isc.sans.edu 9/3/2026, 3:48:48 AM · external

Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)

Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)
CyberSIXT Evidence Panel
Primary Source github.com

THE diary by Frank Igbokwe discusses the Honeypot-Omaha DShield Sensor, a decoy system designed to attract threat actors. It highlights the use of a tool called 'cowrie' that captures malicious activities on exposed ports. Igbokwe outlines the automation of cyber attacks, including password brute-forcing, and describes his development of a Python script named 'batch.py' to analyze data collected from these interactions.

The script processes log files, consolidates relevant data, and creates visual summaries of threat actor activities. It includes an analysis pipeline with various phases, resulting in detailed reports on detected threats and insights into potential vulnerabilities. The research reflects on understanding threat actors' methods and the importance of security measurements in monitoring and response.

View Primary Source Via isc.sans.edu

Article by CyberSIXT