
cowrie
Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Self-contained SSH honeypot for capturing attacker interactions and turning them into structured security intelligence.

Custom YARA rule for detecting artifacts of CVE-2025-32433, an Erlang/OTP SSH pre-authentication RCE vulnerability. Validated against public PoCs and…

Experimental Decoy Broker

Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…

Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.

PEAK Baseline Threat Hunt dashboards for Security Onion 3.0 — covering DNS, HTTP, TLS, SMB, Kerberos, SSH, RDP, DCE/RPC, LDAP, Modbus, DNP3,…

Medium-interaction SSH honeypot deployment capturing real-world brute-force traffic, malware drops, and attacker behavior. Includes TTY session…

Multi-host UFW firewall dashboard — explains rules in plain English, detects security gaps, and provides connection diagnostics

Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

HASSH fingerprints for identifying OpenSSH servers potentially vulnerable to CVE-2024-6387 (regreSSHion).

Fingerprint SSH clients and servers.

An ssh honeypot with the XZ backdoor. CVE-2024-3094

Advisory and analysis repository for CVE-2024-3094, detailing a critical backdoor in Linux SSH library with mitigation steps for servers and Android…


19 Customizable honeypots for monitoring network traffic, bots activities and username\password credentials (DNS, HTTP Proxy, HTTP, HTTPS, SSH, POP3,…