Very simple but effective docker deployed honeypot to detect port scanning in your environment. Configure ports to be exposed Edit or add ports within the brackets on line 14 of honey_ports.sh for p in {80,3306}; do Also expose corresponding ports in line 17 of dockerfile EXPOSE 80 3306 Build container image docker build -t honey_ports . Run honey_ports container sudo docker run -d -v /var/log:/logs_out honey_ports By default logs of attempted connections will be written to "hp_connections.log" which is stored on a mounted volume on the host.
FEATURES
SIMILAR TOOLS
Libnids is an implementation of an E-component of Network Intrusion Detection System that emulates the IP stack of Linux 2.0.x and offers IP defragmentation, TCP stream assembly, and TCP port scan detection.
A technique to associate applications with TLS parameters for identifying malware and vulnerable applications.
A TCP-based traceroute implementation that bypasses firewall filters to trace the path to a destination.
A powerful and extensible framework for reconnaissance and attacking various networks and devices.
A tool for classifying packets into flows based on 4-tuple without additional processing.
Tcpdump is a command-line packet analyzer for capturing and analyzing network traffic.
A fast and flexible web fuzzer for identifying vulnerabilities in web applications
A low-interaction honeypot for detecting and analyzing potential attacks on Android devices via ADB over TCP/IP
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.