ISC StormCast for Monday, February 5th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 5 February 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, February 5th, 2020, edition of the Sansenet Storms |
| 0:06.6 | Thunder's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, |
| 0:12.0 | Florida. One of the questions that often comes up with our honeypot is if it's possible to gain |
| 0:19.7 | more insight into attacks hitting your individual |
| 0:23.3 | honeypot. Now, some of this can be done by just looking at your account in the shield.org or |
| 0:30.5 | the internet storm center. However, the information there is, of course, limited to information |
| 0:36.4 | that you submitted to us and that's |
| 0:40.4 | just sort of the basics of the attacks. On the other hand, the logs on the honey pot itself, |
| 0:47.4 | while they have a lot more details, they're often not that sort of easy accessible in particular |
| 0:53.2 | to people new to this field. |
| 0:56.8 | So Guy took it upon himself and did a real great job in figuring out how to build a little bit |
| 1:04.9 | of a dashboard that shows what's going on in your honeypot. |
| 1:14.6 | Now, this just got a lot easier now thanks to a Ghee-Hoo built a dashboard for the honeypot |
| 1:18.6 | using the ElkStack, Elasticsearch, Logstash, and Kibbana. |
| 1:23.6 | Great Kibbana dashboard here. |
| 1:25.6 | What I like in particular is the TTI logs, which is basically all the commands that attackers attempted to execute in the cowrie part of the honeypot. |
| 1:38.0 | This particular setup is made available as a Docker container. It can run on some of the better equipped Raspberry Pies, but definitely if you're running |
| 1:50.7 | your honeypot in a virtual machine or such, but you have a little bit more resources, it |
| 1:55.3 | shouldn't be all that difficult to run this dashboard. |
| 2:00.2 | Any feedback, as always, is very much appreciated. |
| 2:03.6 | Any data items or such that you may want to add, |
| 2:08.1 | or so to this setup or any bugs that you're running into. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

