
SSHintel
Self-contained SSH honeypot for capturing attacker interactions and turning them into structured security intelligence.

Self-contained SSH honeypot for capturing attacker interactions and turning them into structured security intelligence.

Fingerprint SSH clients and servers.

Create Basic SSH Honeypot With Python

An ssh honeypot with the XZ backdoor. CVE-2024-3094

Advisory and analysis repository for CVE-2024-3094, detailing a critical backdoor in Linux SSH library with mitigation steps for servers and Android…

Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.

Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…

Custom YARA rule for detecting artifacts of CVE-2025-32433, an Erlang/OTP SSH pre-authentication RCE vulnerability. Validated against public PoCs and…

Multi-host UFW firewall dashboard — explains rules in plain English, detects security gaps, and provides connection diagnostics

PEAK Baseline Threat Hunt dashboards for Security Onion 3.0 — covering DNS, HTTP, TLS, SMB, Kerberos, SSH, RDP, DCE/RPC, LDAP, Modbus, DNP3,…

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

HASSH fingerprints for identifying OpenSSH servers potentially vulnerable to CVE-2024-6387 (regreSSHion).

Experimental Decoy Broker

A high interaction SSH honeypot

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/


FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic