Analysis using Gephi with DShield Sensor Data, (Wed, Jan 7th)
ID: 8e02055a-d82e-56bc-a975-412a7e3f46b3
STIX ID: report--8e02055a-d82e-56bc-a975-412a7e3f46b3
Feed Name: SANS ISC Diary
Threat Score
The author analyzed 30 days of Cowrie honeypot logs exported via Kibana ES|QL and visualized relationships with Gephi/Graphviz to identify clusters of file-based malware activity. The analysis highlights two groupings (one identified as redtail), shows which sensors saw which files, and provides IoCs: four IP addresses and multiple SHA‑256 file hashes observed during the period.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
