YALIH YALIH Logo

YALIH YALIH

0
Free
Visit Website

YALIH YALIH (Yet Another Low Interaction Honeyclient) is a low Interaction Client honeypot designed to detect malicious websites through signature, anomaly and pattern matching techniques. * Suspecious URL collection from malicious website databases (three databases) * URL collection through Bing API * Suspecious URL collection from your inbox and SPAM folder through pop3 and IMAP protocol * Javascript extraction, de-obfuscation and de-minification of scripts embedded within a website * Referrer Emulation and redirection handling * Cookies and session handling * Browser and browser agent and OS emulation * Proxy capabilities to detect Geo-location and/or IP cloacking attacks * Signature detection using ClamAV antivirus database * Anomaly and pattern matching detection through Yara (http://plusvic.github.io/yara/) * Automated Yara signature generation =================================== Easy Installation and documentation ==================================== Authors/Contributors: * Victoria University of Wellington * Masood Mansoori - masood.mansoori@gmail.com * Singapore Polytechnic * Lai Qi Wei - laiqiwei30@hotmail.com

FEATURES

ALTERNATIVES

GHH is a honeypot tool to defend against search engine hackers using Google as a hacking tool.

A tool for generating permutations, alterations and mutations of subdomains and resolving them

A low interaction honeypot for detecting CVE-2018-0101 vulnerability in Cisco ASA component.

A web honeypot tool for detecting and monitoring potential attacks on phpMyAdmin installations.

A DICOM server with a twist, blocking C-STORE attempts for protection but logging them.

Honeypot platform for tracking and monitoring UDP-based DDoS attacks with support for various honeypot services.

A honeypot tool that simulates an open relay to capture and analyze spam

A Perl honeypot program for monitoring hostile traffic and wasting hackers' time.