Th3miggy/Building-a-Cowrie-SSH-Honeypot-with-Wazuh-intergation

GitHub: Th3miggy/Building-a-Cowrie-SSH-Honeypot-with-Wazuh-intergation

该项目通过在 Ubuntu 上部署 Cowrie SSH 蜜罐并与 Wazuh 集成,构建了一个用于实时检测和分析暴力破解攻击的安全实验环境。

Stars: 0 | Forks: 0

# 搭建具有 Wazuh 集成功能的 Cowrie SSH 蜜罐 在这个项目中,我们将启动一台 Ubuntu 服务器虚拟机,并在该服务器上构建一个 Cowrie SSH 蜜罐,然后我们将把该服务器连接到我们预先存在的 Wazuh manager 中,并在威胁狩猎中实时捕获暴力破解攻击。 PROJECTNAME 目标 [简要目标 - 完成后删除此项] The Detection Lab 项目旨在建立一个受控环境,用于模拟和检测网络攻击。主要重点是在安全信息和事件管理 (SIEM) 系统中摄取和分析日志,生成测试遥测数据以模拟真实世界的攻击场景。这种实践经验旨在加深对网络安全、攻击模式和防御策略的理解。 掌握的技能 [要点列表 - 完成后删除此项] ``` Advanced understanding of SIEM concepts and practical application. Proficiency in analyzing and interpreting network logs. Ability to generate and recognize attack signatures and patterns. Enhanced knowledge of network protocols and security vulnerabilities. Development of critical thinking and problem-solving skills in cybersecurity. ``` 使用的工具 [要点列表 - 完成后删除此项] ``` Security Information and Event Management (SIEM) system for log ingestion and analysis. Network analysis tools (such as Wireshark) for capturing and examining network traffic. Telemetry generation tools to create realistic network traffic and attack scenarios. ``` 步骤 将屏幕截图拖放到此处,或使用 imgur 并通过 imgsrc 引用它们。 每张屏幕截图都应配有一些文字,说明该屏幕截图的内容。 以下是示例。 参考 1:网络拓扑图
标签:Wazuh, 子域枚举, 红队行动, 网络安全, 蜜罐, 证书利用, 隐私保护