logo

GoSpoof – Turning Attacks into Intel 

ID: db289a8c-29d2-59b8-818d-d38860da70e1

STIX ID: report--db289a8c-29d2-59b8-818d-d38860da70e1

Feed Name: Black Hills Infosec Blog

Date Published: 2025-10-29

Date Updated: 2026-04-27

Author: BHIS

...
...

GoSpoof is a modernized, Go-based deception tool (forked from Portspoof) that emulates open services to confuse and collect intelligence on attackers. It supports honeypot logging, a persistence mode to run as a systemd service, a "RubberGlue" feature to tunnel connections back to attackers, and includes a web "Command Center" UI that aggregates attackers and payloads for SOC analysis, turning noisy attacks into actionable defender intelligence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.