Showing 36 of 125 projects
A framework for building high-interaction SSH honeypots with customizable command emulation.
A low-interaction MySQL honeypot written in C that logs unauthorized access attempts.
A simple SSH honeypot written in Go to log and monitor unauthorized SSH login attempts.
Synchronizes threat intelligence indicators from MISP to Suricata datasets and sends alert sightings back to MISP.
A repository of sample Suricata eve.json log files generated from various network pcap datasets for security analysis and learning.
A script that transforms a Raspberry Pi into an XRDP honeypot to capture and monitor unauthorized login attempts.
A lightweight SSH honeypot that logs connection attempts, including IP, username, password, and client version.
A Bro (Zeek) file analyzer plugin that integrates YARA rule scanning for malware detection in network traffic.
A modular Perl framework for passive network security assessment by analyzing traffic with multiple analysis engines.
A Go-based SSH honeypot that logs and notifies you of unauthorized SSH login attempts on your server.
A curated collection of open-source and commercial rulesets for Suricata and Snort network intrusion detection systems.
A modified OpenSSH daemon that forwards attacker commands to Cowrie for logging and interaction interpretation.
A hybrid AI honeypot for detecting and interacting with mass web application exploitation attempts.
A lightweight IMAP and SMTP honeypot written in Go for detecting and logging email protocol attacks.
A network security honeypot designed to detect and analyze malicious activity as featured in Applied Network Security Monitoring.
A script to detect and remove Thinkst Canarytokens from files using signature-based detection.
A low-interaction Python honeypot that mimics vulnerable services to detect and log intrusion attempts.
A high-interaction honeypot system that emulates Redis protocol to detect and analyze unauthorized access attempts.
A modern web-based management system for Suricata IDS/IPS, featuring advanced analytics and visualization capabilities.
A low-interaction honeypot that mimics a PostgreSQL server to detect and log unauthorized connection attempts.
A low-interaction SSH honeypot written in C for detecting and logging unauthorized access attempts.
A minimal honeypot that detects unauthorized connection attempts and triggers customizable alerts.
A no-frills low-interaction SSH honeypot written in Go that logs authentication attempts.
A Suricata plugin that outputs Eve JSON events to Apache Kafka for real-time network security monitoring.
An SSH honeypot that logs credentials from brute-force attacks and provides statistics via an HTTP API.
A collection of open-source threat detection rules for Snort, Sigma, and Yara security tools.
A Go-based SSH honeypot that logs attacker commands and IP addresses in a fake shell environment.
A medium-interaction PostgreSQL honeypot that logs attacker queries and connections for security monitoring.
A Go client library for interacting with Suricata's Unix socket to execute commands and retrieve data.
A command-line tool that formats and syntax highlights Suricata intrusion detection rules for improved readability.
Syntax highlighting for Suricata rules in Visual Studio Code.
A tool to dynamically maintain Suricata's network interface configuration based on link status and assign detection threads via weighted allocation.
A collection of honeypot service emulators written in Go for improved security and performance.
Community-maintained style guide for Suricata rules and configuration files.
Terraform module to deploy Suricata IDS with Google Cloud packet mirroring for network traffic inspection.
A lightweight honeypot written in Go that emulates SSH and Telnet services to log attacker activity.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.