TGViewer
📜 Чтиво 📜 📜 Чтиво 📜 @chtivvvo · 137 subscribers
Post #1453 177
What did I say to make you stop talking to me?

[...] Attackers are interested in attempting to detect honeypots; over the years, we have seen various ways to do so. But so far, we have not done much to prevent this. We randomize some fo the parameters, but overall, we just run a "stock" cowrie install. There is however a relatively easy method to find out what gave the honeypot away after the attacker connected.

Most attackers will immediately disconnect after they realize they have found a honeypot. So as a simple method, you just find out what the last command was an attacker executed. I just did this for some of our larger honeypots, investigating about 10 million cowrie sessions. [...]
  • 👍 2
More from @chtivvvo
  1. Dec 3, 2024Novel phishing campaign uses corrupted Word documents to evade security A novel phishing a…
  2. Nov 18, 2024Phishing emails increasingly use SVG attachments to evade detection Threat actors increasi…
  3. Nov 3, 2024https://arstechnica.com/information-technology/2024/11/microsoft-warns-of-8000-strong-botn…
  4. Oct 31, 2024https://sharpsec.run/rce-vulnerability-in-qbittorrent/
  5. Oct 11, 2024https://securelist.com/miner-campaign-misuses-open-source-siem-agent/114022/
  6. Oct 9, 2024https://www.bleepingcomputer.com/news/security/european-govt-air-gapped-systems-breached-u…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →