Showing 33 of 105 projects
A Python-based FTP honeypot that captures credentials, malware files, and distributes honeytokens.
A lightweight SSH honeypot that logs connection attempts, including IP, username, password, and client version.
A simple Docker honeypot server that emulates parts of the Docker HTTP API to detect and log reconnaissance and container creation attempts.
A low-interaction honeypot that detects exploitation attempts targeting the CVE-2017-10271 WebLogic remote code execution vulnerability.
A Bro (Zeek) file analyzer plugin that integrates YARA rule scanning for malware detection in network traffic.
A Go-based SSH honeypot that logs and notifies you of unauthorized SSH login attempts on your server.
A curated collection of open-source and commercial rulesets for Suricata and Snort network intrusion detection systems.
Demo code for analyzing AWS CloudTrail and S3 logs using Apache Spark to detect security anomalies and enable SQL queries.
A DICOM honeypot server that logs and analyzes medical imaging protocol traffic for security monitoring.
An Elasticsearch honeypot written in Node.js to capture exploitation attempts targeting CVE-2014-3120.
A low/zero interaction SSH authentication logging honeypot that logs attempts as structured JSON.
A Docker-based script to deploy Dionaea and Kippo honeypots, moving SSH to port 65534 and logging attacks.
A network security honeypot designed to detect and analyze malicious activity as featured in Applied Network Security Monitoring.
A Terraform provider for managing Signal Sciences web application firewall and security monitoring resources.
A low-interaction VNC honeypot that logs authentication attempts against a static challenge.
A low-interaction honeypot that mimics a PostgreSQL server to detect and log unauthorized connection attempts.
A low-interaction honeypot that simulates Oracle MICROS servers to detect exploitation attempts of the CVE-2018-2636 directory traversal vulnerability.
A Suricata plugin that outputs Eve JSON events to Apache Kafka for real-time network security monitoring.
An SSH honeypot that logs credentials from brute-force attacks and provides statistics via an HTTP API.
A collection of open-source threat detection rules for Snort, Sigma, and Yara security tools.
A medium-interaction PostgreSQL honeypot that logs attacker queries and connections for security monitoring.
A Go-based SSH honeypot that logs attacker commands and IP addresses in a fake shell environment.
A GUI interface for Suricata IPS on Qubes OS, providing desktop notifications for suspicious network packets.
A lightweight honeypot for analyzing network attacks with configurable services and LEEF-compliant logging.
A Suricata output plugin that writes Eve JSON events to Redis without blocking the main thread.
A Docker-deployed honeypot that detects port scanning attempts by exposing fake services.
A Node.js FTP honeypot that captures malicious file uploads from bots and scanners.
Automatically updates a pinned GitHub gist with Shodan.io exposure statistics for your public IP.
A Perl web application that provides simple statistics and analytics for the Glastopf honeypot.
Enterprise-grade intrusion detection system integrating Suricata IDS directly into servers for deep network visibility and threat detection.
A Zabbix plugin that monitors Suricata IDS/IPS performance metrics and alerts in real-time.
A LibreNMS JSON SNMP extend and Nagios-style check for monitoring Suricata intrusion detection system statistics.
A Perl tool that ingests EVE JSON logs from Suricata and Sagan into PostgreSQL for structured querying and analysis.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.