CURLing for Crypto on Honeypots, (Mon, Dec 9th)
SANS Internet Storm Center, InfoCON: green 2024-12-08
Summary:
I get a daily report from my honeypots for Cowrie activity [1], which includes telnet and SSH sessions attempted on the honyepot. One indicator I use to find sessions of interest is the number of commands run. Most of the time there are about 20 commands run per session, but a session with over 1,000 commands run in a session is unexpected.