Showing 33 of 141 projects
A Go-based honeypot agent that emulates multiple network services to capture attacker activity and credentials.
A forensic tool that parses Java Cache IDX files to extract malware download history and binary data for incident response.
Synchronizes threat intelligence indicators from MISP to Suricata datasets and sends alert sightings back to MISP.
A PowerShell module for interacting with the urlscan.io API to automate threat hunting and intelligence gathering.
A Dockerized subset of the Modern Honey Network running honeypots (Cowrie and Dionaea) with a centralized broker for event collection and visualization.
A Python-based FTP honeypot that captures credentials, malware files, and distributes honeytokens.
A configurable SMTP honeypot written in Go that captures and analyzes spam emails for security research.
A curated collection of tools, resources, and data for Industrial Control System (ICS) and SCADA security research and testing.
A curated collection of open-source and commercial rulesets for Suricata and Snort network intrusion detection systems.
A Python honeypot framework that simulates vulnerable IoT devices to capture attack sources, droppers, and payloads.
A hybrid AI honeypot for detecting and interacting with mass web application exploitation attempts.
A high-interaction honeypot system that emulates Redis protocol to detect and analyze unauthorized access attempts.
A Python library for interfacing with the cuckoo-modified malware sandbox via its API.
A honeypot that emulates a Belkin N300 wireless router to observe malicious traffic targeting home networks.
A Python-based OpenIOC editor for creating and managing threat intelligence indicators across multiple security systems.
A honeypot that logs attacks on instant messaging protocols to analyze malicious activity patterns.
A Docker container running the Cowrie SSH honeypot with DShield reporting to contribute to internet threat intelligence.
Maltego transform pack for analyzing and visualizing honeypot data, starting with Kippo honeypot systems.
Scripts to create malware analysis datasets in the same format as the FFRI Dataset, extracting features from executable files.
Go client library for interacting with the MalShare malware repository API.
A medium-interaction PostgreSQL honeypot that logs attacker queries and connections for security monitoring.
Suricata rulesets that detect and block phishing attacks using malicious URLs and domains from community threat feeds.
A Splunk app that clusters security events from hpfeeds channels and visualizes them with D3.js parallel coordinates graphs.
A medium interaction SSH honeypot designed to log brute force attacks and attacker shell interactions.
Creates fake file systems for honeypots using LLMs to generate realistic lures and configurations for threat engagement.
Parses Cowrie honeypot logs and imports them into a Neo4j graph database for security analysis.
A Node.js FTP honeypot that captures malicious file uploads from bots and scanners.
A PHP-based web dashboard for visualizing attack statistics from the Wordpot WordPress honeypot.
A Twisted-based honeypot for detecting and logging network attacks.
A PHP-based web interface for visualizing attack statistics from the Shockpot SSH honeypot.
A free URL security scanner that performs 8 comprehensive checks and AI analysis to detect red flags before connecting to apps.
A CLI tool that generates Suricata rules from IOCs in JSON, CSV, or flags using customizable templates.
A Python tool that organizes malware and benign files into a structured database with tagging and querying capabilities.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.