Daily Blog #741: AI powered Honeypots
这篇文章介绍了AI在蜜罐技术中的应用。传统蜜罐需要大量工作来模拟真实环境,而AI通过大语言模型动态生成文件、进程和服务信息,使攻击者更难识别蜜罐。作者推荐了两个AI蜜罐项目:Splunk的DECEIVE和Galah,并认为这些工具非常有趣且高效。 2025-2-7 04:27:0 Author: www.hecfblog.com(查看原文) 阅读量:18 收藏

By February 06, 2025

Hello Reader,

I’ve always found honeypots fascinating. There’s something deeply satisfying about reviewing logs of frustrated attackers and uncovering their latest tactics. However, setting up a convincing honeypot has traditionally required a lot of effort—crafting realistic environments, files, and services to appear valuable while ensuring they couldn’t be exploited for real attacks.

AI has changed the game once again. There are now AI-powered honeypots (at least two that I know of) that leverage large language models to simulate entire systems. These models dynamically generate file listings, process lists, file contents, and other system artifacts, making fingerprinting much harder for attackers. I think this is incredibly cool! In fact, I once asked ChatGPT to pretend to be a Linux system—and the results were hilarious!

Here are two AI-powered honeypots worth checking out:

Splunk AI Honeypot (DECEIVE) – SSH Honeypot

🔗 GitHub: splunk/DECEIVE

Galah – HTTP Honeypot

🔗 GitHub: 0x4D31/galah

Hope you find these as interesting as I do!



文章来源: https://www.hecfblog.com/2025/02/daily-blog-741-ai-powered-honeypots.html
如有侵权请联系:admin#unsafe.sh