Sign inSign up

jnltedev/avatoris_sshpot-reporter

By jnltedev

•Updated about 2 months ago

Image
0

564

jnltedev/avatoris_sshpot-reporter repository overview

Reports failed SSH login attempts to the Avatoris threat intelligence API. Passwords are never transmitted.

This image is one half of avatoris/sshpot⁠. It watches the JSON log of a Cowrie⁠ honeypot and, optionally, the real host's sshd authentication log, then reports the source IPs to Avatoris⁠.

⁠Usage

The reporter is not meant to run on its own. Use the compose stack, which starts it together with the honeypot:

curl -O https://raw.githubusercontent.com/avatoris/sshpot/main/docker-compose.yml
AVATORIS_API_KEY=your-key docker compose up -d

Get a free API key at https://avatoris.com/login⁠.

⁠How reporting works

The first failed attempt from an IP is reported immediately. Avatoris accepts at most one report per target IP every 30 minutes, so further attempts inside that window are counted locally in SQLite and sent afterwards as a single aggregated follow-up. This keeps the attack telemetry without wasting API calls.

Only metadata is reported: source IP, timestamp, category, attempt count and the usernames that were tried. Passwords never leave the container.

⁠Configuration

VariableDefaultPurpose
AVATORIS_API_KEYrequiredYour Avatoris API key
ENABLE_HONEYPOT_WATCHtrueReport failed logins seen by Cowrie
ENABLE_HOST_SSHD_WATCHfalseAlso report failures against the real host sshd
REPORT_WINDOW_SECONDS1800Avatoris deduplication window
REPORTS_PER_MINUTE25Client side rate limit
FLUSH_INTERVAL_SECONDS60How often aggregated counts are flushed
COWRIE_JSON_PATH/data/cowrie_var/log/cowrie/cowrie.jsonCowrie log to tail
AUTH_LOG_PATH/data/auth.logHost auth log to tail
STATE_DB_PATH/data/state/reporter.dbSQLite state file

Runs as an unprivileged user (UID 10001) with all capabilities dropped.

⁠Tags

latest tracks the newest release. Pin a version such as 1.0.0 for reproducible deployments. edge is built from the main branch and is not recommended for production.

Built for linux/amd64 and linux/arm64.

Source, documentation and issues: https://github.com/avatoris/sshpot⁠

Licensed under MIT.

Tag summary

Content type

Image

Digest

sha256:1bdc8a181…

Size

45.6 MB

Last updated

about 2 months ago

docker pull jnltedev/avatoris_sshpot-reporter