Log4Pot Logo

Log4Pot

0
Free
Visit Website

A honeypot designed to detect and capture exploitation attempts of the Log4Shell vulnerability (CVE-2021-44228). It listens on various ports for Log4Shell exploitation, detects exploitation in request lines and headers, downloads exploit payloads recursively, and offers logging to both file and Azure blob storage. To use, install Poetry, clone the GitHub repository, install dependencies, configure parameters in log4pot.conf, and run the tool. It can also be run without external dependencies for basic functionality. For redirecting traffic to Log4Pot, iptables commands can be used.

FEATURES

ALTERNATIVES

RDP based Honeypot that creates virtual machines for incoming connections and analyzes traffic with Suricata.

SMTP Honeypot with custom modules for different modes of operation.

High-interaction SSH honeypot for logging SSH proxy with ongoing development.

Ansible role for deploying and managing Bifrozt honeypots

A honeypot mimicking Tomcat manager endpoints to log requests and save attacker's WAR files for analysis.

A full featured script to visualize statistics from a Shockpot honeypot, based on Kippo-Graph and utilizing various PHP libraries.

ElasticSearch honeypot to capture attempts to exploit CVE-2014-3120, with logging and daemon options.

A low Interaction Client honeypot designed to detect malicious websites through signature, anomaly and pattern matching techniques.