A Python-based Elasticsearch honeypot that detects and analyzes attacks exploiting the CVE-2015-1427 Groovy vulnerability.
Delilah is a honeypot system designed to mimic vulnerable Elasticsearch instances and attract attackers exploiting the CVE-2015-1427 Groovy vulnerability. It detects attack commands, reconnaissance attempts, and download commands (like wget and curl), while attempting to download malicious files for later analysis. The system sends real-time email notifications to analysts upon detecting attacks.
Delilah is built to provide security analysts with actionable intelligence on active threats by safely emulating vulnerable systems and capturing attacker behavior in detail.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.