SSHoney Logo

SSHoney

0
Free
Visit Website

SSHoney is an SSH honeypot designed to log SSH connection attempts on a given port. It listens on a non-privileged port (default 2222), pretends to be an SSH server, and logs connection details like IP, username, password, and SSH client version to stdout, syslog, or a specified log file. Basic setup involves installing the source and binary, ensuring the binary path is in the system path, and generating a host key.

FEATURES

ALTERNATIVES

A honeypot system that detects and identifies attack commands, recon attempts, and download commands, mimicking a vulnerable Elasticsearch instance.

A honeypot installation for Drupal that supports Go modules and mimics different versions of Drupal.

A high-interaction honeypot solution for detecting and analyzing SMB-based attacks

A low interaction honeypot to detect CVE-2018-2636 in Oracle Hospitality Applications.

RDP based Honeypot that creates virtual machines for incoming connections and analyzes traffic with Suricata.

A honeypot tool to detect and log CVE-2019-19781 scan and exploitation attempts.

An open source honeypot for NoSQL databases with support for Redis and additional features for detecting attackers and logging attack incidents.

An automation framework for subdomain bruteforcing

PINNED