
🍯 T-Pot - 올인원 멀티 허니팟 플랫폼 🐝

T-Pot은 올인원, 선택적으로 분산 가능한, 멀티아키텍처(amd64, arm64) 허니팟 플랫폼으로, 20개 이상의 허니팟과 Elastic Stack을 사용한 수많은 시각화 옵션, 애니메이션 실시간 공격 지도, 그리고 사기 경험을 더욱 향상시키는 다양한 보안 도구를 지원합니다.
ssh 필요)curl 설치: $ sudo [apt, dnf, zypper] install curl (아직 설치되지 않은 경우)$HOME에서 루트가 아닌 사용자로 설치 프로그램 실행:```
env bash -c "$(curl -sL https://github.com/telekom-security/tpotce/raw/master/install.sh)"* 지침을 따르고, 메시지를 읽고, 가능한 포트 충돌을 확인한 후 재부팅하세요.
<!-- TOC -->
- [T-Pot - 올인원 멀티 허니팟 플랫폼](#t-pot---the-all-in-one-multi-honeypot-platform)
- [TL;DR](#tldr)
- [면책 조항](#disclaimer)
- [기술 개념](#technical-concept)
- [허니팟 및 도구](#honeypots-and-tools)
- [기술 아키텍처](#technical-architecture)
- [서비스](#services)
- [사용자 유형](#user-types)
- [시스템 요구 사항](#system-requirements)
- [VM에서 실행](#running-in-a-vm)
- [하드웨어에서 실행](#running-on-hardware)
- [클라우드에서 실행](#running-in-a-cloud)
- [필요한 포트](#required-ports)
- [LLM 기반 허니팟](#llm-based-honeypots)
- [Ollama](#ollama)
- [ChatGPT](#chatgpt)
- [시스템 배치](#system-placement)
- [설치](#installation)
- [배포판 선택](#choose-your-distro)
- [Raspberry Pi 4 (8GB) 지원](#raspberry-pi-4-8gb-support)
- [T-Pot 다운로드 및 설치](#get-and-install-t-pot)
- [macOS 및 Windows](#macos--windows)
- [Red Hat Enterprise Linux](#red-hat-enterprise-linux)
- [설치 유형](#installation-types)
- [표준 / 하이브](#standard--hive)
- [분산](#distributed)
- [T-Pot 제거](#uninstall-t-pot)
- [첫 시작](#first-start)
- [독립형 첫 시작](#standalone-first-start)
- [분산 배포](#distributed-deployment)
- [계획 및 인증서](#planning-and-certificates)
- [센서 배포](#deploying-sensors)
- [센서 제거](#removing-sensors)
- [커뮤니티 데이터 제출](#community-data-submission)
- [옵트인 HPFEEDS 데이터 제출](#opt-in-hpfeeds-data-submission)
- [원격 액세스 및 도구](#remote-access-and-tools)
- [SSH](#ssh)
- [T-Pot 랜딩 페이지](#t-pot-landing-page)
- [Kibana 대시보드](#kibana-dashboard)
- [공격 지도](#attack-map)
- [Cyberchef](#cyberchef)
- [Elasticvue](#elasticvue)
- [Spiderfoot](#spiderfoot)
- [구성](#configuration)
- [T-Pot 구성 파일](#t-pot-config-file)
- [T-Pot 허니팟 및 서비스 사용자 정의](#customize-t-pot-honeypots-and-services)
- [유지 관리](#maintenance)
- [일반 업데이트](#general-updates)
- [업데이트 스크립트](#update-script)
- [일일 재부팅](#daily-reboot)
- [알려진 문제](#known-issues)
- [Docker 이미지 다운로드 실패](#docker-images-fail-to-download)
- [T-Pot 네트워킹 실패](#t-pot-networking-fails)
- [T-Pot 시작](#start-t-pot)
- [T-Pot 중지](#stop-t-pot)
- [T-Pot 데이터 폴더](#t-pot-data-folder)
- [로그 지속성](#log-persistence)
- [공장 초기화](#factory-reset)
- [컨테이너 및 이미지 표시](#show-containers-and-images)
- [Blackhole](#blackhole)
- [Nginx (T-Pot 웹 UI)에 사용자 추가](#add-users-to-nginx-t-pot-webui)
- [Kibana 객체 가져오기 및 내보내기](#import-and-export-kibana-objects)
- [내보내기](#export)
- [가져오기](#import)
- [문제 해결](#troubleshooting)
- [로그](#logs)
- [RAM 및 저장소](#ram-and-storage)
- [연락처](#contact)
- [이슈](#issues)
- [토론](#discussions)
- [라이선스](#licenses)
- [크레딧](#credits)
- [다음의 개발자 및 개발 커뮤니티](#the-developers-and-development-communities-of)
- [**다음 회사 및 조직**](#the-following-companies-and-organizations)
- [**그리고 물론 커뮤니티에 참여해 주신 ***여러분***!**](#and-of-course-you-for-joining-the-community)
- [사용 후기](#testimonials)
- [감사합니다 💖](#thank-you-)
<!-- TOC -->
<br><br>
# 면책 조항
- T-Pot을 설치하고 실행하는 것은 당신의 책임입니다. 시스템 손상 가능성을 완전히 배제할 수 없으므로 신중하게 배포 방식을 선택하세요.
- 빠른 도움을 위해 [Issues](https://github.com/telekom-security/tpotce/issues) 및 [Discussions](https://github.com/telekom-security/tpotce/discussions)를 참조하세요.
- 이 소프트웨어는 최선의 노력을 다해 설계 및 제공됩니다. 커뮤니티 및 오픈 소스 프로젝트로서 많은 다른 오픈 소스 소프트웨어를 사용하며 버그나 문제가 있을 수 있습니다. 책임감 있게 보고해 주세요.
- 허니팟은 설계상 민감한 데이터를 호스팅해서는 안 됩니다. 어떤 것도 추가하지 않도록 하세요.
- 기본적으로 데이터는 [Sicherheitstacho](https://www.sicherheitstacho.eu/start/main)로 전송됩니다. 구성 파일(`~/tpotce/docker-compose.yml`)에서 [제거](#community-data-submission)하여 `ewsposter` 섹션을 비활성화할 수 있습니다. 하지만 이 경우 공유가 정말 중요합니다!
<br><br>
# 기술 개념
T-Pot의 주요 구성 요소가 `tpotinit` Docker 이미지로 이동되어, 이제 T-Pot은 여러 Linux 배포판은 물론 macOS 및 Windows(단, 모두 Docker Desktop의 기능 세트로 제한됨)를 지원합니다. T-Pot은 [docker](https://www.docker.com/) 및 [docker compose](https://docs.docker.com/compose/)를 사용하여 가능한 한 많은 허니팟과 도구를 동시에 실행하고 호스트 하드웨어를 최대한 활용하는 것을 목표로 합니다.
<br><br>
## 허니팟 및 도구
- T-Pot은 다음 허니팟용 Docker 이미지를 제공합니다:<br>
[adbhoney](https://github.com/huuck/ADBHoney),
[beelzebub](https://github.com/beelzebub-labs/beelzebub),
[ciscoasa](https://github.com/Cymmetria/ciscoasa_honeypot),
[citrixhoneypot](https://github.com/MalwareTech/CitrixHoneypot),
[conpot](http://conpot.org/),
[cowrie](https://github.com/cowrie/cowrie),
[ddospot](https://github.com/aelth/ddospot),
[dicompot](https://github.com/nsmfoo/dicompot),
[dionaea](https://github.com/DinoTools/dionaea),
[elasticpot](https://gitlab.com/bontchev/elasticpot),
[endlessh](https://github.com/skeeto/endlessh),
[galah](https://github.com/0x4D31/galah),
[go-pot](https://github.com/ryanolee/go-pot),
[glutton](https://github.com/mushorg/glutton),
[h0neytr4p](https://github.com/pbssubhash/h0neytr4p),
[hellpot](https://github.com/yunginnanet/HellPot),
[heralding](https://github.com/johnnykv/heralding),
[honeyaml](https://github.com/mmta/honeyaml),
[honeypots](https://github.com/qeeqbox/honeypots),
[honeytrap](https://github.com/armedpot/honeytrap/),
[ipphoney](https://gitlab.com/bontchev/ipphoney),
[log4pot](https://github.com/thomaspatzke/Log4Pot),
[mailoney](https://github.com/phin3has/mailoney),
[medpot](https://github.com/schmalle/medpot),
[miniprint](https://github.com/sa7mon/miniprint),
[redishoneypot](https://github.com/cypwnpwnsocute/RedisHoneyPot),
[rdphoneypot](https://gitlab.com/bontchev/rdphoneypot),
[sentrypeer](https://github.com/SentryPeer/SentryPeer),
[snare](http://mushmush.org/),
[tanner](http://mushmush.org/),
[wordpot](https://github.com/gbrindisi/wordpot)
다음 도구와 함께:
* [Autoheal](https://github.com/willfarrell/docker-autoheal) 상태 점검에 실패한 컨테이너를 자동으로 다시 시작하는 도구입니다.
* [Cyberchef](https://gchq.github.io/CyberChef/) 암호화, 인코딩, 압축 및 데이터 분석을 위한 웹 앱입니다.
* [Elastic Stack](https://www.elastic.co/videos) T-Pot이 수집한 모든 이벤트를 아름답게 시각화합니다.
* [Elasticvue](https://github.com/cars10/elasticvue/) Elasticsearch 클러스터를 탐색하고 상호 작용하기 위한 웹 프론트엔드입니다.
* [Fatt](https://github.com/0x4D31/fatt) pcap 파일 및 실시간 네트워크 트래픽에서 네트워크 메타데이터 및 지문을 추출하는 pyshark 기반 스크립트입니다.
* [T-Pot-Attack-Map](https://github.com/telekom-security/t-pot-attack-map) T-Pot을 위한 아름답게 애니메이션 처리된 공격 지도입니다.
* [P0f](https://lcamtuf.coredump.cx/p0f3/) 순수 수동 트래픽 지문 추출을 위한 도구입니다.
* [Spiderfoot](https://github.com/smicallef/spiderfoot) 오픈 소스 인텔리전스 자동화 도구입니다.
* [Suricata](https://suricata.io/) 네트워크 보안 모니터링 엔진입니다.
... 최상의 즉시 사용 가능한 경험과 사용하기 쉬운 멀티 허니팟 시스템을 제공합니다.
<br><br>
## 기술 아키텍처

소스 코드 및 구성 파일은 T-Pot GitHub 저장소에 완전히 저장됩니다. Docker 이미지는 T-Pot 환경에 맞게 빌드 및 사전 구성됩니다.
개별 Dockerfile 및 구성은 [docker 폴더](https://github.com/telekom-security/tpotce/tree/master/docker)에 있습니다.
<br><br>