HoneyPot SOC
vm3.lab-it.net
Time Range

Overview

Total Events (24h)
Unique Attackers
SSH Brute (Cowrie)
Web Scans (HTTP)
Critical Alerts (24h)
IDS Alerts (24h)
All-time Total

Events Over Time

Recent Alerts

Incident Cases

CRITICAL
HIGH
MEDIUM
LOW
ACTIVE (Open + In Progress)

Create New Case

ID Severity Title Source IP Status Created

IDS Alerts

Suricata + ET Open ruleset · 66K signatures
SEV-1 CRITICAL
SEV-2 HIGH
SEV-3 INFO
TOTAL 24H

Top Signatures

most triggered detections

Categories

alert distribution

Recent Alerts

Time Source IP Country Signature Proto

SSH Bot Fingerprints (HASSH)

같은 hash = 같은 봇/봇넷

Top HASSH Fingerprints (Last 7d)

# HASSH SSH Client Unique IPs Sessions Sample IP First Seen

Threat Intelligence Matches

매칭된 IP (24h)
관련 이벤트

Known-bad IPs in our traffic

알려진 봇넷 — 즉시 차단 후보
#IPCountryEvents 24hTI SourceCIDR

Geographic Distribution

countries · 30-day heatmap

World Map

countries

Activity Heatmap

hour × day-of-week · 30d

Top Threats

click IP to drill down

Top Attacker IPs

Live Attack Feed

Attack Patterns

most common indicators

Top Scan Paths

HTTP

Top Credentials

SSH

Top Commands

post-login

Correlation Analysis

shared IOCs across multiple attackers

Shared Credentials

same user/pass across IPs

Shared Commands

same exec across IPs

Advanced Analytics

subnet detection · network graph · alert rules

Alert Rules

active
NameFieldOpValueAction
No rules configured

Malicious Sources

URLs captured from attacker commands

Malicious URLs

TimeSource IPCountryURL
분석 중...
위협 분석 리포트
위협 점수 이력
활동 요약
전체 이벤트
로그인 성공
로그인 실패
시간 순 공격 세션 재현 (건)
🚫 차단된 IP 목록
iptables로 자동 차단된 공격자 IP