This project aims to deploy Cowrie honeypot on an internet facing server to capture attack intelligence and malware samples. The end goal is to derive our capture information into actionable intelligence that improves SSH defenses.
Completed
- Setup Cowrie on AWS EC2 instance
- Port logs to Sumo Logic
- Create Panel for captures analysis
To do
- Create YARA rules for malwares captured
- Modify Cowrie to evade nmap detection
Sumo Logic Panel