SplunkDashboards
how-to-setup-a-honeypot
Our great sponsors
SplunkDashboards | how-to-setup-a-honeypot | |
---|---|---|
1 | 6 | |
49 | 139 | |
- | - | |
0.0 | 0.0 | |
over 3 years ago | almost 2 years ago | |
- | - |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
SplunkDashboards
-
Looking for Splunk dashboards
I've been trying to find some dashboards for threathunting and ive only managed to find these 2 sources: https://github.com/Truvis/SplunkDashboards and https://gosplunk.com/category/splunk-dashboards/ i was wondering if anyone knew of some other good places for threat hunting dashes?
how-to-setup-a-honeypot
-
How do I ensure safety when making a honeypot?
To start off, I intend to follow this really detailed rundown of how to create and secure my own honeypot https://github.com/Nirusu/how-to-setup-a-honeypot. Something I continue to worry about is how do I guarantee the threat actors I catch snooping aren't able to pivot or move laterally? Another concern I have is making sure whatever malicious actors go through my router, aren't able to infect anything. Is that just the extra risk you take in doing this?
- How to setup a honeypot with an IDS, ELK and TLS traffic inspection
What are some alternatives?
MISP - MISP (core software) - Open Source Threat Intelligence and Sharing Platform
elk-pi - Elk Audio OS binary images for Raspberry Pi
Spring4Shell-Detection - Lazy SPL to detect Spring4Shell exploitation
elkpi-sdk - Yocto cross-compiling toolchains for Elk on Raspberry Pi 3 32 bit
slack-alerts - Splunk custom alert action for sending messages to Slack channels
malware-samples - A collection of malware samples caught by several honeypots i manage
SysmonTools - Utilities for Sysmon
tpotce - 🍯 T-Pot - The All In One Honeypot Platform 🐝 [Moved to: https://github.com/telekom-security/tpotce]
QSimpleScada - Qt based simple SCADA framework, with dashboard, static and dynamic components
tpotce - 🍯 T-Pot - The All In One Honeypot Platform 🐝
TA-UserWatchlist - User Watchlist App for Splunk
soar-notable-automation-tracker - 📈 track & quantify the value gained through Splunk ES Notable automation