Skip to content

This issue was moved to a discussion.

You can continue the conversation there. Go to discussion →

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

extraction of payloads into ElasticSearch #1652

Closed
mlodic opened this issue Sep 9, 2024 · 0 comments
Closed

extraction of payloads into ElasticSearch #1652

mlodic opened this issue Sep 9, 2024 · 0 comments
Labels
no basic support info Please follow the guidelines so we can help

Comments

@mlodic
Copy link

mlodic commented Sep 9, 2024

hey guys how are you? :)

Last day I was looking for a chance to automatically extract payloads from adbhoney and cowrie so that I can feed other platforms like IntelOwl.

Correct me if I am wrong: right now, those payloads can be found only in the /data/<honeypot> folders.

I thought about adding a logstash parser here to extract those payload from the file system and push a new document for each payload in Elastic with the base64 or hex encoded payload.

In that way it would be possible to use ElasticSearch to extract them and maybe add them into GreedyBear too as an additional feed.

Does it make sense to you? If yes, we could try doing that and open a PR to the project?

Looking forward to meet you at the next workshop :)

@github-actions github-actions bot added the no basic support info Please follow the guidelines so we can help label Sep 9, 2024
@telekom-security telekom-security locked and limited conversation to collaborators Sep 10, 2024
@t3chn0m4g3 t3chn0m4g3 converted this issue into discussion #1653 Sep 10, 2024

This issue was moved to a discussion.

You can continue the conversation there. Go to discussion →

Labels
no basic support info Please follow the guidelines so we can help
Projects
None yet
Development

No branches or pull requests

1 participant