Limiting visibility/(trying to make it look less like a honeypot) #1141
Unanswered
lcia-projects
asked this question in
Q&A
Replies: 1 comment 3 replies
-
Is there already a solution for this? Got the same situation now. |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
hi, i'm not sure what the right terminology would be.. but what i'd like to do is "turn off" some of the tpot honeypots so they all aren't running.. so its not as obvious as a honeypot.
For example, I'd like to mimic a small business:
So i might only want, RDP, SFTP,SSH, Suricata running.
do i just need to comment out the rest of the honeypots in the tpot.yml? do i need to modify a firewall or any other configuration files? What would be the best approach to this?
what would be a good small business scenario/build?
any suggestions would be appreciated
Beta Was this translation helpful? Give feedback.
All reactions