YALIH YALIH Logo

YALIH YALIH

0
Free
Visit Website

YALIH YALIH (Yet Another Low Interaction Honeyclient) is a low Interaction Client honeypot designed to detect malicious websites through signature, anomaly and pattern matching techniques. * Suspecious URL collection from malicious website databases (three databases) * URL collection through Bing API * Suspecious URL collection from your inbox and SPAM folder through pop3 and IMAP protocol * Javascript extraction, de-obfuscation and de-minification of scripts embedded within a website * Referrer Emulation and redirection handling * Cookies and session handling * Browser and browser agent and OS emulation * Proxy capabilities to detect Geo-location and/or IP cloacking attacks * Signature detection using ClamAV antivirus database * Anomaly and pattern matching detection through Yara (http://plusvic.github.io/yara/) * Automated Yara signature generation =================================== Easy Installation and documentation ==================================== Authors/Contributors: * Victoria University of Wellington * Masood Mansoori - masood.mansoori@gmail.com * Singapore Polytechnic * Lai Qi Wei - laiqiwei30@hotmail.com

FEATURES

ALTERNATIVES

A low-interaction honeypot that simulates network services to detect and monitor potential intrusion attempts on internal networks.

A Go-based honeypot server for detecting and logging attacker activity

A honeypot tool to mimic the router backdoor 'TCP32764' found in various router firmwares, providing a way to test for vulnerabilities.

Uploader honeypot designed to look like poor website security.

A full featured script to visualize statistics from a Shockpot honeypot, based on Kippo-Graph and utilizing various PHP libraries.

An extensible and open-source system for running, monitoring, and managing honeypots with advanced features.

An active and aggressive honeypot tool for network security.

A honeypot for the Log4Shell vulnerability (CVE-2021-44228) with various detection and logging features.

PINNED