GreedyBear
GreedyBear copied to clipboard
Create feeds for other honeypot types
GreedyBear works by extracting the data from the T-Pot logs generated by the honeypots.
As a first alpha release we just integrated log4jpot + cowrie.
We should also integrate all the other available honeypots in the T-PoT. Glutton should be the first
is I need to wait until #11 gets complete, for this issue?
no at all. no requirements here. You can take example of how I have already integrated the other honeypots as I mentioned.
However, the main problem here is to be able to connect to an active T-Pot instance so contributors can analyze the data and extract them accordingly. Without it, it is difficult to do a good integration.
I am right now trying to understand how to provide access to a T-Pot dedicated for this scope (development purposes).
Here there are all the honeypots supported by T-Pot (https://github.com/telekom-security/tpotce/tree/22.x/docker))
Okay, I will work on that.
We will provide a "staging" T-Pot for developing these integrations once a project is accepted for the GSoC.
Hi @mlodic, I faced similar integrations issues. This project is accepted in GSoC now. Can I work on this issue? It would be making it easy for others to setup and retrieve feeds from T-Pot.
PS: Please guide me with further steps
hey, thanks for your interest! We are working right now to set up that new T-Pot instance for development purposes. I'll update this issue as soon as we have results
closed with #86