Honeypot as a Service
haas.nic.cz
Honeypot as a Service
1–10 of 15 posts
Re: Honeypot as a Service
#2Providers like Crowdstrike https://www.crowdstrike.com/ already aggregate results of malware scans for customers.
This is different because it is National CSIRT of the Czech Republic and because it is a honeypot, it will let the attacker use more commands.
Re: Honeypot as a Service
#3Re: Honeypot as a Service
#4"You will get interesting information about the attacks"
(╭ರ_ ⊙ )
Re: Honeypot as a Service
#5Re: Honeypot as a Service
#6If a honeypot is widely used, won't scammers just detect the honeypot? or even just detect latency from their connection being proxied elsewhere?
It's fairly difficult to detect a well-made honeypot.
>even just detect latency from their connection being proxied elsewhere
Not if the attacker is legitimately placed far away from you. Also, from my experience these bots have very large timeouts set.
Re: Honeypot as a Service
#7Won't they see the packets hopping to other devices via a command like 'traceroute'?
Re: Honeypot as a Service
#8> "Your computer stays safe because all communication is redirected to our server." Won't they see the packets hopping to other devices via a command like 'traceroute'?
Re: Honeypot as a Service
#9Re: Honeypot as a Service
#10If a honeypot is widely used, won't scammers just detect the honeypot? or even just detect latency from their connection being proxied elsewhere?
The authors of the tools they use may try to implement honeypot detection, but that's fruitless cat & mouse game, and to what end?
Assuming "honeypot" based on latency is a fool's errand because many legitimate things can induce latency.