Acapulco (Attack Community grAPh COnstruction) Logo

Acapulco (Attack Community grAPh COnstruction)

A Splunk application that processes honeypot data from hpfeeds channels to generate clustered meta-events and visualizations for security analysis.

10
Security Operations
Free
Visit website
0

Acapulco (Attack Community grAPh COnstruction) Description

Acapulco (Attack Community grAPh COnstruction) is a Splunk application developed by The Honeynet Project that processes honeypot data from hpfeeds channels to generate meta-events for security analysis. The application automatically collects data from multiple hpfeeds channels and creates clustered meta-events using DBSCAN or K-means algorithms. These processed events are then visualized through parallel coordinates graphs built with the D3.js visualization library, providing an external client interface for data analysis. The tool includes a runner.py script that processes hpfeeds log files to create two types of meta-event files: one containing plain features and another with clustered feature values. This clustering approach helps identify patterns and relationships within honeypot data. Installation involves deploying the Splunk application bundle to a central server by extracting it to the splunk/etc/apps directory. Once configured with hpfeeds integration, the application can process honeypot logs and generate the visualization data for security analysis purposes. The software is distributed under the GNU GPL license and is designed to provide insights for cybersecurity professionals analyzing attack patterns and honeypot interactions.

FEATURED

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Stay Updated with Mandos Brief

Get the latest cybersecurity updates in your inbox

POPULAR

RoboShadow Logo

Automated vulnerability assessment and remediation platform

11
TestSavantAI Logo

Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.

6
Cybersec Feeds Logo

A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.

5
Fabric Platform by BlackStork Logo

Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.

5
Mandos Brief Newsletter Logo

A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

5
View Popular Tools →