-honeypot](https://github.com/freak3dot/smart-honeypot) - PHP Script demonstrating a smart honey pot
- [wp-smart-honeypot](https://github.com/freak3dot/wp-smart-honeypot) - Wordpress plugin to reduce comment spam with a smarter honeypot
2015-08-21 19:26:04 +00:00
- [wordpot](https://github.com/gbrindisi/wordpot) - A Wordpress Honeypot
2015-06-19 12:45:18 +00:00
- [Bukkit Honeypot](https://github.com/Argomirr/Honeypot) Honeypot - A honeypot plugin for Bukkit
2015-08-21 19:26:04 +00:00
- [Laravel Application Honeypot](https://github.com/msurguy/Honeypot) - Honeypot - Simple spam prevention package for Laravel applications
- [stack-honeypot](https://github.com/CHH/stack-honeypot) - Inserts a trap for spam bots into responses
- [EoHoneypotBundle](https://github.com/eymengunay/EoHoneypotBundle) - Honeypot type for Symfony2 forms
2015-06-22 13:19:11 +00:00
- [shockpot](https://github.com/threatstream/shockpot) - WebApp Honeypot for detecting Shell Shock exploit attempts
2015-06-18 12:58:09 +00:00
- Service Honeypots
2015-06-18 13:13:48 +00:00
- [Kippo](https://github.com/desaster/kippo) - Medium interaction SSH honeypot
2015-08-21 19:26:04 +00:00
- [honeyntp](https://github.com/fygrave/honeyntp) - NTP logger/honeypot
- [honeypot-camera](https://github.com/alexbredo/honeypot-camera) - observation camera honeypot
2015-06-21 20:29:44 +00:00
- [troje](https://github.com/dutchcoders/troje/) - a honeypot built around lxc containers. It will run each connection with the service within a seperate lxc container.
2015-06-22 13:19:11 +00:00
- [slipm-honeypot](https://github.com/rshipp/slipm-honeypot) - A simple low-interaction port monitoring honeypot
2015-06-18 12:58:09 +00:00
- Anti-honeypot stuff
2015-06-21 20:29:44 +00:00
- [kippo_detect](https://github.com/andrew-morris/kippo_detect) - This is not a honeypot, but it detects kippo. (This guy has lots of more interesting stuff)
2015-06-18 13:13:48 +00:00
- ICS/SCADA honeypots
2015-06-19 20:10:29 +00:00
- [Conpot](https://github.com/glastopf/conpot) - ICS/SCADA honeypot
- [scada-honeynet](http://www.digitalbond.com/tools/scada-honeynet/) - mimics many of the services from a popular PLC and better helps SCADA researchers understand potential risks of exposed control system devices
- [SCADA honeynet](http://scadahoneynet.sourceforge.net) - Building Honeypots for Industrial Networks
2015-06-19 11:19:39 +00:00
2015-06-18 13:34:52 +00:00
- Deployment
- [Dionaea and EC2 in 20 Minutes](http://andrewmichaelsmith.com/2012/03/dionaea-honeypot-on-ec2-in-20-minutes/) - a tutorial on setting up Dionaea on an EC2 instance
2015-06-22 13:19:11 +00:00
- [honeypotpi](https://github.com/free5ty1e/honeypotpi) - Script for turning a Raspberry Pi into a Honey Pot Pi
2015-06-19 11:19:39 +00:00
- Data Analysis
- [Kippo-Graph](http://bruteforce.gr/kippo-graph) - a full featured script to visualize statistics from a Kippo SSH honeypot
2015-06-19 20:10:29 +00:00
- [Kippo stats](https://github.com/mfontani/kippo-stats) - Mojolicious app to display statistics for your kippo SSH honeypot
2015-06-19 11:19:39 +00:00
2015-06-18 13:34:52 +00:00
- Other/random
- [NOVA](https://github.com/DataSoft/Nova) uses honeypots as detectors, looks like a complete system
2015-08-21 19:26:04 +00:00
- [Open Canary](https://pypi.python.org/pypi/opencanary) - A low interaction honeypot intended to be run on internal networks.
2015-06-19 11:19:39 +00:00
- Open Relay Spam Honeypot
2015-06-19 20:10:29 +00:00
- [SpamHAT](https://github.com/miguelraulb/spamhat) - Spam Honeypot Tool
2015-06-19 11:19:39 +00:00
- Botnet C2 monitor
2015-06-19 20:10:29 +00:00
- [Hale](http://github.com/pjlantz/Hale) - Botnet command &amp; control monitor
2015-06-19 11:19:39 +00:00
- IPv6 attack detection tool
2015-06-19 20:10:29 +00:00
- [ipv6-attack-detector](https://github.com/mzweilin/ipv6-attack-detector/) - Google Summer of Code 2012 project, supported by The Honeynet Project organization
2015-06-19 11:19:39 +00:00
- Research Paper
2015-08-23 01:45:08 +00:00
- [vEYE](http://link.springer.com/article/10.1007%2Fs10115-008-0137-3) - behavioral footprinting for self-propagating worm detection and profiling
2015-06-19 11:19:39 +00:00
- Honeynet statistics
2015-08-23 01:45:08 +00:00
- [HoneyStats](http://sourceforge.net/projects/honeystats/) - A statistical view of the recorded activity on a Honeynet
2015-06-19 11:19:39 +00:00
- dynamic code instrumentation toolkit
2015-08-23 19:58:48 +00:00
- [Frida](http://www.frida.re) - Inject JavaScript to explore native apps on Windows, Mac, Linux, iOS and Android
2015-06-19 11:19:39 +00:00
- Front-end for dionaea
2015-08-23 19:58:48 +00:00
- [DionaeaFR](https://github.com/rubenespadas/DionaeaFR) - Front Web to Dionaea low-interaction honeypot
2015-06-19 11:19:39 +00:00
- Tool to convert website to server honeypots
2015-08-23 19:58:48 +00:00
- [HIHAT](http://hihat.sourceforge.net/) - ransform arbitrary PHP applications into web-based high-interaction Honeypots
2015-06-19 11:19:39 +00:00
- Malware collector
2015-08-23 19:58:48 +00:00
- [Kippo-Malware](http://bruteforce.gr/kippo-malware) - Python script that will download all malicious files stored as URLs in a Kippo SSH honeypot database
2015-06-19 11:19:39 +00:00
- Sebek in QEMU
2015-08-23 19:58:48 +00:00
- [Qebek](https://projects.honeynet.org/sebek/wiki/Qebek) - QEMU based Sebek. As Sebek, it is data capture tool for high interaction honeypot
2015-06-19 11:19:39 +00:00
- Malware Simulator
2015-06-19 20:10:29 +00:00
- [imalse](https://github.com/hbhzwj/imalse) - Integrated MALware Simulator and Emulator
2015-06-19 11:19:39 +00:00
- Distributed sensor deployment
2015-08-23 19:58:48 +00:00
- [Smarthoneypot](http://smarthoneypot.com) - custom honeypot intelligence system that is simple to deploy and easy to manage
2015-06-19 11:19:39 +00:00
- Network Analysis Tool
2015-08-23 19:58:48 +00:00
- [Tracexploit](https://code.google.com/p/tracexploit/) - replay network packets
2015-06-19 11:19:39 +00:00
- Log anonymizer
2015-08-23 19:58:48 +00:00
- [LogAnon](http://code.google.com/p/loganon/) - log anonymization library that helps having anonymous logs consistent between logs and network captures
2015-06-19 11:19:39 +00:00
- server
2015-08-23 19:58:48 +00:00
- [Honeysink](http://www.honeynet.org/node/773) - open source network sinkhole that provides a mechanism for detection and prevention of malicious traffic on a given network
2015-06-19 11:19:39 +00:00
- Botnet traffic detection
2015-08-23 19:58:48 +00:00
- [dnsMole](https://code.google.com/p/dns-mole/) - analyse dns traffic, and to potentionaly detect botnet C&C server and infected hosts
2015-06-19 11:19:39 +00:00
- Low interaction honeypot (router back door)
2015-06-19 20:10:29 +00:00
- [Honeypot-32764](https://github.com/knalli/honeypot-for-tcp-32764) - Honeypot for router backdoor (TCP 32764)
2015-06-19 11:19:39 +00:00
- honeynet farm traffic redirector
2015-08-23 19:58:48 +00:00
- [Honeymole](https://web.archive.org/web/20120122130150/http://www.honeynet.org.pt/index.php/HoneyMole) - eploy multiple sensors that redirect traffic to a centralized collection of honeypots
2015-06-19 11:19:39 +00:00
- IDS signature generator
2015-08-23 19:58:48 +00:00
- [Nebula](http://nebula.carnivore.it/) - network intrusion signature generator
2015-06-19 11:19:39 +00:00
- Fake wireless access point
- [FakeAP](http://www.blackalchemy.to/project/fakeap/)
2015-06-19 11:19:39 +00:00
- HTTPS Proxy
- [mitmproxy](http://mitmproxy.org/)
2015-06-19 11:19:39 +00:00
- spamtrap
- [Jackpot Mailswerver](http://jackpot.uk.net/)
2015-07-17 11:59:19 +00:00
- [SendMeSpamIDS.py](https://github.com/johestephan/SendMeSpamIDS.py) Simple SMTP fetch all IDS and analyzer
2015-06-19 11:19:39 +00:00
- System instrumentation
- [Sysdig](http://www.sysdig.org)
2015-06-19 11:19:39 +00:00
- Honeypot for USB-spreading malware
- [Ghost-usb](https://code.google.com/p/ghost-usb-honeypot/)
2015-06-19 11:19:39 +00:00
- Data Collection
- [Kippo2MySQL](http://bruteforce.gr/kippo2mysql)
- [Kippo2ElasticSearch](http://bruteforce.gr/kippo2elasticsearch)
2015-06-19 11:19:39 +00:00
- Passive network audit framework parser
2015-06-19 20:10:29 +00:00
- [pnaf](https://github.com/jusafing/pnaf) - Passive Network Audit Framework
2015-06-19 11:19:39 +00:00
- VM Introspection
- [VIX virtual machine introspection toolkit](http://assert.uaf.edu/research/vmi.html)
- [xenaccess](https://code.google.com/p/xenaccess/)
- [vmscope](http://cs.gmu.edu/~xwangc/Publications/RAID07-VMscope.pdf)
- [vmitools](http://libvmi.com/)
2015-06-19 11:19:39 +00:00
- Binary debugger
2015-06-19 20:10:29 +00:00
- [Hexgolems - Schem Debugger Frontend](https://github.com/hexgolems/schem) - A debugger frontend
- [Hexgolems - Pint Debugger Backend](https://github.com/hexgolems/pint) - A debugger backend and LUA wrapper for PIN
2015-06-19 11:19:39 +00:00
- Mobile Analysis Tool
2015-06-19 20:10:29 +00:00
- [APKinspector](https://github.com/honeynet/apkinspector/) - APKinspector is a powerful GUI tool for analysts to analyze the Android applications
- [Androguard](https://code.google.com/p/androguard/)
2015-06-19 11:19:39 +00:00
- Low interaction honeypot
- [Honeypoint](http://microsolved.com/?page_id=69)
- [Honeyperl](http://sourceforge.net/projects/honeyperl/)
2015-06-19 11:19:39 +00:00
- Honeynet data fusion
- [HFlow2](https://projects.honeynet.org/hflow)
2015-06-19 11:19:39 +00:00
- Server
- [Tiny Honeypot](http://www.alpinista.org/thp/ -> http://web.archive.org/web/20090606073121/http://www.alpinista.org/files/thp/)
- [Nephenthes](http://nepenthes.carnivore.it//)
- [LaBrea](http://labrea.sourceforge.net/labrea-info.html)
2015-06-19 20:10:29 +00:00
- [Kippo](https://github.com/desaster/kippo) - SSH honeypot
- [KFSensor](http://www.keyfocus.net/kfsensor/)
- [Honeytrap](http://honeytrap.carnivore.it/)
2015-06-19 11:19:39 +00:00
- [Honeyd](https://github.com/provos/honeyd) Also see [more honeyd tools](#honeyd)
- [Honeeebox](http://honeeebox.net)
- [Glastopf](http://glastopf.org/)
2015-06-19 20:10:29 +00:00
- [DNS Honeypot](https://github.com/jekil/UDPot) - Simple UDP honeypot scripts
- [Dionaea](http://dionaea.carnivore.it/)
- [Conpot](http://conpot.org/)
- [Bifrozt](http://sourceforge.net/projects/bifrozt/)
2015-06-22 13:19:11 +00:00
- [Beeswarm](http://www.beeswarm-ids.org/) - Honeypot deployment made easy
- [Bait and Switch](http://baitnswitch.sourceforge.net)
- [Artillery](https://github.com/trustedsec/artillery/)
- [Amun](http://amunhoney.sourceforge.net)
2015-06-19 11:19:39 +00:00
- VM cloaking script
- [Antivmdetect](https://github.com/nsmfoo/antivmdetection)
2015-06-19 11:19:39 +00:00
- IDS signature generation
- [Honeycomb](http://www.cl.cam.ac.uk/~cpk25/honeycomb/)
2015-06-19 11:19:39 +00:00
- Multiple
- [Honeeepi](https://redmine.honeynet.org/projects/honeeepi/wiki)
2015-06-19 11:19:39 +00:00
- Web interface to packet analyzer
- [OpenWitness](https://github.com/oguzy/openwitness)
2015-06-19 11:19:39 +00:00
- lookup service for AS-numbers and prefixes
- [CC2ASN](http://www.cc2asn.com/)
2015-06-19 11:19:39 +00:00
- Data Collection / Analysis Tool
- [Carniwwwhore](http://carnivore.it/2010/11/27/carniwwwhore)
2015-06-19 11:19:39 +00:00
- Web interface (for Thug)
- [Rumal](https://github.com/pdelsante/rumal)
2015-06-19 11:19:39 +00:00
- Snort binary carving
- [Pehunter](http://src.carnivore.it/pehunter/)
2015-06-19 11:19:39 +00:00
- Data Collection / Data Sharing
- [HPfriends](http://hpfriends.honeycloud.net/#/home) - data-sharing platform
- [HPFeeds](https://github.com/rep/hpfeeds/) - lightweight authenticated publish-subscribe protocol
2015-06-19 11:19:39 +00:00
- PE-executables analyses
- [Xandora](http://www.xandora.net/xangui/)
2015-06-19 11:19:39 +00:00
- Distributed spam tracking
- [Project Honeypot](https://www.projecthoneypot.org)
2015-06-19 11:19:39 +00:00
- Python bindings for libemu
- [Pylibemu](https://github.com/buffer/pylibemu)
2015-06-19 11:19:39 +00:00
- Controlled-relay spam honeypot
- [Shiva](https://github.com/shiva-spampot/shiva)
2015-07-03 18:13:47 +00:00
- [Shiva The Spam Honeypot Tips And Tricks For Getting It Up And Running](https://www.pentestpartners.com/blog/shiva-the-spam-honeypot-tips-and-tricks-for-getting-it-up-and-running/)
2015-06-19 11:19:39 +00:00
- Visualization Tool
- [Webviz](not working)
- [Glastopf Analytics](https://github.com/vavkamil/Glastopf-Analytics)
- [Afterglow Cloud](http://afterglow.secviz.org/)
- [Afterglow](http://afterglow.sourceforge.net/)
2015-06-19 11:19:39 +00:00
- central management tool
- [PHARM](http://www.nepenthespharm.com/)
2015-06-19 11:19:39 +00:00
- Network connection analyzer
- [Impost](http://impost.sourceforge.net/)
2015-06-19 11:19:39 +00:00
- Virtual Machine Cloaking
- [VMCloak](https://github.com/jbremer/vmcloak)
2015-06-19 11:19:39 +00:00
- Honeypot deployment
- [Modern Honeynet Network](http://threatstream.github.io/mhn/)
- [SurfIDS](http://ids.surfnet.nl/)
2015-06-19 11:19:39 +00:00
- Honeynet analysis tool
- [Honeynet Security Console](http://www.activeworx.org/programs/hsc/index.htm)
2015-06-19 11:19:39 +00:00
- Automated malware analysis system
- [Cuckoo](http://www.cuckoosandbox.org/)
- [Anubis](https://anubis.iseclab.org/)
2015-06-19 11:19:39 +00:00
- Low interaction
- [mwcollectd](http//git.mwcollect.org/mwcollectd)
2015-06-19 11:19:39 +00:00
- Low interaction honeypot on USB stick
- [Honeystick](http://www.ukhoneynet.org/research/honeystick-howto/)
2015-06-19 11:19:39 +00:00
- Honeypot extensions to Wireshark
- [Whireshark Extensions](https://www.honeynet.org/project/WiresharkExtensions)
2015-06-19 11:19:39 +00:00
- Data Analysis Tool
- [HpfeedsHoneyGraph](https://github.com/yuchincheng/HpfeedsHoneyGraph)
- [Acapulco](https://github.com/hgascon/Acapulco4HNP)
2015-06-19 11:19:39 +00:00
- Telephony honeypot
- [Zapping Rachel](https://seanmckaybeck.com/2014/08/17/zapping-rachel/)
2015-06-19 11:19:39 +00:00
- Client
2015-06-19 11:19:39 +00:00
- [Pwnypot](https://github.com/shjalayeri/pwnypot)
2015-06-18 14:00:01 +00:00
- [MonkeySpider](http://monkeyspider.sourceforge.net)
- [Capture-HPC-NG](https://github.com/CERT-Polska/HSN-Capture-HPC-NG)
- [Wepawet](http://wepawet.cs.ucsb.edu/about.php)
- [URLQuery](https://urlquery.net/)
- [Trigona](https://www.honeynet.org/project/Trigona)
- [Thug](https://buffer.github.io/thug/)
- [Shelia](http://www.cs.vu.nl/~herbertb/misc/shelia/)
- [PhoneyC](https://github.com/honeynet/phoneyc)
- [Libemu](http://libemu.carnivore.it/)
- [Jsunpack-n](https://code.google.com/p/jsunpack-n/)
- [HoneyC](https://projects.honeynet.org/honeyc)
- [HoneyBOT](http://www.atomicsoftwaresolutions.com/honeybot.php)
- [CWSandbox / GFI Sandbox](http://www.gfi.com/malware-analysis-tool)
- [Capture-HPC-Linux](https://redmine.honeynet.org/projects/linux-capture-hpc/wiki)
- [Capture-HPC](https://projects.honeynet.org/capture-hpc)
- [Andrubis](https://anubis.iseclab.org/)
2015-06-19 11:19:39 +00:00
- Commercial high interaction honeypot
- [Countertack Scout](http://www.countertack.com/countertack-scout)
2015-06-19 11:19:39 +00:00
- Visual analysis for network traffic
- [ovizart-ng](https://github.com/honeynet/ovizart-ng)
- [ovizart](https://github.com/honeynet/ovizart)
2015-06-19 11:19:39 +00:00
- Binary Management and Analysis Framework
- [Viper](http://viper.li/)
2015-06-19 11:19:39 +00:00
- Honeypot
- [Single-honeypot](http://sourceforge.net/projects/single-honeypot/)
- [Honeyd For Windows](http://www.securityprofiling.com/honeyd/honeyd.shtml)
- [SWiSH](http://shat.net/swish/)
- [IMHoneypot](https://github.com/glastopf/imhoneypot)
- [Deception Toolkit](http://www.all.net/dtk/dtk.html)
- [Cybercop Sting](http://www.nai.com/international/uk/asp_set/products/tns/ccsting_intro.asp)
2015-06-19 11:19:39 +00:00
- PDF document inspector
2015-06-21 15:31:06 +00:00
- [peepdf](https://github.com/jesparza/peepdf)
2015-06-19 11:19:39 +00:00
- Distribution system
- [Thug Distributed Task Queuing](https://thug-distributed.readthedocs.org/en/latest/index.html)
2015-06-19 11:19:39 +00:00
- HoneyClient Management
- [HoneyWeb](https://code.google.com/p/gsoc-honeyweb/)
2015-06-19 11:19:39 +00:00
- Network Analysis
- [HoneyProxy](http://honeyproxy.org/)
2015-06-19 11:19:39 +00:00
- Hybrid low/high interaction honeypot
- [HoneyBrid](http://honeybrid.sourceforge.net)
2015-06-19 11:19:39 +00:00
- Sebek on Xen
- [xebek](https://code.google.com/p/xebek/)
2015-06-19 11:19:39 +00:00
- SSH Honeypot
- [Kojoney](http://kojoney.sourceforge.net/)
2015-07-02 06:44:51 +00:00
- [Cowrie](https://github.com/micheloosterhof/cowrie)
2015-06-19 11:19:39 +00:00
- Glastopf data analysis
- [Glastopf Analytics](https://github.com/vavkamil/Glastopf-Analytics)
2015-06-19 11:19:39 +00:00
- Distributed sensor project
- [DShield Web Honeypot Project](https://sites.google.com/site/webhoneypotsite/)
- [Distributed Web Honeypot Project](http://projects.webappsec.org/w/page/29606603/Distributed%20Web%20Honeypots)
2015-06-19 11:19:39 +00:00
- a pcap analyzer
- [Honeysnap](https://projects.honeynet.org/honeysnap/)
2015-06-19 11:19:39 +00:00
- Client Web crawler
- [HoneySpider Network](https://github.com/CERT-Polska/hsn2-bundle)
2015-06-19 11:19:39 +00:00
- network traffic redirector
- [Honeywall](https://projects.honeynet.org/honeywall/)
2015-06-19 11:19:39 +00:00
- Honeypot Distribution with mixed content
- [HoneyDrive](http://bruteforce.gr/honeydrive)
2015-06-19 11:19:39 +00:00
- Honeypot sensor
- [Dragon Research Group Distro](https://www.dragonresearchgroup.org/drg-distro.html)
2015-06-19 11:19:39 +00:00
- File carving
- [TestDisk & PhotoRec](http://www.cgsecurity.org/)
2015-06-19 11:19:39 +00:00
- File and Network Threat Intelligence
- [VirusTotal](http://virustotal.com)
2015-06-19 11:19:39 +00:00
- data capture
- [Sebek](https://projects.honeynet.org/sebek/)
2015-06-19 11:19:39 +00:00
- SSH proxy
- [HonSSH](https://github.com/tnich/honssh)
2015-06-19 11:19:39 +00:00
- Anti-Cheat
- [Minecraft honeypot](http://www.curse.com/bukkit-plugins/minecraft/honeypot)
2015-06-19 11:19:39 +00:00
- behavioral analysis tool for win32
- [Capture BAT](https://www.honeynet.org/node/315)
2015-06-19 11:19:39 +00:00
- Live CD
- [DAVIX](http://davix.secviz.org)
2015-06-19 11:19:39 +00:00
- Spamtrap
- [Spampot.py](http://woozle.org/%7Eneale/src/python/spampot.py)
- [Spamhole](http://www.spamhole.net/)
- [spamd](http://www.openbsd.org/cgi-bin/man.cgi?query=spamd&apropos=0&sektion=0&manpath=OpenBSD+Current&arch=i386&format=html)
- [SMTPot.py](http://llama.whoi.edu/smtpot.py)
2015-07-22 08:32:34 +00:00
- [Mail::SMTP::Honeypot](http://search.cpan.org/~miker/Mail-SMTP-Honeypot-0.11/Honeypot.pm) - perl module that appears to provide the functionality of a standard SMTP server
2015-06-19 11:19:39 +00:00
- Commercial honeynet
- [Specter](http://www.specter.com/default50.htm)
- [Smoke Detector](http://palisadesys.com/products/smokedetector/)
- [Sandtrap](http://www.sandstorm.net/products/sandtrap/)
- [PatriotBox](http://www.alkasis.com/?fuseaction=products.info&id=20)
- [PacketDecoy](http://palisadesys.com/products/packetdecoy/)
- [NetFacade](http://www22.verizon.com/fns/solutions/netsec/netsec_netfacade.html)
- [Netbait](http://www.netbaitinc.com)
2015-06-19 11:19:39 +00:00
- Server (Bluetooth)
- [Bluepot](http://code.google.com/p/bluepot/)
2015-06-19 11:19:39 +00:00
- Dynamic analysis of Android apps
- [Droidbox](https://code.google.com/p/droidbox/)
2015-06-19 11:19:39 +00:00
- Dockerized Low Interaction packaging
- [Manuka](https://github.com/andrewmichaelsmith/manuka)
2015-07-03 18:29:24 +00:00
- [Dockerized Thug](https://registry.hub.docker.com/u/honeynet/thug/)
2015-07-03 18:31:42 +00:00
- [Dockerpot](https://github.com/mrschyte/dockerpot) A docker based honeypot.
- [Docker honeynet](https://github.com/sreinhardt/Docker-Honeynet) Several Honeynet tools set up for Docker containers
2015-06-19 11:19:39 +00:00
- Network analysis
- [Quechua](https://bitbucket.org/zaccone/quechua)
2015-06-19 11:19:39 +00:00
- Sebek data visualization
- [Sebek Dataviz](http://www.honeynet.org/gsoc/project4)
2015-06-19 11:19:39 +00:00
- Threat Intel feed aggregator / network grapher
- [Malcom](http://malcom.io)
2015-06-19 11:19:39 +00:00
- SIP Server
- [Artemnesia VoIP](http://artemisa.sourceforge.net)
2015-06-19 11:19:39 +00:00
- Botnet C2 monitoring
- [botsnoopd](http://botsnoopd.mwcollect.org)
2015-06-19 11:19:39 +00:00
- low interaction
- [mysqlpot](https://github.com/schmalle/mysqlpot)
2015-06-19 11:19:39 +00:00
- Malware collection
- [Honeybow](http://honeybow.mwcollect.org/)
2015-06-19 11:19:39 +00:00
## <a name="honeyd"></a> Honeyd Tools
- Honeyd plugin
- [Honeycomb](http://www.honeyd.org/tools.php)
- Honeyd viewer
- [Honeyview](http://honeyview.sourceforge.net/)
- Honeyd to MySQL connector
- [Honeyd2MySQL](http://bruteforce.gr/honeyd2mysql)
- Bootable honeyd
- [HOACD](http://www.honeynet.org.br/tools/)
- Honeyd ported to Windows
- [Winhoneyd](http://www2.netvigilance.com/winhoneyd)
- A script to visualize statistics from honeyd
- [Honeyd-Viz](http://bruteforce.gr/honeyd-viz)
- Honeyd UI
- [Honeyd configuration GUI](http://www.citi.umich.edu/u/provos/honeyd/ch01-results/1/)
- Honeyd stats
- [Honeydsum.pl](http://www.honeynet.org.br/)
## <a name="analysis"></a> Network and Artifact Analysis
- Sandbox
- [PHPSandbox](http://www.fieryprophet.com/phpsandbox)
2015-06-18 14:00:01 +00:00
- [RFISandbox](http://monkey.org/~jose/software/rfi-sandbox/)
- [dorothy2](https://github.com/m4rco-/dorothy2)
- [COMODO automated sandbox](https://help.comodo.com/topic-72-1-451-4768-.html)
2015-06-19 11:19:39 +00:00
- Sandbox
- [Argos](http://www.few.vu.nl/argos/)
- Sandbox-as-a-Service
2015-06-20 12:19:00 +00:00
- [malwr.com](http://malwr.com) - free malware analysis service and community
- [detux.org](http://detux.org) - Multiplatform Linux Sandbox
2015-06-19 11:19:39 +00:00
2015-06-19 12:45:18 +00:00
## <a name="visualizers"></a> Data Tools
- Front Ends
- [Tango](https://github.com/aplura/Tango) Tango - Honeypot Intelligence with Splunk
2015-06-19 20:10:29 +00:00
- [Django-kippo](https://github.com/jedie/django-kippo) - Django App for kippo SSH Honeypot
2015-06-19 11:19:39 +00:00
- Visualization
- [HoneyMap](https://github.com/fw42/honeymap)
2015-06-19 12:19:10 +00:00
- [HoneyMalt](https://github.com/SneakersInc/HoneyMalt)
2015-07-03 18:13:47 +00:00
## <a name="guides"></a>Guides
- [T-Pot: A Multi-Honeypot Platform](https://dtag-dev-sec.github.io/mediator/feature/2015/03/17/concept.html)
2015-08-05 16:29:14 +00:00
- [Honeypot (Dionaea and kippo) setup script](https://github.com/andrewmichaelsmith/honeypot-setup-script/)