Binary Breadcrumbs: Correlating Malware Samples with Honeypot Logs Using PowerShell [Guest Diary], (Wed, Nov 5th)
ID: a5c0ff71-ecb6-5c79-9d0c-4115575d4f85
STIX ID: report--a5c0ff71-ecb6-5c79-9d0c-4115575d4f85
Feed Name: SANS ISC Diary
A SANS ISC guest diary describes a practical method for reviewing Cowrie honeypot JSON logs on a restricted Windows laptop using PowerShell. It walks through a compact script that builds an array of malware hashes, recursively reads log files, and leverages Select-String and nested loops to locate matches, illustrating core techniques for traversing files, retrieving and searching text, and quickly extracting useful signals without installing additional tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
