Honeycomb Logo

Honeycomb

0
Free
Visit Website

Honeycomb is a system for automated generation of signatures for network intrusion detection systems (NIDSs) by applying protocol analysis and pattern-detection techniques to traffic captured on honeypots. It is particularly effective at spotting worms and can create detailed signatures for known threats like Slammer and Code Red. The system can be used to actively search for signatures in any kind of traffic and has potential applications in spam detection.

FEATURES

ALTERNATIVES

A tool for exploiting HTTP/2 cleartext smuggling vulnerabilities

TCPFLOW is a tool for capturing data transmitted over TCP connections.

An HTTP proxy, monitor, and reverse proxy tool for viewing HTTP and SSL/HTTPS traffic.

Netcap efficiently converts network packets into structured audit records for machine learning algorithms, using Protocol Buffers for encoding.

A private network system utilizing WireGuard for enhanced networking capabilities.

Fast, smart, effective port scanner with extensive extendability and adaptive learning.

Passive SSL client fingerprinting tool using handshake analysis.

A collection of PCAPs for ICS/SCADA utilities and protocols with the option for users to contribute.

PINNED