Enrichment Data: Keeping it Fresh, (Fri, Sep 6th)

SANS Internet Storm Center, InfoCON: green 2024-09-06

Summary:

I like to enrich my honeypot data from a variety of sources to help understand a bit more about the context of the attack. This includes the types of networks the attacks are coming from or whether malware submitted to a honeypot is new. I use a variety of sources to enrich my cowrie data using cowrieprocessor [1]:

Link:

https://isc.sans.edu/diary/rss/31236

From feeds:

Intel Hub ยป T01 - SANS Internet Storm Center, InfoCON: green

Tags:

Date tagged:

09/06/2024, 01:36

Date published:

09/05/2024, 19:58