SANS Stormcast Tuesday, March 31st, 2026: Honeypot Session Lifetime; Let’s Encrypt Tests Mass Revocation; F5 RCE Exploited
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 31 March 2026
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, March 31st, 2006 edition of the Sands Internet Storm Center's Stormcast. |
| 0:12.6 | My name is Johannes Ulrich, recording today from Orlando, Florida. |
| 0:17.7 | And this episode is brought you by the Sands.edu graduate certificate program in Purple Team Operations. |
| 0:25.6 | Well, in diaries today, Jesse is asking an interesting question. |
| 0:29.6 | Well, first of all, when do Honeypot sessions disconnect? |
| 0:33.6 | First of all, a couple statistics here. |
| 0:35.6 | Most Honeypot sessions do last a very short time, a couple seconds. |
| 0:40.4 | That's no surprise because we have a lot of attackers that will just connect to a quick |
| 0:45.7 | you name or a quick check like that and then disconnect again. |
| 0:50.2 | Now, there are a couple of outliers. |
| 0:52.3 | There are a couple of sessions that last like several minutes. |
| 0:56.1 | Also, some sessions that do launch a large number of commands. |
| 1:01.3 | Now, quite often these sessions are basically just sort of using these commands to transfer |
| 1:06.4 | some kind of binary or such. |
| 1:07.9 | So they're not actually sort of distinct different commands, but really |
| 1:11.0 | just repeats of the same command and then just adding more data to a particular binary. But what I |
| 1:17.9 | find actually most interesting in Jesse's diary is what's the last command that an attacker |
| 1:24.9 | executes in the honeypot because that command sometimes gives |
| 1:29.3 | away why they're connected to a honeypot or that they're connected to a honeypot. |
| 1:34.4 | So Jesse looked at some of these commands and indeed some of these commands have distinct |
| 1:39.4 | different return values depending on whether or not they're running in a honeypot or not. |
| 1:44.7 | So, well, we'll probably have to fix up some of the responses here to keep them longer entertained in our honeypots. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

