Man, I love honeypotter’s simplicity. Set it up once and it just... works.
But yeah, it’s not catching everything. I’ve started logging the misses and feeding them into a SIEM (Splunk, in my case). Adds some overhead, but now I get way better visibility.
If you’re not into SIEMs, maybe just add a simple IP blacklist updater?
But yeah, it’s not catching everything. I’ve started logging the misses and feeding them into a SIEM (Splunk, in my case). Adds some overhead, but now I get way better visibility.
If you’re not into SIEMs, maybe just add a simple IP blacklist updater?
