Automated Tools to Assist with DShield Honeypot Investigations [Guest Diary], (Wed, Jun 11th)
ID: f1b8a889-8f79-591a-8ac6-290d2111dc33
STIX ID: report--f1b8a889-8f79-591a-8ac6-290d2111dc33
Feed Name: SANS ISC Diary
A SANS ISC intern describes two Python tools built to process large JSON web logs from a DShield honeypot: one for broad summary reporting (top/bottom IPs, URLs, user-agents, response codes, credential attempts, detected hashes) and a second for detailed per-IP analysis. The tools were used on a 3.5GB log (2025-05-31) to identify suspicious file requests, credential guessing, and an IP generating requests resembling exploitation of CVE-2021-20016 against SonicWall; the diary includes example outputs and links to the code repositories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
