🤬
Revision indexing in progress... (symbol navigation in revisions will be accurate after indexed)
  • ■ ■ ■ ■ ■ ■
    README.md
    skipped 7 lines
    8 8   
    9 9  # Contents
    10 10   
    11  -- [Related Lists](#related-lists)
    12  -- [Honeypots](#honeypots)
    13  -- [Honeyd Tools](#honeyd-tools)
    14  -- [Network and Artifact Analysis](#network-and-artifact-analysis)
    15  -- [Data Tools](#data-tools)
    16  -- [Guides](#guides)
     11 +- [Awesome Honeypots ![Awesome Honeypots](https://github.com/sindresorhus/awesome)](#awesome-honeypots-)
     12 +- [Contents](#contents)
     13 + - [Related Lists](#related-lists)
     14 + - [Honeypots](#honeypots)
     15 + - [Honeyd Tools](#honeyd-tools)
     16 + - [Network and Artifact Analysis](#network-and-artifact-analysis)
     17 + - [Data Tools](#data-tools)
     18 + - [Guides](#guides)
    17 19   
    18 20  ## Related Lists
    19 21   
    skipped 3 lines
    23 25  ## Honeypots
    24 26   
    25 27  - Database Honeypots
    26  - - [Delilah](https://github.com/SecurityTW/delilah) - Elasticsearch Honeypot written in Python (originally from Novetta).
    27  - - [ESPot](https://github.com/mycert/ESPot) - Elasticsearch honeypot written in NodeJS, to capture every attempts to exploit CVE-2014-3120.
    28  - - [Elastic honey](https://github.com/jordan-wright/elastichoney) - Simple Elasticsearch Honeypot.
    29  - - [MongoDB-HoneyProxy](https://github.com/Plazmaz/MongoDB-HoneyProxy) - MongoDB honeypot proxy.
    30  - - [NoSQLpot](https://github.com/torque59/nosqlpot) - Honeypot framework built on a NoSQL-style database.
    31  - - [mysql-honeypotd](https://github.com/sjinks/mysql-honeypotd) - Low interaction MySQL honeypot written in C.
    32  - - [MysqlPot](https://github.com/schmalle/MysqlPot) - MySQL honeypot, still very early stage.
    33  - - [pghoney](https://github.com/betheroot/pghoney) - Low-interaction Postgres Honeypot.
    34  - - [sticky_elephant](https://github.com/betheroot/sticky_elephant) - Medium interaction postgresql honeypot.
     28 + 
     29 + - [Delilah](https://github.com/SecurityTW/delilah) - Elasticsearch Honeypot written in Python (originally from Novetta).
     30 + - [ESPot](https://github.com/mycert/ESPot) - Elasticsearch honeypot written in NodeJS, to capture every attempts to exploit CVE-2014-3120.
     31 + - [Elastic honey](https://github.com/jordan-wright/elastichoney) - Simple Elasticsearch Honeypot.
     32 + - [MongoDB-HoneyProxy](https://github.com/Plazmaz/MongoDB-HoneyProxy) - MongoDB honeypot proxy.
     33 + - [NoSQLpot](https://github.com/torque59/nosqlpot) - Honeypot framework built on a NoSQL-style database.
     34 + - [mysql-honeypotd](https://github.com/sjinks/mysql-honeypotd) - Low interaction MySQL honeypot written in C.
     35 + - [MysqlPot](https://github.com/schmalle/MysqlPot) - MySQL honeypot, still very early stage.
     36 + - [pghoney](https://github.com/betheroot/pghoney) - Low-interaction Postgres Honeypot.
     37 + - [sticky_elephant](https://github.com/betheroot/sticky_elephant) - Medium interaction postgresql honeypot.
    35 38   
    36 39  - Web honeypots
    37  - - [EoHoneypotBundle](https://github.com/eymengunay/EoHoneypotBundle) - Honeypot type for Symfony2 forms.
    38  - - [Glastopf](https://github.com/mushorg/glastopf) - Web Application Honeypot.
    39  - - [Google Hack Honeypot](http://ghh.sourceforge.net) - Designed to provide reconnaissance against attackers that use search engines as a hacking tool against your resources.
    40  - - [HellPot](https://github.com/yunginnanet/HellPot) - Honeypot that tries to crash the bots and clients that visit it's location.
    41  - - [Laravel Application Honeypot](https://github.com/msurguy/Honeypot) - Simple spam prevention package for Laravel applications.
    42  - - [Nodepot](https://github.com/schmalle/Nodepot) - NodeJS web application honeypot.
    43  - - [PasitheaHoneypot](https://github.com/Marist-Innovation-Lab/PasitheaHoneypot) - RestAPI honeypot.
    44  - - [Servletpot](https://github.com/schmalle/servletpot) - Web application Honeypot.
    45  - - [Shadow Daemon](https://shadowd.zecure.org/overview/introduction/) - Modular Web Application Firewall / High-Interaction Honeypot for PHP, Perl, and Python apps.
    46  - - [StrutsHoneypot](https://github.com/Cymmetria/StrutsHoneypot) - Struts Apache 2 based honeypot as well as a detection module for Apache 2 servers.
    47  - - [WebTrap](https://github.com/IllusiveNetworks-Labs/WebTrap) - Designed to create deceptive webpages to deceive and redirect attackers away from real websites.
    48  - - [basic-auth-pot (bap)](https://github.com/bjeborn/basic-auth-pot) - HTTP Basic Authentication honeypot.
    49  - - [bwpot](https://github.com/graneed/bwpot) - Breakable Web applications honeyPot.
    50  - - [django-admin-honeypot](https://github.com/dmpayton/django-admin-honeypot) - Fake Django admin login screen to notify admins of attempted unauthorized access.
    51  - - [drupo](https://github.com/d1str0/drupot) - Drupal Honeypot.
    52  - - [honeyhttpd](https://github.com/bocajspear1/honeyhttpd) - Python-based web server honeypot builder.
    53  - - [honeyup](https://github.com/LogoiLab/honeyup) - An uploader honeypot designed to look like poor website security.
    54  - - [owa-honeypot](https://github.com/joda32/owa-honeypot) - A basic flask based Outlook Web Honey pot.
    55  - - [phpmyadmin_honeypot](https://github.com/gfoss/phpmyadmin_honeypot) - Simple and effective phpMyAdmin honeypot.
    56  - - [shockpot](https://github.com/threatstream/shockpot) - WebApp Honeypot for detecting Shell Shock exploit attempts.
    57  - - [smart-honeypot](https://github.com/freak3dot/smart-honeypot) - PHP Script demonstrating a smart honey pot.
    58  - - Snare/Tanner - successors to Glastopf
    59  - - [Snare](https://github.com/mushorg/snare) - Super Next generation Advanced Reactive honeypot.
    60  - - [Tanner](https://github.com/mushorg/tanner) - Evaluating SNARE events.
    61  - - [stack-honeypot](https://github.com/CHH/stack-honeypot) - Inserts a trap for spam bots into responses.
    62  - - [tomcat-manager-honeypot](https://github.com/helospark/tomcat-manager-honeypot) - Honeypot that mimics Tomcat manager endpoints. Logs requests and saves attacker's WAR file for later study
    63  - - WordPress honeypots
    64  - - [HonnyPotter](https://github.com/MartinIngesen/HonnyPotter) - WordPress login honeypot for collection and analysis of failed login attempts.
    65  - - [HoneyPress](https://github.com/kungfuguapo/HoneyPress) - Python based WordPress honeypot in a Docker container.
    66  - - [wp-smart-honeypot](https://github.com/freak3dot/wp-smart-honeypot) - WordPress plugin to reduce comment spam with a smarter honeypot.
    67  - - [wordpot](https://github.com/gbrindisi/wordpot) - WordPress Honeypot.
     40 + 
     41 + - [Express honeypot](https://github.com/christophe77/express-honeypot) - RFI & LFI honeypot using nodeJS and express.
     42 + - [EoHoneypotBundle](https://github.com/eymengunay/EoHoneypotBundle) - Honeypot type for Symfony2 forms.
     43 + - [Glastopf](https://github.com/mushorg/glastopf) - Web Application Honeypot.
     44 + - [Google Hack Honeypot](http://ghh.sourceforge.net) - Designed to provide reconnaissance against attackers that use search engines as a hacking tool against your resources.
     45 + - [HellPot](https://github.com/yunginnanet/HellPot) - Honeypot that tries to crash the bots and clients that visit it's location.
     46 + - [Laravel Application Honeypot](https://github.com/msurguy/Honeypot) - Simple spam prevention package for Laravel applications.
     47 + - [Nodepot](https://github.com/schmalle/Nodepot) - NodeJS web application honeypot.
     48 + - [PasitheaHoneypot](https://github.com/Marist-Innovation-Lab/PasitheaHoneypot) - RestAPI honeypot.
     49 + - [Servletpot](https://github.com/schmalle/servletpot) - Web application Honeypot.
     50 + - [Shadow Daemon](https://shadowd.zecure.org/overview/introduction/) - Modular Web Application Firewall / High-Interaction Honeypot for PHP, Perl, and Python apps.
     51 + - [StrutsHoneypot](https://github.com/Cymmetria/StrutsHoneypot) - Struts Apache 2 based honeypot as well as a detection module for Apache 2 servers.
     52 + - [WebTrap](https://github.com/IllusiveNetworks-Labs/WebTrap) - Designed to create deceptive webpages to deceive and redirect attackers away from real websites.
     53 + - [basic-auth-pot (bap)](https://github.com/bjeborn/basic-auth-pot) - HTTP Basic Authentication honeypot.
     54 + - [bwpot](https://github.com/graneed/bwpot) - Breakable Web applications honeyPot.
     55 + - [django-admin-honeypot](https://github.com/dmpayton/django-admin-honeypot) - Fake Django admin login screen to notify admins of attempted unauthorized access.
     56 + - [drupo](https://github.com/d1str0/drupot) - Drupal Honeypot.
     57 + - [honeyhttpd](https://github.com/bocajspear1/honeyhttpd) - Python-based web server honeypot builder.
     58 + - [honeyup](https://github.com/LogoiLab/honeyup) - An uploader honeypot designed to look like poor website security.
     59 + - [owa-honeypot](https://github.com/joda32/owa-honeypot) - A basic flask based Outlook Web Honey pot.
     60 + - [phpmyadmin_honeypot](https://github.com/gfoss/phpmyadmin_honeypot) - Simple and effective phpMyAdmin honeypot.
     61 + - [shockpot](https://github.com/threatstream/shockpot) - WebApp Honeypot for detecting Shell Shock exploit attempts.
     62 + - [smart-honeypot](https://github.com/freak3dot/smart-honeypot) - PHP Script demonstrating a smart honey pot.
     63 + - Snare/Tanner - successors to Glastopf
     64 + - [Snare](https://github.com/mushorg/snare) - Super Next generation Advanced Reactive honeypot.
     65 + - [Tanner](https://github.com/mushorg/tanner) - Evaluating SNARE events.
     66 + - [stack-honeypot](https://github.com/CHH/stack-honeypot) - Inserts a trap for spam bots into responses.
     67 + - [tomcat-manager-honeypot](https://github.com/helospark/tomcat-manager-honeypot) - Honeypot that mimics Tomcat manager endpoints. Logs requests and saves attacker's WAR file for later study
     68 + - WordPress honeypots
     69 + - [HonnyPotter](https://github.com/MartinIngesen/HonnyPotter) - WordPress login honeypot for collection and analysis of failed login attempts.
     70 + - [HoneyPress](https://github.com/kungfuguapo/HoneyPress) - Python based WordPress honeypot in a Docker container.
     71 + - [wp-smart-honeypot](https://github.com/freak3dot/wp-smart-honeypot) - WordPress plugin to reduce comment spam with a smarter honeypot.
     72 + - [wordpot](https://github.com/gbrindisi/wordpot) - WordPress Honeypot.
    68 73   
    69 74  - Service Honeypots
    70  - - [ADBHoney](https://github.com/huuck/ADBHoney) - Low interaction honeypot that simulates an Android device running Android Debug Bridge (ADB) server process.
    71  - - [AMTHoneypot](https://github.com/packetflare/amthoneypot) - Honeypot for Intel's AMT Firmware Vulnerability CVE-2017-5689.
    72  - - [DolosHoneypot](https://github.com/Marist-Innovation-Lab/DolosHoneypot) - SDN (software defined networking) honeypot.
    73  - - [Ensnare](https://github.com/ahoernecke/ensnare) - Easy to deploy Ruby honeypot.
    74  - - [HoneyPy](https://github.com/foospidy/HoneyPy) - Low interaction honeypot.
    75  - - [Honeygrove](https://github.com/UHH-ISS/honeygrove) - Multi-purpose modular honeypot based on Twisted.
    76  - - [Honeyport](https://github.com/securitygeneration/Honeyport) - Simple honeyport written in Bash and Python.
    77  - - [Honeyprint](https://github.com/glaslos/honeyprint) - Printer honeypot.
    78  - - [Lyrebird](https://hub.docker.com/r/lyrebird/honeypot-base/) - Modern high-interaction honeypot framework.
    79  - - [MICROS honeypot](https://github.com/Cymmetria/micros_honeypot) - Low interaction honeypot to detect CVE-2018-2636 in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (MICROS).
    80  - - [RDPy](https://github.com/citronneur/rdpy) - Microsoft Remote Desktop Protocol (RDP) honeypot implemented in Python.
    81  - - [SMB Honeypot](https://github.com/r0hi7/HoneySMB) - High interaction SMB service honeypot capable of capturing wannacry-like Malware.
    82  - - [Tom's Honeypot](https://github.com/inguardians/toms_honeypot) - Low interaction Python honeypot.
    83  - - [WebLogic honeypot](https://github.com/Cymmetria/weblogic_honeypot) - Low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware.
    84  - - [WhiteFace Honeypot](https://github.com/csirtgadgets/csirtg-honeypot) - Twisted based honeypot for WhiteFace.
    85  - - [dhp](https://github.com/ciscocsirt/dhp) - Simple Docker Honeypot server emulating small snippets of the Docker HTTP API.
    86  - - [honeycomb_plugins](https://github.com/Cymmetria/honeycomb_plugins) - Plugin repository for Honeycomb, the honeypot framework by Cymmetria.
    87  - - [honeyntp](https://github.com/fygrave/honeyntp) - NTP logger/honeypot.
    88  - - [honeypot-camera](https://github.com/alexbredo/honeypot-camera) - Observation camera honeypot.
    89  - - [honeypot-ftp](https://github.com/alexbredo/honeypot-ftp) - FTP Honeypot.
    90  - - [honeytrap](https://github.com/honeytrap/honeytrap) - Advanced Honeypot framework written in Go that can be connected with other honeypot software.
    91  - - [pyrdp](https://github.com/gosecure/pyrdp) - RDP man-in-the-middle and library for Python 3 with the ability to watch connections live or after the fact.
    92  - - [troje](https://github.com/dutchcoders/troje/) - Honeypot that runs each connection with the service within a separate LXC container.
     75 + 
     76 + - [ADBHoney](https://github.com/huuck/ADBHoney) - Low interaction honeypot that simulates an Android device running Android Debug Bridge (ADB) server process.
     77 + - [AMTHoneypot](https://github.com/packetflare/amthoneypot) - Honeypot for Intel's AMT Firmware Vulnerability CVE-2017-5689.
     78 + - [DolosHoneypot](https://github.com/Marist-Innovation-Lab/DolosHoneypot) - SDN (software defined networking) honeypot.
     79 + - [Ensnare](https://github.com/ahoernecke/ensnare) - Easy to deploy Ruby honeypot.
     80 + - [HoneyPy](https://github.com/foospidy/HoneyPy) - Low interaction honeypot.
     81 + - [Honeygrove](https://github.com/UHH-ISS/honeygrove) - Multi-purpose modular honeypot based on Twisted.
     82 + - [Honeyport](https://github.com/securitygeneration/Honeyport) - Simple honeyport written in Bash and Python.
     83 + - [Honeyprint](https://github.com/glaslos/honeyprint) - Printer honeypot.
     84 + - [Lyrebird](https://hub.docker.com/r/lyrebird/honeypot-base/) - Modern high-interaction honeypot framework.
     85 + - [MICROS honeypot](https://github.com/Cymmetria/micros_honeypot) - Low interaction honeypot to detect CVE-2018-2636 in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (MICROS).
     86 + - [RDPy](https://github.com/citronneur/rdpy) - Microsoft Remote Desktop Protocol (RDP) honeypot implemented in Python.
     87 + - [SMB Honeypot](https://github.com/r0hi7/HoneySMB) - High interaction SMB service honeypot capable of capturing wannacry-like Malware.
     88 + - [Tom's Honeypot](https://github.com/inguardians/toms_honeypot) - Low interaction Python honeypot.
     89 + - [WebLogic honeypot](https://github.com/Cymmetria/weblogic_honeypot) - Low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware.
     90 + - [WhiteFace Honeypot](https://github.com/csirtgadgets/csirtg-honeypot) - Twisted based honeypot for WhiteFace.
     91 + - [dhp](https://github.com/ciscocsirt/dhp) - Simple Docker Honeypot server emulating small snippets of the Docker HTTP API.
     92 + - [honeycomb_plugins](https://github.com/Cymmetria/honeycomb_plugins) - Plugin repository for Honeycomb, the honeypot framework by Cymmetria.
     93 + - [honeyntp](https://github.com/fygrave/honeyntp) - NTP logger/honeypot.
     94 + - [honeypot-camera](https://github.com/alexbredo/honeypot-camera) - Observation camera honeypot.
     95 + - [honeypot-ftp](https://github.com/alexbredo/honeypot-ftp) - FTP Honeypot.
     96 + - [honeytrap](https://github.com/honeytrap/honeytrap) - Advanced Honeypot framework written in Go that can be connected with other honeypot software.
     97 + - [pyrdp](https://github.com/gosecure/pyrdp) - RDP man-in-the-middle and library for Python 3 with the ability to watch connections live or after the fact.
     98 + - [troje](https://github.com/dutchcoders/troje/) - Honeypot that runs each connection with the service within a separate LXC container.
    93 99   
    94 100  - Distributed Honeypots
    95  - - [DemonHunter](https://github.com/RevengeComing/DemonHunter) - Low interaction honeypot server.
     101 + 
     102 + - [DemonHunter](https://github.com/RevengeComing/DemonHunter) - Low interaction honeypot server.
    96 103   
    97 104  - Anti-honeypot stuff
    98  - - [kippo_detect](https://github.com/andrew-morris/kippo_detect) - Offensive component that detects the presence of the kippo honeypot.
     105 + 
     106 + - [kippo_detect](https://github.com/andrew-morris/kippo_detect) - Offensive component that detects the presence of the kippo honeypot.
    99 107   
    100 108  - ICS/SCADA honeypots
    101  - - [Conpot](https://github.com/mushorg/conpot) - ICS/SCADA honeypot.
    102  - - [GasPot](https://github.com/sjhilt/GasPot) - Veeder Root Gaurdian AST, common in the oil and gas industry.
    103  - - [SCADA honeynet](http://scadahoneynet.sourceforge.net) - Building Honeypots for Industrial Networks.
    104  - - [gridpot](https://github.com/sk4ld/gridpot) - Open source tools for realistic-behaving electric grid honeynets.
    105  - - [scada-honeynet](http://www.digitalbond.com/blog/2007/07/24/scada-honeynet-article-in-infragard-publication/) - Mimics many of the services from a popular PLC and better helps SCADA researchers understand potential risks of exposed control system devices.
     109 + 
     110 + - [Conpot](https://github.com/mushorg/conpot) - ICS/SCADA honeypot.
     111 + - [GasPot](https://github.com/sjhilt/GasPot) - Veeder Root Gaurdian AST, common in the oil and gas industry.
     112 + - [SCADA honeynet](http://scadahoneynet.sourceforge.net) - Building Honeypots for Industrial Networks.
     113 + - [gridpot](https://github.com/sk4ld/gridpot) - Open source tools for realistic-behaving electric grid honeynets.
     114 + - [scada-honeynet](http://www.digitalbond.com/blog/2007/07/24/scada-honeynet-article-in-infragard-publication/) - Mimics many of the services from a popular PLC and better helps SCADA researchers understand potential risks of exposed control system devices.
    106 115   
    107 116  - Other/random
    108  - - [Damn Simple Honeypot (DSHP)](https://github.com/naorlivne/dshp) - Honeypot framework with pluggable handlers.
    109  - - [NOVA](https://github.com/DataSoft/Nova) - Uses honeypots as detectors, looks like a complete system.
    110  - - [OpenFlow Honeypot (OFPot)](https://github.com/upa/ofpot) - Redirects traffic for unused IPs to a honeypot, built on POX.
    111  - - [OpenCanary](https://github.com/thinkst/opencanary) - Modular and decentralised honeypot daemon that runs several canary versions of services that alerts when a service is (ab)used.
    112  - - [ciscoasa_honeypot](https://github.com/cymmetria/ciscoasa_honeypot) A low interaction honeypot for the Cisco ASA component capable of detecting CVE-2018-0101, a DoS and remote code execution vulnerability.
    113  - - [miniprint](https://github.com/sa7mon/miniprint) - A medium interaction printer honeypot.
     117 + 
     118 + - [Damn Simple Honeypot (DSHP)](https://github.com/naorlivne/dshp) - Honeypot framework with pluggable handlers.
     119 + - [NOVA](https://github.com/DataSoft/Nova) - Uses honeypots as detectors, looks like a complete system.
     120 + - [OpenFlow Honeypot (OFPot)](https://github.com/upa/ofpot) - Redirects traffic for unused IPs to a honeypot, built on POX.
     121 + - [OpenCanary](https://github.com/thinkst/opencanary) - Modular and decentralised honeypot daemon that runs several canary versions of services that alerts when a service is (ab)used.
     122 + - [ciscoasa_honeypot](https://github.com/cymmetria/ciscoasa_honeypot) A low interaction honeypot for the Cisco ASA component capable of detecting CVE-2018-0101, a DoS and remote code execution vulnerability.
     123 + - [miniprint](https://github.com/sa7mon/miniprint) - A medium interaction printer honeypot.
    114 124   
    115 125  - Botnet C2 tools
    116  - - [Hale](https://github.com/pjlantz/Hale) - Botnet command and control monitor.
    117  - - [dnsMole](https://code.google.com/archive/p/dns-mole/) - Analyses DNS traffic and potentionaly detect botnet command and control server activity, along with infected hosts.
     126 + 
     127 + - [Hale](https://github.com/pjlantz/Hale) - Botnet command and control monitor.
     128 + - [dnsMole](https://code.google.com/archive/p/dns-mole/) - Analyses DNS traffic and potentionaly detect botnet command and control server activity, along with infected hosts.
    118 129   
    119 130  - IPv6 attack detection tool
    120  - - [ipv6-attack-detector](https://github.com/mzweilin/ipv6-attack-detector/) - Google Summer of Code 2012 project, supported by The Honeynet Project organization.
     131 + 
     132 + - [ipv6-attack-detector](https://github.com/mzweilin/ipv6-attack-detector/) - Google Summer of Code 2012 project, supported by The Honeynet Project organization.
    121 133   
    122 134  - Dynamic code instrumentation toolkit
    123  - - [Frida](https://www.frida.re) - Inject JavaScript to explore native apps on Windows, Mac, Linux, iOS and Android.
     135 + 
     136 + - [Frida](https://www.frida.re) - Inject JavaScript to explore native apps on Windows, Mac, Linux, iOS and Android.
    124 137   
    125 138  - Tool to convert website to server honeypots
    126  - - [HIHAT](http://hihat.sourceforge.net/) - Transform arbitrary PHP applications into web-based high-interaction Honeypots.
     139 + 
     140 + - [HIHAT](http://hihat.sourceforge.net/) - Transform arbitrary PHP applications into web-based high-interaction Honeypots.
    127 141   
    128 142  - Malware collector
    129  - - [Kippo-Malware](https://bruteforcelab.com/kippo-malware) - Python script that will download all malicious files stored as URLs in a Kippo SSH honeypot database.
     143 + 
     144 + - [Kippo-Malware](https://bruteforcelab.com/kippo-malware) - Python script that will download all malicious files stored as URLs in a Kippo SSH honeypot database.
    130 145   
    131 146  - Distributed sensor deployment
    132  - - [Community Honey Network](https://communityhoneynetwork.readthedocs.io/en/stable/) - CHN aims to make deployments honeypots and honeypot management tools easy and flexible. The default deployment method uses Docker Compose and Docker to deploy with a few simple commands.
    133  - - [Modern Honey Network](https://github.com/threatstream/mhn) - Multi-snort and honeypot sensor management, uses a network of VMs, small footprint SNORT installations, stealthy dionaeas, and a centralized server for management.
     147 + 
     148 + - [Community Honey Network](https://communityhoneynetwork.readthedocs.io/en/stable/) - CHN aims to make deployments honeypots and honeypot management tools easy and flexible. The default deployment method uses Docker Compose and Docker to deploy with a few simple commands.
     149 + - [Modern Honey Network](https://github.com/threatstream/mhn) - Multi-snort and honeypot sensor management, uses a network of VMs, small footprint SNORT installations, stealthy dionaeas, and a centralized server for management.
    134 150   
    135 151  - Network Analysis Tool
    136  - - [Tracexploit](https://code.google.com/archive/p/tracexploit/) - Replay network packets.
     152 + 
     153 + - [Tracexploit](https://code.google.com/archive/p/tracexploit/) - Replay network packets.
    137 154   
    138 155  - Log anonymizer
    139  - - [LogAnon](http://code.google.com/archive/p/loganon/) - Log anonymization library that helps having anonymous logs consistent between logs and network captures.
     156 + 
     157 + - [LogAnon](http://code.google.com/archive/p/loganon/) - Log anonymization library that helps having anonymous logs consistent between logs and network captures.
    140 158   
    141 159  - Low interaction honeypot (router back door)
    142  - - [Honeypot-32764](https://github.com/knalli/honeypot-for-tcp-32764) - Honeypot for router backdoor (TCP 32764).
    143  - - [WAPot](https://github.com/lcashdol/WAPot) - Honeypot that can be used to observe traffic directed at home routers.
     160 + 
     161 + - [Honeypot-32764](https://github.com/knalli/honeypot-for-tcp-32764) - Honeypot for router backdoor (TCP 32764).
     162 + - [WAPot](https://github.com/lcashdol/WAPot) - Honeypot that can be used to observe traffic directed at home routers.
    144 163   
    145 164  - honeynet farm traffic redirector
    146  - - [Honeymole](https://web.archive.org/web/20100326040550/http://www.honeynet.org.pt:80/index.php/HoneyMole) - Deploy multiple sensors that redirect traffic to a centralized collection of honeypots.
     165 + 
     166 + - [Honeymole](https://web.archive.org/web/20100326040550/http://www.honeynet.org.pt:80/index.php/HoneyMole) - Deploy multiple sensors that redirect traffic to a centralized collection of honeypots.
    147 167   
    148 168  - HTTPS Proxy
    149  - - [mitmproxy](https://mitmproxy.org/) - Allows traffic flows to be intercepted, inspected, modified, and replayed.
     169 + 
     170 + - [mitmproxy](https://mitmproxy.org/) - Allows traffic flows to be intercepted, inspected, modified, and replayed.
    150 171   
    151 172  - System instrumentation
    152  - - [Sysdig](https://sysdig.com/opensource/) - Open source, system-level exploration allows one to capture system state and activity from a running GNU/Linux instance, then save, filter, and analyze the results.
    153  - - [Fibratus](https://github.com/rabbitstack/fibratus) - Tool for exploration and tracing of the Windows kernel.
     173 + 
     174 + - [Sysdig](https://sysdig.com/opensource/) - Open source, system-level exploration allows one to capture system state and activity from a running GNU/Linux instance, then save, filter, and analyze the results.
     175 + - [Fibratus](https://github.com/rabbitstack/fibratus) - Tool for exploration and tracing of the Windows kernel.
    154 176   
    155 177  - Honeypot for USB-spreading malware
    156  - - [Ghost-usb](https://github.com/honeynet/ghost-usb-honeypot) - Honeypot for malware that propagates via USB storage devices.
     178 + 
     179 + - [Ghost-usb](https://github.com/honeynet/ghost-usb-honeypot) - Honeypot for malware that propagates via USB storage devices.
    157 180   
    158 181  - Data Collection
    159  - - [Kippo2MySQL](https://bruteforcelab.com/kippo2mysql) - Extracts some very basic stats from Kippo’s text-based log files and inserts them in a MySQL database.
    160  - - [Kippo2ElasticSearch](https://bruteforcelab.com/kippo2elasticsearch) - Python script to transfer data from a Kippo SSH honeypot MySQL database to an ElasticSearch instance (server or cluster).
     182 + 
     183 + - [Kippo2MySQL](https://bruteforcelab.com/kippo2mysql) - Extracts some very basic stats from Kippo’s text-based log files and inserts them in a MySQL database.
     184 + - [Kippo2ElasticSearch](https://bruteforcelab.com/kippo2elasticsearch) - Python script to transfer data from a Kippo SSH honeypot MySQL database to an ElasticSearch instance (server or cluster).
    161 185   
    162 186  - Passive network audit framework parser
    163  - - [Passive Network Audit Framework (pnaf)](https://github.com/jusafing/pnaf) - Framework that combines multiple passive and automated analysis techniques in order to provide a security assessment of network platforms.
     187 + 
     188 + - [Passive Network Audit Framework (pnaf)](https://github.com/jusafing/pnaf) - Framework that combines multiple passive and automated analysis techniques in order to provide a security assessment of network platforms.
    164 189   
    165 190  - VM monitoring and tools
    166  - - [Antivmdetect](https://github.com/nsmfoo/antivmdetection) - Script to create templates to use with VirtualBox to make VM detection harder.
    167  - - [VMCloak](https://github.com/hatching/vmcloak) - Automated Virtual Machine Generation and Cloaking for Cuckoo Sandbox.
    168  - - [vmitools](http://libvmi.com/) - C library with Python bindings that makes it easy to monitor the low-level details of a running virtual machine.
     191 + 
     192 + - [Antivmdetect](https://github.com/nsmfoo/antivmdetection) - Script to create templates to use with VirtualBox to make VM detection harder.
     193 + - [VMCloak](https://github.com/hatching/vmcloak) - Automated Virtual Machine Generation and Cloaking for Cuckoo Sandbox.
     194 + - [vmitools](http://libvmi.com/) - C library with Python bindings that makes it easy to monitor the low-level details of a running virtual machine.
    169 195   
    170 196  - Binary debugger
    171  - - [Hexgolems - Pint Debugger Backend](https://github.com/hexgolems/pint) - Debugger backend and LUA wrapper for PIN.
    172  - - [Hexgolems - Schem Debugger Frontend](https://github.com/hexgolems/schem) - Debugger frontend.
     197 + 
     198 + - [Hexgolems - Pint Debugger Backend](https://github.com/hexgolems/pint) - Debugger backend and LUA wrapper for PIN.
     199 + - [Hexgolems - Schem Debugger Frontend](https://github.com/hexgolems/schem) - Debugger frontend.
    173 200   
    174 201  - Mobile Analysis Tool
    175  - - [Androguard](https://github.com/androguard/androguard) - Reverse engineering, Malware and goodware analysis of Android applications and more.
    176  - - [APKinspector](https://github.com/honeynet/apkinspector/) - Powerful GUI tool for analysts to analyze the Android applications.
     202 + 
     203 + - [Androguard](https://github.com/androguard/androguard) - Reverse engineering, Malware and goodware analysis of Android applications and more.
     204 + - [APKinspector](https://github.com/honeynet/apkinspector/) - Powerful GUI tool for analysts to analyze the Android applications.
    177 205   
    178 206  - Low interaction honeypot
    179  - - [Honeyperl](https://sourceforge.net/projects/honeyperl/) - Honeypot software based in Perl with plugins developed for many functions like : wingates, telnet, squid, smtp, etc.
    180  - - [T-Pot](https://github.com/dtag-dev-sec/tpotce) - All in one honeypot appliance from telecom provider T-Mobile
     207 + 
     208 + - [Honeyperl](https://sourceforge.net/projects/honeyperl/) - Honeypot software based in Perl with plugins developed for many functions like : wingates, telnet, squid, smtp, etc.
     209 + - [T-Pot](https://github.com/dtag-dev-sec/tpotce) - All in one honeypot appliance from telecom provider T-Mobile
    181 210   
    182 211  - Honeynet data fusion
    183  - - [HFlow2](https://projects.honeynet.org/hflow) - Data coalesing tool for honeynet/network analysis.
     212 + 
     213 + - [HFlow2](https://projects.honeynet.org/hflow) - Data coalesing tool for honeynet/network analysis.
    184 214   
    185 215  - Server
    186  - - [Amun](http://amunhoney.sourceforge.net) - Vulnerability emulation honeypot.
    187  - - [Artillery](https://github.com/trustedsec/artillery/) - Open-source blue team tool designed to protect Linux and Windows operating systems through multiple methods.
    188  - - [Bait and Switch](http://baitnswitch.sourceforge.net) - Redirects all hostile traffic to a honeypot that is partially mirroring your production system.
    189  - - [Bifrozt](https://github.com/Ziemeck/bifrozt-ansible) - Automatic deploy bifrozt with ansible.
    190  - - [Conpot](http://conpot.org/) - Low interactive server side Industrial Control Systems honeypot.
    191  - - [Heralding](https://github.com/johnnykv/heralding) - Credentials catching honeypot.
    192  - - [HoneyWRT](https://github.com/CanadianJeff/honeywrt) - Low interaction Python honeypot designed to mimic services or ports that might get targeted by attackers.
    193  - - [Honeyd](https://github.com/provos/honeyd) - See [honeyd tools](#honeyd-tools).
    194  - - [Honeysink](http://www.honeynet.org/node/773) - Open source network sinkhole that provides a mechanism for detection and prevention of malicious traffic on a given network.
    195  - - [Hontel](https://github.com/stamparm/hontel) - Telnet Honeypot.
    196  - - [KFSensor](http://www.keyfocus.net/kfsensor/) - Windows based honeypot Intrusion Detection System (IDS).
    197  - - [LaBrea](http://labrea.sourceforge.net/labrea-info.html) - Takes over unused IP addresses, and creates virtual servers that are attractive to worms, hackers, and other denizens of the Internet.
    198  - - [MTPot](https://github.com/Cymmetria/MTPot) - Open Source Telnet Honeypot, focused on Mirai malware.
    199  - - [SIREN](https://github.com/blaverick62/SIREN) - Semi-Intelligent HoneyPot Network - HoneyNet Intelligent Virtual Environment.
    200  - - [TelnetHoney](https://github.com/balte/TelnetHoney) - Simple telnet honeypot.
    201  - - [UDPot Honeypot](https://github.com/jekil/UDPot) - Simple UDP/DNS honeypot scripts.
    202  - - [Yet Another Fake Honeypot (YAFH)](https://github.com/fnzv/YAFH) - Simple honeypot written in Go.
    203  - - [arctic-swallow](https://github.com/ajackal/arctic-swallow) - Low interaction honeypot.
    204  - - [fapro](https://github.com/fofapro/fapro) - Fake Protocol Server.
    205  - - [glutton](https://github.com/mushorg/glutton) - All eating honeypot.
    206  - - [go-HoneyPot](https://github.com/Mojachieee/go-HoneyPot) - Honeypot server written in Go.
    207  - - [go-emulators](https://github.com/kingtuna/go-emulators) - Honeypot Golang emulators.
    208  - - [honeymail](https://github.com/sec51/honeymail) - SMTP honeypot written in Golang.
    209  - - [honeytrap](https://github.com/tillmannw/honeytrap) - Low-interaction honeypot and network security tool written to catch attacks against TCP and UDP services.
    210  - - [imap-honey](https://github.com/yvesago/imap-honey) - IMAP honeypot written in Golang.
    211  - - [mwcollectd](https://www.openhub.net/p/mwcollectd) - Versatile malware collection daemon, uniting the best features of nepenthes and honeytrap.
    212  - - [potd](https://github.com/lnslbrty/potd) - Highly scalable low- to medium-interaction SSH/TCP honeypot designed for OpenWrt/IoT devices leveraging several Linux kernel features, such as namespaces, seccomp and thread capabilities.
    213  - - [portlurker](https://github.com/bartnv/portlurker) - Port listener in Rust with protocol guessing and safe string display.
    214  - - [slipm-honeypot](https://github.com/rshipp/slipm-honeypot) - Simple low-interaction port monitoring honeypot.
    215  - - [telnet-iot-honeypot](https://github.com/Phype/telnet-iot-honeypot) - Python telnet honeypot for catching botnet binaries.
    216  - - [telnetlogger](https://github.com/robertdavidgraham/telnetlogger) - Telnet honeypot designed to track the Mirai botnet.
    217  - - [vnclowpot](https://github.com/magisterquis/vnclowpot) - Low interaction VNC honeypot.
    218 216   
     217 + - [Amun](http://amunhoney.sourceforge.net) - Vulnerability emulation honeypot.
     218 + - [Artillery](https://github.com/trustedsec/artillery/) - Open-source blue team tool designed to protect Linux and Windows operating systems through multiple methods.
     219 + - [Bait and Switch](http://baitnswitch.sourceforge.net) - Redirects all hostile traffic to a honeypot that is partially mirroring your production system.
     220 + - [Bifrozt](https://github.com/Ziemeck/bifrozt-ansible) - Automatic deploy bifrozt with ansible.
     221 + - [Conpot](http://conpot.org/) - Low interactive server side Industrial Control Systems honeypot.
     222 + - [Heralding](https://github.com/johnnykv/heralding) - Credentials catching honeypot.
     223 + - [HoneyWRT](https://github.com/CanadianJeff/honeywrt) - Low interaction Python honeypot designed to mimic services or ports that might get targeted by attackers.
     224 + - [Honeyd](https://github.com/provos/honeyd) - See [honeyd tools](#honeyd-tools).
     225 + - [Honeysink](http://www.honeynet.org/node/773) - Open source network sinkhole that provides a mechanism for detection and prevention of malicious traffic on a given network.
     226 + - [Hontel](https://github.com/stamparm/hontel) - Telnet Honeypot.
     227 + - [KFSensor](http://www.keyfocus.net/kfsensor/) - Windows based honeypot Intrusion Detection System (IDS).
     228 + - [LaBrea](http://labrea.sourceforge.net/labrea-info.html) - Takes over unused IP addresses, and creates virtual servers that are attractive to worms, hackers, and other denizens of the Internet.
     229 + - [MTPot](https://github.com/Cymmetria/MTPot) - Open Source Telnet Honeypot, focused on Mirai malware.
     230 + - [SIREN](https://github.com/blaverick62/SIREN) - Semi-Intelligent HoneyPot Network - HoneyNet Intelligent Virtual Environment.
     231 + - [TelnetHoney](https://github.com/balte/TelnetHoney) - Simple telnet honeypot.
     232 + - [UDPot Honeypot](https://github.com/jekil/UDPot) - Simple UDP/DNS honeypot scripts.
     233 + - [Yet Another Fake Honeypot (YAFH)](https://github.com/fnzv/YAFH) - Simple honeypot written in Go.
     234 + - [arctic-swallow](https://github.com/ajackal/arctic-swallow) - Low interaction honeypot.
     235 + - [fapro](https://github.com/fofapro/fapro) - Fake Protocol Server.
     236 + - [glutton](https://github.com/mushorg/glutton) - All eating honeypot.
     237 + - [go-HoneyPot](https://github.com/Mojachieee/go-HoneyPot) - Honeypot server written in Go.
     238 + - [go-emulators](https://github.com/kingtuna/go-emulators) - Honeypot Golang emulators.
     239 + - [honeymail](https://github.com/sec51/honeymail) - SMTP honeypot written in Golang.
     240 + - [honeytrap](https://github.com/tillmannw/honeytrap) - Low-interaction honeypot and network security tool written to catch attacks against TCP and UDP services.
     241 + - [imap-honey](https://github.com/yvesago/imap-honey) - IMAP honeypot written in Golang.
     242 + - [mwcollectd](https://www.openhub.net/p/mwcollectd) - Versatile malware collection daemon, uniting the best features of nepenthes and honeytrap.
     243 + - [potd](https://github.com/lnslbrty/potd) - Highly scalable low- to medium-interaction SSH/TCP honeypot designed for OpenWrt/IoT devices leveraging several Linux kernel features, such as namespaces, seccomp and thread capabilities.
     244 + - [portlurker](https://github.com/bartnv/portlurker) - Port listener in Rust with protocol guessing and safe string display.
     245 + - [slipm-honeypot](https://github.com/rshipp/slipm-honeypot) - Simple low-interaction port monitoring honeypot.
     246 + - [telnet-iot-honeypot](https://github.com/Phype/telnet-iot-honeypot) - Python telnet honeypot for catching botnet binaries.
     247 + - [telnetlogger](https://github.com/robertdavidgraham/telnetlogger) - Telnet honeypot designed to track the Mirai botnet.
     248 + - [vnclowpot](https://github.com/magisterquis/vnclowpot) - Low interaction VNC honeypot.
    219 249   
    220 250  - IDS signature generation
    221  - - [Honeycomb](http://www.icir.org/christian/honeycomb/) - Automated signature creation using honeypots.
     251 + 
     252 + - [Honeycomb](http://www.icir.org/christian/honeycomb/) - Automated signature creation using honeypots.
    222 253   
    223 254  - Lookup service for AS-numbers and prefixes
    224  - - [CC2ASN](http://www.cc2asn.com/) - Simple lookup service for AS-numbers and prefixes belonging to any given country in the world.
     255 + 
     256 + - [CC2ASN](http://www.cc2asn.com/) - Simple lookup service for AS-numbers and prefixes belonging to any given country in the world.
    225 257   
    226 258  - Data Collection / Data Sharing
    227  - - [HPfriends](http://hpfriends.honeycloud.net/#/home) - Honeypot data-sharing platform.
    228  - - [hpfriends - real-time social data-sharing](https://heipei.io/sigint-hpfriends/) - Presentation about HPFriends feed system
    229  - - [HPFeeds](https://github.com/rep/hpfeeds/) - Lightweight authenticated publish-subscribe protocol.
     259 + 
     260 + - [HPfriends](http://hpfriends.honeycloud.net/#/home) - Honeypot data-sharing platform.
     261 + - [hpfriends - real-time social data-sharing](https://heipei.io/sigint-hpfriends/) - Presentation about HPFriends feed system
     262 + - [HPFeeds](https://github.com/rep/hpfeeds/) - Lightweight authenticated publish-subscribe protocol.
    230 263   
    231 264  - Central management tool
    232  - - [PHARM](http://www.nepenthespharm.com/) - Manage, report, and analyze your distributed Nepenthes instances.
     265 + 
     266 + - [PHARM](http://www.nepenthespharm.com/) - Manage, report, and analyze your distributed Nepenthes instances.
    233 267   
    234 268  - Network connection analyzer
    235  - - [Impost](http://impost.sourceforge.net/) - Network security auditing tool designed to analyze the forensics behind compromised and/or vulnerable daemons.
     269 + 
     270 + - [Impost](http://impost.sourceforge.net/) - Network security auditing tool designed to analyze the forensics behind compromised and/or vulnerable daemons.
    236 271   
    237 272  - Honeypot deployment
    238  - - [Modern Honeynet Network](http://threatstream.github.io/mhn/) - Streamlines deployment and management of secure honeypots.
     273 + 
     274 + - [Modern Honeynet Network](http://threatstream.github.io/mhn/) - Streamlines deployment and management of secure honeypots.
    239 275   
    240 276  - Honeypot extensions to Wireshark
    241  - - [Wireshark Extensions](https://www.honeynet.org/project/WiresharkExtensions) - Apply Snort IDS rules and signatures against packet capture files using Wireshark.
    242 277   
     278 + - [Wireshark Extensions](https://www.honeynet.org/project/WiresharkExtensions) - Apply Snort IDS rules and signatures against packet capture files using Wireshark.
    243 279   
    244 280  - Client
    245  - - [CWSandbox / GFI Sandbox](https://www.gfi.com/products-and-solutions/all-products)
    246  - - [Capture-HPC-Linux](https://redmine.honeynet.org/projects/linux-capture-hpc/wiki)
    247  - - [Capture-HPC-NG](https://github.com/CERT-Polska/HSN-Capture-HPC-NG)
    248  - - [Capture-HPC](https://projects.honeynet.org/capture-hpc) - High interaction client honeypot (also called honeyclient).
    249  - - [HoneyBOT](http://www.atomicsoftwaresolutions.com/)
    250  - - [HoneyC](https://projects.honeynet.org/honeyc)
    251  - - [HoneySpider Network](https://github.com/CERT-Polska/hsn2-bundle) - Highly-scalable system integrating multiple client honeypots to detect malicious websites.
    252  - - [HoneyWeb](https://code.google.com/archive/p/gsoc-honeyweb/) - Web interface created to manage and remotely share Honeyclients resources.
    253  - - [Jsunpack-n](https://github.com/urule99/jsunpack-n)
    254  - - [MonkeySpider](http://monkeyspider.sourceforge.net)
    255  - - [PhoneyC](https://github.com/honeynet/phoneyc) - Python honeyclient (later replaced by Thug).
    256  - - [Pwnypot](https://github.com/shjalayeri/pwnypot) - High Interaction Client Honeypot.
    257  - - [Rumal](https://github.com/thugs-rumal/) - Thug's Rumāl: a Thug's dress and weapon.
    258  - - [Shelia](https://www.cs.vu.nl/~herbertb/misc/shelia/) - Client-side honeypot for attack detection.
    259  - - [Thug](https://buffer.github.io/thug/) - Python-based low-interaction honeyclient.
    260  - - [Thug Distributed Task Queuing](https://thug-distributed.readthedocs.io/en/latest/index.html)
    261  - - [Trigona](https://www.honeynet.org/project/Trigona)
    262  - - [URLQuery](https://urlquery.net/)
    263  - - [YALIH (Yet Another Low Interaction Honeyclient)](https://github.com/Masood-M/yalih) - Low-interaction client honeypot designed to detect malicious websites through signature, anomaly, and pattern matching techniques.
     281 + 
     282 + - [CWSandbox / GFI Sandbox](https://www.gfi.com/products-and-solutions/all-products)
     283 + - [Capture-HPC-Linux](https://redmine.honeynet.org/projects/linux-capture-hpc/wiki)
     284 + - [Capture-HPC-NG](https://github.com/CERT-Polska/HSN-Capture-HPC-NG)
     285 + - [Capture-HPC](https://projects.honeynet.org/capture-hpc) - High interaction client honeypot (also called honeyclient).
     286 + - [HoneyBOT](http://www.atomicsoftwaresolutions.com/)
     287 + - [HoneyC](https://projects.honeynet.org/honeyc)
     288 + - [HoneySpider Network](https://github.com/CERT-Polska/hsn2-bundle) - Highly-scalable system integrating multiple client honeypots to detect malicious websites.
     289 + - [HoneyWeb](https://code.google.com/archive/p/gsoc-honeyweb/) - Web interface created to manage and remotely share Honeyclients resources.
     290 + - [Jsunpack-n](https://github.com/urule99/jsunpack-n)
     291 + - [MonkeySpider](http://monkeyspider.sourceforge.net)
     292 + - [PhoneyC](https://github.com/honeynet/phoneyc) - Python honeyclient (later replaced by Thug).
     293 + - [Pwnypot](https://github.com/shjalayeri/pwnypot) - High Interaction Client Honeypot.
     294 + - [Rumal](https://github.com/thugs-rumal/) - Thug's Rumāl: a Thug's dress and weapon.
     295 + - [Shelia](https://www.cs.vu.nl/~herbertb/misc/shelia/) - Client-side honeypot for attack detection.
     296 + - [Thug](https://buffer.github.io/thug/) - Python-based low-interaction honeyclient.
     297 + - [Thug Distributed Task Queuing](https://thug-distributed.readthedocs.io/en/latest/index.html)
     298 + - [Trigona](https://www.honeynet.org/project/Trigona)
     299 + - [URLQuery](https://urlquery.net/)
     300 + - [YALIH (Yet Another Low Interaction Honeyclient)](https://github.com/Masood-M/yalih) - Low-interaction client honeypot designed to detect malicious websites through signature, anomaly, and pattern matching techniques.
    264 301   
    265 302  - Honeypot
    266  - - [Deception Toolkit](http://www.all.net/dtk/dtk.html)
    267  - - [IMHoneypot](https://github.com/mushorg/imhoneypot)
     303 + 
     304 + - [Deception Toolkit](http://www.all.net/dtk/dtk.html)
     305 + - [IMHoneypot](https://github.com/mushorg/imhoneypot)
    268 306   
    269 307  - PDF document inspector
    270  - - [peepdf](https://github.com/jesparza/peepdf) - Powerful Python tool to analyze PDF documents.
     308 + 
     309 + - [peepdf](https://github.com/jesparza/peepdf) - Powerful Python tool to analyze PDF documents.
    271 310   
    272 311  - Hybrid low/high interaction honeypot
    273  - - [HoneyBrid](http://honeybrid.sourceforge.net)
     312 + 
     313 + - [HoneyBrid](http://honeybrid.sourceforge.net)
    274 314   
    275 315  - SSH Honeypots
    276  - - [Blacknet](https://github.com/morian/blacknet) - Multi-head SSH honeypot system.
    277  - - [Cowrie](https://github.com/cowrie/cowrie) - Cowrie SSH Honeypot (based on kippo).
    278  - - [DShield docker](https://github.com/xme/dshield-docker) - Docker container running cowrie with DShield output enabled.
    279  - - [HonSSH](https://github.com/tnich/honssh) - Logs all SSH communications between a client and server.
    280  - - [HUDINX](https://github.com/Cryptix720/HUDINX) - Tiny interaction SSH honeypot engineered in Python to log brute force attacks and, most importantly, the entire shell interaction performed by the attacker.
    281  - - [Kippo](https://github.com/desaster/kippo) - Medium interaction SSH honeypot.
    282  - - [Kippo_JunOS](https://github.com/gregcmartin/Kippo_JunOS) - Kippo configured to be a backdoored netscreen.
    283  - - [Kojoney2](https://github.com/madirish/kojoney2) - Low interaction SSH honeypot written in Python and based on Kojoney by Jose Antonio Coret.
    284  - - [Kojoney](http://kojoney.sourceforge.net/) - Python-based Low interaction honeypot that emulates an SSH server implemented with Twisted Conch.
    285  - - [Longitudinal Analysis of SSH Cowrie Honeypot Logs](https://github.com/deroux/longitudinal-analysis-cowrie) - Python based command line tool to analyze cowrie logs over time.
    286  - - [LongTail Log Analysis @ Marist College](http://longtail.it.marist.edu/honey/) - Analyzed SSH honeypot logs.
    287  - - [Malbait](https://github.com/batchmcnulty/Malbait) - Simple TCP/UDP honeypot implemented in Perl.
    288  - - [MockSSH](https://github.com/ncouture/MockSSH) - Mock an SSH server and define all commands it supports (Python, Twisted).
    289  - - [cowrie2neo](https://github.com/xlfe/cowrie2neo) - Parse cowrie honeypot logs into a neo4j database.
    290  - - [go-sshoney](https://github.com/ashmckenzie/go-sshoney) - SSH Honeypot.
    291  - - [go0r](https://github.com/fzerorubigd/go0r) - Simple ssh honeypot in Golang.
    292  - - [gohoney](https://github.com/PaulMaddox/gohoney) - SSH honeypot written in Go.
    293  - - [hived](https://github.com/sahilm/hived) - Golang-based honeypot.
    294  - - [hnypots-agent)](https://github.com/joshrendek/hnypots-agent) - SSH Server in Go that logs username and password combinations.
    295  - - [honeypot.go](https://github.com/mdp/honeypot.go) - SSH Honeypot written in Go.
    296  - - [honeyssh](https://github.com/ppacher/honeyssh) - Credential dumping SSH honeypot with statistics.
    297  - - [hornet](https://github.com/czardoz/hornet) - Medium interaction SSH honeypot that supports multiple virtual hosts.
    298  - - [ssh-auth-logger](https://github.com/JustinAzoff/ssh-auth-logger) - Low/zero interaction SSH authentication logging honeypot.
    299  - - [ssh-honeypot](https://github.com/droberson/ssh-honeypot) - Fake sshd that logs IP addresses, usernames, and passwords.
    300  - - [ssh-honeypot](https://github.com/amv42/sshd-honeypot) - Modified version of the OpenSSH deamon that forwards commands to Cowrie where all commands are interpreted and returned.
    301  - - [ssh-honeypotd](https://github.com/sjinks/ssh-honeypotd) - Low-interaction SSH honeypot written in C.
    302  - - [sshForShits](https://github.com/traetox/sshForShits) - Framework for a high interaction SSH honeypot.
    303  - - [sshesame](https://github.com/jaksi/sshesame) - Fake SSH server that lets everyone in and logs their activity.
    304  - - [sshhipot](https://github.com/magisterquis/sshhipot) - High-interaction MitM SSH honeypot.
    305  - - [sshlowpot](https://github.com/magisterquis/sshlowpot) - Yet another no-frills low-interaction SSH honeypot in Go.
    306  - - [sshsyrup](https://github.com/mkishere/sshsyrup) - Simple SSH Honeypot with features to capture terminal activity and upload to asciinema.org.
    307  - - [twisted-honeypots](https://github.com/lanjelot/twisted-honeypots) - SSH, FTP and Telnet honeypots based on Twisted.
     316 + 
     317 + - [Blacknet](https://github.com/morian/blacknet) - Multi-head SSH honeypot system.
     318 + - [Cowrie](https://github.com/cowrie/cowrie) - Cowrie SSH Honeypot (based on kippo).
     319 + - [DShield docker](https://github.com/xme/dshield-docker) - Docker container running cowrie with DShield output enabled.
     320 + - [HonSSH](https://github.com/tnich/honssh) - Logs all SSH communications between a client and server.
     321 + - [HUDINX](https://github.com/Cryptix720/HUDINX) - Tiny interaction SSH honeypot engineered in Python to log brute force attacks and, most importantly, the entire shell interaction performed by the attacker.
     322 + - [Kippo](https://github.com/desaster/kippo) - Medium interaction SSH honeypot.
     323 + - [Kippo_JunOS](https://github.com/gregcmartin/Kippo_JunOS) - Kippo configured to be a backdoored netscreen.
     324 + - [Kojoney2](https://github.com/madirish/kojoney2) - Low interaction SSH honeypot written in Python and based on Kojoney by Jose Antonio Coret.
     325 + - [Kojoney](http://kojoney.sourceforge.net/) - Python-based Low interaction honeypot that emulates an SSH server implemented with Twisted Conch.
     326 + - [Longitudinal Analysis of SSH Cowrie Honeypot Logs](https://github.com/deroux/longitudinal-analysis-cowrie) - Python based command line tool to analyze cowrie logs over time.
     327 + - [LongTail Log Analysis @ Marist College](http://longtail.it.marist.edu/honey/) - Analyzed SSH honeypot logs.
     328 + - [Malbait](https://github.com/batchmcnulty/Malbait) - Simple TCP/UDP honeypot implemented in Perl.
     329 + - [MockSSH](https://github.com/ncouture/MockSSH) - Mock an SSH server and define all commands it supports (Python, Twisted).
     330 + - [cowrie2neo](https://github.com/xlfe/cowrie2neo) - Parse cowrie honeypot logs into a neo4j database.
     331 + - [go-sshoney](https://github.com/ashmckenzie/go-sshoney) - SSH Honeypot.
     332 + - [go0r](https://github.com/fzerorubigd/go0r) - Simple ssh honeypot in Golang.
     333 + - [gohoney](https://github.com/PaulMaddox/gohoney) - SSH honeypot written in Go.
     334 + - [hived](https://github.com/sahilm/hived) - Golang-based honeypot.
     335 + - [hnypots-agent)](https://github.com/joshrendek/hnypots-agent) - SSH Server in Go that logs username and password combinations.
     336 + - [honeypot.go](https://github.com/mdp/honeypot.go) - SSH Honeypot written in Go.
     337 + - [honeyssh](https://github.com/ppacher/honeyssh) - Credential dumping SSH honeypot with statistics.
     338 + - [hornet](https://github.com/czardoz/hornet) - Medium interaction SSH honeypot that supports multiple virtual hosts.
     339 + - [ssh-auth-logger](https://github.com/JustinAzoff/ssh-auth-logger) - Low/zero interaction SSH authentication logging honeypot.
     340 + - [ssh-honeypot](https://github.com/droberson/ssh-honeypot) - Fake sshd that logs IP addresses, usernames, and passwords.
     341 + - [ssh-honeypot](https://github.com/amv42/sshd-honeypot) - Modified version of the OpenSSH deamon that forwards commands to Cowrie where all commands are interpreted and returned.
     342 + - [ssh-honeypotd](https://github.com/sjinks/ssh-honeypotd) - Low-interaction SSH honeypot written in C.
     343 + - [sshForShits](https://github.com/traetox/sshForShits) - Framework for a high interaction SSH honeypot.
     344 + - [sshesame](https://github.com/jaksi/sshesame) - Fake SSH server that lets everyone in and logs their activity.
     345 + - [sshhipot](https://github.com/magisterquis/sshhipot) - High-interaction MitM SSH honeypot.
     346 + - [sshlowpot](https://github.com/magisterquis/sshlowpot) - Yet another no-frills low-interaction SSH honeypot in Go.
     347 + - [sshsyrup](https://github.com/mkishere/sshsyrup) - Simple SSH Honeypot with features to capture terminal activity and upload to asciinema.org.
     348 + - [twisted-honeypots](https://github.com/lanjelot/twisted-honeypots) - SSH, FTP and Telnet honeypots based on Twisted.
    308 349   
    309 350  - Distributed sensor project
    310  - - [DShield Web Honeypot Project](https://sites.google.com/site/webhoneypotsite/)
     351 + 
     352 + - [DShield Web Honeypot Project](https://sites.google.com/site/webhoneypotsite/)
    311 353   
    312 354  - A pcap analyzer
    313  - - [Honeysnap](https://projects.honeynet.org/honeysnap/)
     355 + 
     356 + - [Honeysnap](https://projects.honeynet.org/honeysnap/)
    314 357   
    315 358  - Network traffic redirector
    316  - - [Honeywall](https://projects.honeynet.org/honeywall/)
     359 + 
     360 + - [Honeywall](https://projects.honeynet.org/honeywall/)
    317 361   
    318 362  - Honeypot Distribution with mixed content
    319  - - [HoneyDrive](https://bruteforcelab.com/honeydrive)
     363 + 
     364 + - [HoneyDrive](https://bruteforcelab.com/honeydrive)
    320 365   
    321 366  - Honeypot sensor
    322  - - [Honeeepi](https://redmine.honeynet.org/projects/honeeepi/wiki) - Honeypot sensor on a Raspberry Pi based on a customized Raspbian OS.
     367 + 
     368 + - [Honeeepi](https://redmine.honeynet.org/projects/honeeepi/wiki) - Honeypot sensor on a Raspberry Pi based on a customized Raspbian OS.
    323 369   
    324 370  - File carving
    325  - - [TestDisk & PhotoRec](https://www.cgsecurity.org/)
     371 + 
     372 + - [TestDisk & PhotoRec](https://www.cgsecurity.org/)
    326 373   
    327 374  - Behavioral analysis tool for win32
    328  - - [Capture BAT](https://www.honeynet.org/node/315)
     375 + 
     376 + - [Capture BAT](https://www.honeynet.org/node/315)
    329 377   
    330 378  - Live CD
    331  - - [DAVIX](https://www.secviz.org/node/89) - The DAVIX Live CD.
     379 + 
     380 + - [DAVIX](https://www.secviz.org/node/89) - The DAVIX Live CD.
    332 381   
    333 382  - Spamtrap
    334  - - [Mail::SMTP::Honeypot](https://metacpan.org/pod/release/MIKER/Mail-SMTP-Honeypot-0.11/Honeypot.pm) - Perl module that appears to provide the functionality of a standard SMTP server.
    335  - - [Mailoney](https://github.com/awhitehatter/mailoney) - SMTP honeypot, Open Relay, Cred Harvester written in python.
    336  - - [SendMeSpamIDS.py](https://github.com/johestephan/VerySimpleHoneypot) - Simple SMTP fetch all IDS and analyzer.
    337  - - [Shiva](https://github.com/shiva-spampot/shiva) - Spam Honeypot with Intelligent Virtual Analyzer.
    338  - - [Shiva The Spam Honeypot Tips And Tricks For Getting It Up And Running](https://www.pentestpartners.com/security-blog/shiva-the-spam-honeypot-tips-and-tricks-for-getting-it-up-and-running/)
    339  - - [SpamHAT](https://github.com/miguelraulb/spamhat) - Spam Honeypot Tool.
    340  - - [Spamhole](http://www.spamhole.net/)
    341  - - [honeypot](https://github.com/jadb/honeypot) - The Project Honey Pot un-official PHP SDK.
    342  - - [spamd](http://man.openbsd.org/cgi-bin/man.cgi?query=spamd%26apropos=0%26sektion=0%26manpath=OpenBSD+Current%26arch=i386%26format=html)
     383 + 
     384 + - [Mail::SMTP::Honeypot](https://metacpan.org/pod/release/MIKER/Mail-SMTP-Honeypot-0.11/Honeypot.pm) - Perl module that appears to provide the functionality of a standard SMTP server.
     385 + - [Mailoney](https://github.com/awhitehatter/mailoney) - SMTP honeypot, Open Relay, Cred Harvester written in python.
     386 + - [SendMeSpamIDS.py](https://github.com/johestephan/VerySimpleHoneypot) - Simple SMTP fetch all IDS and analyzer.
     387 + - [Shiva](https://github.com/shiva-spampot/shiva) - Spam Honeypot with Intelligent Virtual Analyzer.
     388 + - [Shiva The Spam Honeypot Tips And Tricks For Getting It Up And Running](https://www.pentestpartners.com/security-blog/shiva-the-spam-honeypot-tips-and-tricks-for-getting-it-up-and-running/)
     389 + - [SpamHAT](https://github.com/miguelraulb/spamhat) - Spam Honeypot Tool.
     390 + - [Spamhole](http://www.spamhole.net/)
     391 + - [honeypot](https://github.com/jadb/honeypot) - The Project Honey Pot un-official PHP SDK.
     392 + - [spamd](http://man.openbsd.org/cgi-bin/man.cgi?query=spamd%26apropos=0%26sektion=0%26manpath=OpenBSD+Current%26arch=i386%26format=html)
    343 393   
    344 394  - Commercial honeynet
    345  - - [Cymmetria Mazerunner](ttps://cymmetria.com/products/mazerunner/) - Leads attackers away from real targets and creates a footprint of the attack.
     395 + 
     396 + - [Cymmetria Mazerunner](ttps://cymmetria.com/products/mazerunner/) - Leads attackers away from real targets and creates a footprint of the attack.
    346 397   
    347 398  - Server (Bluetooth)
    348  - - [Bluepot](https://github.com/andrewmichaelsmith/bluepot)
     399 + 
     400 + - [Bluepot](https://github.com/andrewmichaelsmith/bluepot)
    349 401   
    350 402  - Dynamic analysis of Android apps
    351  - - [Droidbox](https://code.google.com/archive/p/droidbox/)
     403 + 
     404 + - [Droidbox](https://code.google.com/archive/p/droidbox/)
    352 405   
    353 406  - Dockerized Low Interaction packaging
    354  - - [Docker honeynet](https://github.com/sreinhardt/Docker-Honeynet) - Several Honeynet tools set up for Docker containers.
    355  - - [Dockerized Thug](https://hub.docker.com/r/honeynet/thug/) - Dockerized [Thug](https://github.com/buffer/thug) to analyze malicious web content.
    356  - - [Dockerpot](https://github.com/mrschyte/dockerpot) - Docker based honeypot.
    357  - - [Manuka](https://github.com/andrewmichaelsmith/manuka) - Docker based honeypot (Dionaea and Kippo).
    358  - - [honey_ports](https://github.com/run41/honey_ports) - Very simple but effective docker deployed honeypot to detect port scanning in your environment.
    359  - - [mhn-core-docker](https://github.com/MattCarothers/mhn-core-docker) - Core elements of the Modern Honey Network implemented in Docker.
     407 + 
     408 + - [Docker honeynet](https://github.com/sreinhardt/Docker-Honeynet) - Several Honeynet tools set up for Docker containers.
     409 + - [Dockerized Thug](https://hub.docker.com/r/honeynet/thug/) - Dockerized [Thug](https://github.com/buffer/thug) to analyze malicious web content.
     410 + - [Dockerpot](https://github.com/mrschyte/dockerpot) - Docker based honeypot.
     411 + - [Manuka](https://github.com/andrewmichaelsmith/manuka) - Docker based honeypot (Dionaea and Kippo).
     412 + - [honey_ports](https://github.com/run41/honey_ports) - Very simple but effective docker deployed honeypot to detect port scanning in your environment.
     413 + - [mhn-core-docker](https://github.com/MattCarothers/mhn-core-docker) - Core elements of the Modern Honey Network implemented in Docker.
    360 414   
    361 415  - Network analysis
    362  - - [Quechua](https://bitbucket.org/zaccone/quechua)
     416 + 
     417 + - [Quechua](https://bitbucket.org/zaccone/quechua)
    363 418   
    364 419  - SIP Server
    365  - - [Artemnesia VoIP](http://artemisa.sourceforge.net)
     420 + 
     421 + - [Artemnesia VoIP](http://artemisa.sourceforge.net)
    366 422   
    367 423  - IOT Honeypot
    368  - - [HoneyThing](https://github.com/omererdem/honeything) - TR-069 Honeypot.
    369  - - [Kako](https://github.com/darkarnium/kako) - Honeypots for a number of well known and deployed embedded device vulnerabilities.
     424 + 
     425 + - [HoneyThing](https://github.com/omererdem/honeything) - TR-069 Honeypot.
     426 + - [Kako](https://github.com/darkarnium/kako) - Honeypots for a number of well known and deployed embedded device vulnerabilities.
    370 427   
    371 428  - Honeytokens
    372  - - [CanaryTokens](https://github.com/thinkst/canarytokens) - Self-hostable honeytoken generator and reporting dashboard; demo version available at [CanaryTokens.org](https://canarytokens.org/generate).
    373  - - [Honeybits](https://github.com/0x4D31/honeybits) - Simple tool designed to enhance the effectiveness of your traps by spreading breadcrumbs and honeytokens across your production servers and workstations to lure the attacker toward your honeypots.
    374  - - [Honeyλ (HoneyLambda)](https://github.com/0x4D31/honeylambda) - Simple, serverless application designed to create and monitor URL honeytokens, on top of AWS Lambda and Amazon API Gateway.
    375  - - [dcept](https://github.com/secureworks/dcept) - Tool for deploying and detecting use of Active Directory honeytokens.
    376  - - [honeyku](https://github.com/0x4D31/honeyku) - Heroku-based web honeypot that can be used to create and monitor fake HTTP endpoints (i.e. honeytokens).
     429 + - [CanaryTokens](https://github.com/thinkst/canarytokens) - Self-hostable honeytoken generator and reporting dashboard; demo version available at [CanaryTokens.org](https://canarytokens.org/generate).
     430 + - [Honeybits](https://github.com/0x4D31/honeybits) - Simple tool designed to enhance the effectiveness of your traps by spreading breadcrumbs and honeytokens across your production servers and workstations to lure the attacker toward your honeypots.
     431 + - [Honeyλ (HoneyLambda)](https://github.com/0x4D31/honeylambda) - Simple, serverless application designed to create and monitor URL honeytokens, on top of AWS Lambda and Amazon API Gateway.
     432 + - [dcept](https://github.com/secureworks/dcept) - Tool for deploying and detecting use of Active Directory honeytokens.
     433 + - [honeyku](https://github.com/0x4D31/honeyku) - Heroku-based web honeypot that can be used to create and monitor fake HTTP endpoints (i.e. honeytokens).
    377 434   
    378 435  ## Honeyd Tools
    379 436   
    380 437  - Honeyd plugin
    381  - - [Honeycomb](http://www.honeyd.org/tools.php)
     438 + 
     439 + - [Honeycomb](http://www.honeyd.org/tools.php)
    382 440   
    383 441  - Honeyd viewer
    384  - - [Honeyview](http://honeyview.sourceforge.net/)
     442 + 
     443 + - [Honeyview](http://honeyview.sourceforge.net/)
    385 444   
    386 445  - Honeyd to MySQL connector
    387  - - [Honeyd2MySQL](https://bruteforcelab.com/honeyd2mysql)
    388 446   
    389  -- A script to visualize statistics from honeyd
    390  - - [Honeyd-Viz](https://bruteforcelab.com/honeyd-viz)
     447 + - [Honeyd2MySQL](https://bruteforcelab.com/honeyd2mysql)
    391 448   
    392  -- Honeyd stats
    393  - - [Honeydsum.pl](https://github.com/DataSoft/Honeyd/blob/master/scripts/misc/honeydsum-v0.3/honeydsum.pl)
     449 +- A script to visualize statistics from honeyd
    394 450   
     451 + - [Honeyd-Viz](https://bruteforcelab.com/honeyd-viz)
    395 452   
     453 +- Honeyd stats
     454 + - [Honeydsum.pl](https://github.com/DataSoft/Honeyd/blob/master/scripts/misc/honeydsum-v0.3/honeydsum.pl)
    396 455   
    397 456  ## Network and Artifact Analysis
    398 457   
    399 458  - Sandbox
    400  - - [Argos](http://www.few.vu.nl/argos/) - Emulator for capturing zero-day attacks.
    401  - - [COMODO automated sandbox](https://help.comodo.com/topic-72-1-451-4768-.html)
    402  - - [Cuckoo](https://cuckoosandbox.org/) - Leading open source automated malware analysis system.
    403  - - [Pylibemu](https://github.com/buffer/pylibemu) - Libemu Cython wrapper.
    404  - - [RFISandbox](https://monkey.org/~jose/software/rfi-sandbox/) - PHP 5.x script sandbox built on top of [funcall](https://pecl.php.net/package/funcall).
    405  - - [dorothy2](https://github.com/m4rco-/dorothy2) - Malware/botnet analysis framework written in Ruby.
    406  - - [imalse](https://github.com/hbhzwj/imalse) - Integrated MALware Simulator and Emulator.
    407  - - [libemu](https://github.com/buffer/libemu) - Shellcode emulation library, useful for shellcode detection.
    408 459   
     460 + - [Argos](http://www.few.vu.nl/argos/) - Emulator for capturing zero-day attacks.
     461 + - [COMODO automated sandbox](https://help.comodo.com/topic-72-1-451-4768-.html)
     462 + - [Cuckoo](https://cuckoosandbox.org/) - Leading open source automated malware analysis system.
     463 + - [Pylibemu](https://github.com/buffer/pylibemu) - Libemu Cython wrapper.
     464 + - [RFISandbox](https://monkey.org/~jose/software/rfi-sandbox/) - PHP 5.x script sandbox built on top of [funcall](https://pecl.php.net/package/funcall).
     465 + - [dorothy2](https://github.com/m4rco-/dorothy2) - Malware/botnet analysis framework written in Ruby.
     466 + - [imalse](https://github.com/hbhzwj/imalse) - Integrated MALware Simulator and Emulator.
     467 + - [libemu](https://github.com/buffer/libemu) - Shellcode emulation library, useful for shellcode detection.
    409 468   
    410 469  - Sandbox-as-a-Service
    411  - - [Hybrid Analysis](https://www.hybrid-analysis.com) - Free malware analysis service powered by Payload Security that detects and analyzes unknown threats using a unique Hybrid Analysis technology.
    412  - - [Joebox Cloud](https://jbxcloud.joesecurity.org/login) - Analyzes the behavior of malicious files including PEs, PDFs, DOCs, PPTs, XLSs, APKs, URLs and MachOs on Windows, Android and Mac OS X for suspicious activities.
    413  - - [VirusTotal](https://www.virustotal.com/) - Analyze suspicious files and URLs to detect types of malware, and automatically share them with the security community.
    414  - - [malwr.com](https://malwr.com/) - Free malware analysis service and community.
     470 + - [Hybrid Analysis](https://www.hybrid-analysis.com) - Free malware analysis service powered by Payload Security that detects and analyzes unknown threats using a unique Hybrid Analysis technology.
     471 + - [Joebox Cloud](https://jbxcloud.joesecurity.org/login) - Analyzes the behavior of malicious files including PEs, PDFs, DOCs, PPTs, XLSs, APKs, URLs and MachOs on Windows, Android and Mac OS X for suspicious activities.
     472 + - [VirusTotal](https://www.virustotal.com/) - Analyze suspicious files and URLs to detect types of malware, and automatically share them with the security community.
     473 + - [malwr.com](https://malwr.com/) - Free malware analysis service and community.
    415 474   
    416 475  ## Data Tools
    417 476   
    418 477  - Front Ends
    419  - - [DionaeaFR](https://github.com/rubenespadas/DionaeaFR) - Front Web to Dionaea low-interaction honeypot.
    420  - - [Django-kippo](https://github.com/jedie/django-kippo) - Django App for kippo SSH Honeypot.
    421  - - [Shockpot-Frontend](https://github.com/GovCERT-CZ/Shockpot-Frontend) - Full featured script to visualize statistics from a Shockpot honeypot.
    422  - - [Tango](https://github.com/aplura/Tango) - Honeypot Intelligence with Splunk.
    423  - - [Wordpot-Frontend](https://github.com/GovCERT-CZ/Wordpot-Frontend) - Full featured script to visualize statistics from a Wordpot honeypot.
    424  - - [honeyalarmg2](https://github.com/schmalle/honeyalarmg2) - Simplified UI for showing honeypot alarms.
    425  - - [honeypotDisplay](https://github.com/Joss-Steward/honeypotDisplay) - Flask website which displays data gathered from an SSH Honeypot.
     478 + 
     479 + - [DionaeaFR](https://github.com/rubenespadas/DionaeaFR) - Front Web to Dionaea low-interaction honeypot.
     480 + - [Django-kippo](https://github.com/jedie/django-kippo) - Django App for kippo SSH Honeypot.
     481 + - [Shockpot-Frontend](https://github.com/GovCERT-CZ/Shockpot-Frontend) - Full featured script to visualize statistics from a Shockpot honeypot.
     482 + - [Tango](https://github.com/aplura/Tango) - Honeypot Intelligence with Splunk.
     483 + - [Wordpot-Frontend](https://github.com/GovCERT-CZ/Wordpot-Frontend) - Full featured script to visualize statistics from a Wordpot honeypot.
     484 + - [honeyalarmg2](https://github.com/schmalle/honeyalarmg2) - Simplified UI for showing honeypot alarms.
     485 + - [honeypotDisplay](https://github.com/Joss-Steward/honeypotDisplay) - Flask website which displays data gathered from an SSH Honeypot.
    426 486   
    427 487  - Visualization
    428  - - [Acapulco](https://github.com/hgascon/acapulco) - Automated Attack Community Graph Construction.
    429  - - [Afterglow Cloud](https://github.com/ayrus/afterglow-cloud)
    430  - - [Afterglow](http://afterglow.sourceforge.net/)
    431  - - [Glastopf Analytics](https://github.com/katkad/Glastopf-Analytics) - Easy honeypot statistics.
    432  - - [HoneyMalt](https://github.com/SneakersInc/HoneyMalt) - Maltego tranforms for mapping Honeypot systems.
    433  - - [HoneyMap](https://github.com/fw42/honeymap) - Real-time websocket stream of GPS events on a fancy SVG world map.
    434  - - [HoneyStats](https://sourceforge.net/projects/honeystats/) - Statistical view of the recorded activity on a Honeynet.
    435  - - [HpfeedsHoneyGraph](https://github.com/yuchincheng/HpfeedsHoneyGraph) - Visualization app to visualize hpfeeds logs.
    436  - - [Kippo stats](https://github.com/mfontani/kippo-stats) - Mojolicious app to display statistics for your kippo SSH honeypot.
    437  - - [Kippo-Graph](https://bruteforcelab.com/kippo-graph) - Full featured script to visualize statistics from a Kippo SSH honeypot.
    438  - - [The Intelligent HoneyNet](https://github.com/jpyorre/IntelligentHoneyNet) - Create actionable information from honeypots.
    439  - - [ovizart](https://github.com/oguzy/ovizart) - Visual analysis for network traffic.
     488 + - [Acapulco](https://github.com/hgascon/acapulco) - Automated Attack Community Graph Construction.
     489 + - [Afterglow Cloud](https://github.com/ayrus/afterglow-cloud)
     490 + - [Afterglow](http://afterglow.sourceforge.net/)
     491 + - [Glastopf Analytics](https://github.com/katkad/Glastopf-Analytics) - Easy honeypot statistics.
     492 + - [HoneyMalt](https://github.com/SneakersInc/HoneyMalt) - Maltego tranforms for mapping Honeypot systems.
     493 + - [HoneyMap](https://github.com/fw42/honeymap) - Real-time websocket stream of GPS events on a fancy SVG world map.
     494 + - [HoneyStats](https://sourceforge.net/projects/honeystats/) - Statistical view of the recorded activity on a Honeynet.
     495 + - [HpfeedsHoneyGraph](https://github.com/yuchincheng/HpfeedsHoneyGraph) - Visualization app to visualize hpfeeds logs.
     496 + - [Kippo stats](https://github.com/mfontani/kippo-stats) - Mojolicious app to display statistics for your kippo SSH honeypot.
     497 + - [Kippo-Graph](https://bruteforcelab.com/kippo-graph) - Full featured script to visualize statistics from a Kippo SSH honeypot.
     498 + - [The Intelligent HoneyNet](https://github.com/jpyorre/IntelligentHoneyNet) - Create actionable information from honeypots.
     499 + - [ovizart](https://github.com/oguzy/ovizart) - Visual analysis for network traffic.
    440 500   
    441 501  ## Guides
    442 502   
    skipped 1 lines
    444 504  - [Honeypot (Dionaea and kippo) setup script](https://github.com/andrewmichaelsmith/honeypot-setup-script/)
    445 505   
    446 506  - Deployment
    447  - - [Dionaea and EC2 in 20 Minutes](http://andrewmichaelsmith.com/2012/03/dionaea-honeypot-on-ec2-in-20-minutes/) - Tutorial on setting up Dionaea on an EC2 instance.
    448  - - [Using a Raspberry Pi honeypot to contribute data to DShield/ISC](https://isc.sans.edu/diary/22680) - The Raspberry Pi based system will allow us to maintain one code base that will make it easier to collect rich logs beyond firewall logs.
    449  - - [honeypotpi](https://github.com/free5ty1e/honeypotpi) - Script for turning a Raspberry Pi into a HoneyPot Pi.
     507 + 
     508 + - [Dionaea and EC2 in 20 Minutes](http://andrewmichaelsmith.com/2012/03/dionaea-honeypot-on-ec2-in-20-minutes/) - Tutorial on setting up Dionaea on an EC2 instance.
     509 + - [Using a Raspberry Pi honeypot to contribute data to DShield/ISC](https://isc.sans.edu/diary/22680) - The Raspberry Pi based system will allow us to maintain one code base that will make it easier to collect rich logs beyond firewall logs.
     510 + - [honeypotpi](https://github.com/free5ty1e/honeypotpi) - Script for turning a Raspberry Pi into a HoneyPot Pi.
    450 511   
    451 512  - Research Papers
    452  - - [Honeypot research papers](https://github.com/shbhmsingh72/Honeypot-Research-Papers) - PDFs of research papers on honeypots.
    453  - - [vEYE](https://link.springer.com/article/10.1007%2Fs10115-008-0137-3) - Behavioral footprinting for self-propagating worm detection and profiling.
     513 + - [Honeypot research papers](https://github.com/shbhmsingh72/Honeypot-Research-Papers) - PDFs of research papers on honeypots.
     514 + - [vEYE](https://link.springer.com/article/10.1007%2Fs10115-008-0137-3) - Behavioral footprinting for self-propagating worm detection and profiling.
    454 515   
Please wait...
Page is in error, reload to recover