Sign inSign up

armedpot/ewsposter

By armedpot

•Updated about 1 year ago

collect logs and alerts from 37 honeypots and send it to backed (eg peba, geba), hpfeeds, influxdb o

Image
0

10K+

armedpot/ewsposter repository overview

⁠EWSPOSTER

EWSPoster is a tool, written in Python to, to collect logs and alers from differents honeypots (eq Glastopf v3⁠, Dionaea⁠, Honeytrap⁠, eMobility⁠, Conpot⁠, Cowrie⁠, Elasticpot⁠, Rdpy⁠, Mailoney⁠, Vnclowpot⁠, Heralding⁠, Ciscoasa⁠, Tanner⁠, Snare⁠, Glutton⁠, Honeysap⁠, Adbhoney⁠, Ipphoney⁠, Dicompot⁠, Medpot⁠, Honeypy⁠, Citrixhoneypot⁠, redishoneypot⁠, endlessh⁠), sentrypeer⁠, log4pot⁠ also network IDS (eg Suricata⁠, Fatt⁠) and transmit them to InfluxDb, JSON, Hpfeed or an Honeypot backend (eg Peba⁠ or Geba).

⁠Requirements

You need to install the libarys list in requirements.txt

pip3 install -r requirements.txt

⁠Usage

Take a look at the usage text.

./ews.py -h
usage: ews.py [-h] [-c CONFIGPATH] [-v] [-d] [-l LOOP]
          [-m {adbhoney,ciscoasa,citrix,conpot,cowrie,dicompot,dionaea,elasticpot,emobility,endlessh,
               fatt,glastopfv3,glutton,heralding,honeypy,honeysap,honeytrap,ipphoney,log4pot,mailoney,
               medpot,rdpy,redishoneypot,sentrypeer,suricata,tanner,vnclowpot,wordpot}]
          [-s] [-i] [-S] [-E] [-j JSONPATH] [-L SENDLIMIT] [-V]

optional arguments:
   -h, --help                                  show this help message and exit
   -c CONFIGPATH, --configpath CONFIGPATH      Load configuration file from Path
   -v, --verbose                               set output verbosity
   -d, --debug                                 set output debug
   -l LOOP, --loop LOOP                        endless loop. Set {xx} for seconds to wait for next loop
   -m, --modul {adbhoney, beelzebub,           only send alerts for this modul
                ciscoasa, citrix,
                conpot, cowrie,
                ddospot, dicompot,
                dionaea, elasticpot,
                emobility, endlessh,
                fatt, galah,
                glastopfv3, glutton,
                gopot, h0neytr4p,
                hellpot, heralding,
                honeyaml, honeypots,
                honeypy, honeysap,
                honeytrap, ipphoney,
                log4pot, mailoney,
                medpot, miniprint,
                rdpy, redishoneypot,
                sentrypeer, suricata,
                tanner, vnclowpot,
                wordpot
   -s, --silent                                silent mode without output
   -i, --ignorecert                            ignore certificate warnings
   -S, --sendonly                              only send unsend alerts
   -E, --ewsonly                               only generate ews alerts files
   -j JSONPATH, --jsonpath JSONPATH            write JSON output file to path
   -L SENDLIMIT, --sendlimit SENDLIMIT         set {xxx} for max alerts will send in one session
   -V, --version                               show the EWS Poster Version

⁠Configuration

Take a look at the example ews.cfg.default and copy it via

cp ews.cfg.default ews.cfg

Tag summary

Content type

Image

Digest

sha256:1e68859f6…

Size

104.5 MB

Last updated

about 1 year ago

docker pull armedpot/ewsposter