Spot trouble early with honeypots and Suricata
ID: 909b9e2d-bbb3-57ba-b722-66a20f572f09
STIX ID: report--909b9e2d-bbb3-57ba-b722-66a20f572f09
Feed Name: Pen Test Partners Blog
A practitioner deployed a T-Pot honeypot with Suricata in a DMZ for three days, ingesting 1.4M alerts via the Elastic stack and observing widespread automated scanning—frequently from cloud IP ranges—and rapid probing for recent and older CVEs (e.g., CVE-2024-6387, CVE-2020-11910) without clear attribution. The report outlines the containerized honeypot services, Suricata rule management, common targets (e.g., 443, 53), and odd payloads, then distills blue-team lessons: focus honeypot scope, enrich telemetry with ASN/cloud tags, tune rules to reduce noise, and integrate outputs into detection, blocklists, and analyst training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
