GreedyBear icon indicating copy to clipboard operation
GreedyBear copied to clipboard

Create feeds for other honeypot types

Open mlodic opened this issue 3 years ago • 7 comments

GreedyBear works by extracting the data from the T-Pot logs generated by the honeypots.

As a first alpha release we just integrated log4jpot + cowrie.

We should also integrate all the other available honeypots in the T-PoT. Glutton should be the first

mlodic avatar Dec 30 '21 18:12 mlodic

is I need to wait until #11 gets complete, for this issue?

yogesh-sirsat avatar Feb 14 '22 06:02 yogesh-sirsat

no at all. no requirements here. You can take example of how I have already integrated the other honeypots as I mentioned.

However, the main problem here is to be able to connect to an active T-Pot instance so contributors can analyze the data and extract them accordingly. Without it, it is difficult to do a good integration.

I am right now trying to understand how to provide access to a T-Pot dedicated for this scope (development purposes).

mlodic avatar Feb 14 '22 10:02 mlodic

Here there are all the honeypots supported by T-Pot (https://github.com/telekom-security/tpotce/tree/22.x/docker))

mlodic avatar Feb 14 '22 11:02 mlodic

Okay, I will work on that.

yogesh-sirsat avatar Feb 14 '22 12:02 yogesh-sirsat

We will provide a "staging" T-Pot for developing these integrations once a project is accepted for the GSoC.

mlodic avatar Feb 21 '22 14:02 mlodic

Hi @mlodic, I faced similar integrations issues. This project is accepted in GSoC now. Can I work on this issue? It would be making it easy for others to setup and retrieve feeds from T-Pot.

PS: Please guide me with further steps

iharshit009 avatar Mar 12 '22 05:03 iharshit009

hey, thanks for your interest! We are working right now to set up that new T-Pot instance for development purposes. I'll update this issue as soon as we have results

mlodic avatar Mar 14 '22 10:03 mlodic

closed with #86

mlodic avatar Dec 07 '22 14:12 mlodic