Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)
ID: 2559db9b-002a-55a1-9eea-a2ac7312144d
STIX ID: report--2559db9b-002a-55a1-9eea-a2ac7312144d
Feed Name: SANS ISC Diary
This guest diary documents activity captured by the Honeypot-Omaha DShield cowrie sensor: repeated automated credential-guessing and telnet/SSH interactions, several successful SSH sessions with commands executed (e.g., uname, BusyBox usage, file deletions), and indications of data collection; the author describes building a Python tool (batch.py) that aggregates logs, queries APIs (ip-api.com, cve.org, paloaltonetworks.com), produces TSV reports and pie-chart visualizations, and investigators' follow-up research into an ISP (PPTECHNOLOGY LIMITED) and observed indicators such as an SSH client fingerprint.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
