HoneyDB Logo

HoneyDB

0
Free
Visit Website

HoneyDB is a honeypot-based threat intelligence platform that provides real-time insights into attacker behavior, allowing users to monitor and analyze malicious activity on their networks. The platform offers a range of features, including threat API access, network monitoring, and agent deployment, to help organizations improve their threat detection and response capabilities. With HoneyDB, users can gain visibility into attacker tactics, techniques, and procedures (TTPs), and leverage this information to enhance their security posture. The platform's threat intelligence feeds can be integrated with existing security tools, enabling more effective incident response and threat hunting. HoneyDB's user-friendly interface provides easy access to threat data, including IP addresses, protocols, and service information, making it easier for security teams to identify and respond to threats in real-time.

FEATURES

ALTERNATIVES

Tool for visualizing correspondences between YARA ruleset and samples

A tool for navigating and annotating ATT&CK matrices with the ability to define custom layers for specific views.

Utilize Jupyter Notebooks to enhance threat hunting capabilities by focusing on different threat categories or stages.

ZoomEye is an advanced cyberspace search engine that provides detailed information on cyberspace assets, including server software and version information, for cybersecurity experts, researchers, and enterprises.

A set of configuration files to use with EclecticIQ's OpenTAXII implementation for MISP integration.

A tool to extract indicators of compromise from security reports in PDF format.

A tool for quick and effective Yara rule creation to isolate malware families and malicious objects.

CIFv3 is the next version of the Cyber Intelligence Framework, developed against Ubuntu16, encouraging users to transition from CIFv2.