{"id":13845469,"url":"https://github.com/punk-security/pwnspoof","last_synced_at":"2025-08-27T07:07:53.647Z","repository":{"id":45025606,"uuid":"389432482","full_name":"punk-security/pwnspoof","owner":"punk-security","description":"Pwnspoof repository","archived":false,"fork":false,"pushed_at":"2023-09-08T15:39:12.000Z","size":3688,"stargazers_count":261,"open_issues_count":4,"forks_count":31,"subscribers_count":15,"default_branch":"main","last_synced_at":"2025-05-20T03:06:47.456Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/punk-security.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2021-07-25T20:09:00.000Z","updated_at":"2025-04-21T11:48:12.000Z","dependencies_parsed_at":"2024-11-10T18:32:03.364Z","dependency_job_id":"056e670f-ca60-4261-a254-a2f27d22c38b","html_url":"https://github.com/punk-security/pwnspoof","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/punk-security/pwnspoof","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/punk-security%2Fpwnspoof","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/punk-security%2Fpwnspoof/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/punk-security%2Fpwnspoof/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/punk-security%2Fpwnspoof/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/punk-security","download_url":"https://codeload.github.com/punk-security/pwnspoof/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/punk-security%2Fpwnspoof/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":272302171,"owners_count":24910130,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-08-27T02:00:09.397Z","response_time":76,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:03:25.331Z","updated_at":"2025-08-27T07:07:53.624Z","avatar_url":"https://github.com/punk-security.png","language":"Python","funding_links":[],"categories":["Python"],"sub_categories":[],"readme":"[![made-with-python](https://img.shields.io/badge/Made%20with-Python-1f425f.svg)](https://www.python.org/)\n[![Maintenance](https://img.shields.io/badge/Maintained%3F-yes-green.svg)](https://GitHub.com/punk-security/pwnspoof/graphs/commit-activity)\n[![Maintainer](https://img.shields.io/badge/maintainer-PunkSecurity-blue)](https://www.punksecurity.co.uk)\n[![Lines of Code](https://sonarcloud.io/api/project_badges/measure?project=punk-security_pwnspoof\u0026metric=ncloc)](https://sonarcloud.io/summary/new_code?id=punk-security_pwnspoof)\n[![Vulnerabilities](https://sonarcloud.io/api/project_badges/measure?project=punk-security_pwnspoof\u0026metric=vulnerabilities)](https://sonarcloud.io/summary/new_code?id=punk-security_pwnspoof)\n[![Bugs](https://sonarcloud.io/api/project_badges/measure?project=punk-security_pwnspoof\u0026metric=bugs)](https://sonarcloud.io/summary/new_code?id=punk-security_pwnspoof)\n\n[![Logo](/images/banner.png)](#)\n\npwnSpoof (from [Punk Security](https://punksecurity.co.uk/)) generates realistic spoofed log files for common web servers with customisable attack scenarios.\n\nEvery log bundle is unique and completely customisable, making it perfect for generating CTF scenarios and for training serials.\n\nCan you find the attacker session and build the incident picture?\n\n[![realistic_activity](/images/realistic_patterns.png)](#)\n\n## Table of Contents\n\n*  [About The Project     ](#About-The-Project)\n*  [Getting Started       ](#Getting-Started)\n    *  [Prerequisites     ](#Prerequisites)\n    *  [Installation      ](#Installation)\n*  [Usage                 ](#Usage)\n    *  [Switches          ](#Switches)\n    *  [Example           ](#Examples)\n*  [View Demo             ](#Demo)\n*  [Road Map              ](#Road-Map)\n*  [Contact               ](#Contact)\n\n## About The Project\n\npwnSpoof was created on the back of a threat hunting training exercise [Punk Security](https://punksecurity.co.uk) delivered for a customer.  The training exercise was to use a log analytic tool such as Splunk (other log analysing tools are available) and IIS logs to find login brute-force attacks and command injections.\n\nThe idea behind the pwnSpoof application is to;\n*  Provide a quick CTF style training environment\n*  Create unique logs every run\n*  Test threat hunting in IIS, Apache, NGINX, Cloudflare and AWS ALB logs\n\nOnce you have created a set of logs, the idea is to load them in to Splunk and use various techniques to answer the following questions;\n\n*  What was the attackers IP address and user_agent?\n*  Did the attacker authenticate and if so, with what account?\n*  Where was geo-location of the attacker?\n*  When did the attack occur?\n*  What kind of attack was it?\n*  What happened during the attack?\n*  What artifacts may remain on the server?\n*  What steps can be taken to remediate?\n\n## Getting Started\n\nThe following will explain how to get started with pwnSpoof\n\n### Prerequisites\n\npwnSpoof is written in python and is tested with python3.   No extra modules are needed, we only use the standard library.\n\nIf you get the following error message, please specifiy python3 when running pwnSpoof.  Python2 is not supported.\n\n```\n  File \"pwnspoof.py\", line 176\n    print(\"{:6.2f}% \".format(y * x), end=\"\\r\", flush=True)\n                                        ^\nSyntaxError: invalid syntax\n```\n\n### Installation\n\n1. Git clone the pwnSpoof repo\n\n```\ngit clone https://github.com/punk-security/pwnspoof\n```\n\n2. change directory to pwnSpoof\n\n```\ncd pwnspoof\n```\n\n3. Run pwnSpoof\n\n```\npython pwnspoof.py --help\n```\n\n## Usage\n### Switches\n\n```\npositional arguments:\n  {banking,wordpress,generic}\n                        App to emulate\n\noptions:\n  -h, --help            show this help message and exit\n  --out OUT             Output file (default: pwnspoof.log)\n  --iocs                Do you want to know the attackers iocs for easier searching? (default: False)\n\nlog generator settings:\n  --log-start-date LOG_START_DATE\n                        Initial start of logs, in the format YYYYMMDD i.e. \"20210727\"\n  --log-end-date LOG_END_DATE\n                        End date for logs, in the format YYYYMMDD i.e. \"20210727\"\n  --session-count SESSION_COUNT\n                        Number of legitimate sessions to spoof (default: 2000)\n  --max-sessions-per-user MAX_SESSIONS_PER_USER\n                        Max number of legitimate sessions per user (default: 3)\n  --server-fqdn SERVER_FQDN\n                        Override the emulated web apps default fqdn\n  --server-ip SERVER_IP\n                        Override the emulated web apps randomised IP\n  --server-type {IIS,NGINX,CLF,CLOUDFLARE,AWS}\n                        Server to spoof (default: IIS)\n  --uri-file URI_FILE   File containing web uris to override defaults, do not include extensions\n  --noise-file NOISE_FILE\n                        File containing noise uris to override defaults, include extensions\n\nattack settings:\n  --spoofed-attacks SPOOFED_ATTACKS\n                        Number of attacker sequences to spoof (default: 1)\n  --attack-type {bruteforce,command_injection}\n                        Number of attacker sequences to spoof (default: bruteforce)\n  --attacker-geo ATTACKER_GEO\n                        Set the attackers geo by 2 letter region. Use RD for random (default: RD)\n  --attacker-user-agent ATTACKER_USER_AGENT\n                        Set the attackers user-agent. Use RD for random (default: RD)\n  --additional-attacker-ips ADDITIONAL_ATTACKER_IPS\n                        Additional attackers ip addresses, comma separated (default: ). If you wish to exclusively use this list set spoofed-attacks to 0\n```\n\n### Examples\n\nThe following example will create a set of IIS logs for bruteforce against pwnedbank.co.uk.\n\n```\npython pwnspoof.py banking --server-fqdn pwnedbank.co.uk --attack-type bruteforce --server-type IIS --out iis-output.log\n```\n\nThe following example will create a set of NGINX logs for command_injection against pwnedbank.co.uk.\n\n```\npython pwnspoof.py banking --server-fqdn pwnedbank.co.uk --attack-type command_injection --server-type NGINX\n```\n\nThe following example will create a set of logs with 5000 routine sessions and 3 attack sessions\n\n```\npython pwnspoof.py banking --session-count 5000 --spoofed-attacks 3\n```\n\nThe following example will create a set of logs and output the attackers IP addresses\n\n```\npython pwnspoof.py banking --spoofed-attacks 3 --iocs \n```\n\nThe following example will create a set of logs and exclusively use the IP addresses specified\n\n```\npython pwnspoof.py banking --spoofed-attacks 0 --additional-attacker-ips 192.168.0.1,192.168.0.2\n```\n\n## Demo\n\n[![Demo](/images/pwnspoof.gif)](#Demo)\n\n## Road Map\n\npwnSpoof is built to produce to authentic web attack logs and it does this really well.  Right now we are focused on refactoring the code, building out our testing suite and getting the first push to PyPi but we have *huge* ambitions for pwnSpoof.\n\n### Coming soon\nAdding extra webapps beyond banking to provide extra variety to the logs\n\n*  Social media\n*  Wordpress\n*  E-Commerce\n\nAdding additional and more dynamic web attacks\n\n*  Full OWASP TOP 10\n*  Customisable payload encoding\n*  Multi-session attacks\n*  Obfuscation \n\n### Unscheduled aspirations\n**Training Videos!**\n\npwnSpoof was built to be a great tool for training the blue team so it only makes sense to produce some training materials to show it off.\n\n*  How to ingest logs in to various log analyser (Splunk, Elastic, Open Disto, Sentinel)\n*  How to use the power of REGEX to pivot around the data\n\n**Not just weblogs**\n\nWe would love to see pwnSpoof generating all kinds of threat hunting logs such as Office365 audit logs for Sharepoint, Onedrive and AzureAD\n\n**Blackhat Arsenal**\n\nWe have submitted pwnSpoof to Blackhat Arsenal for consideration and it would be AWESOME to demo it at Blackhat London this year (2021).\n\n**Why not contact us with some extra ideas, or add to the project**\n\n## Contact\n\n* Simon Gurney        - simon.gurney@punksecurity.co.uk\n* Daniel Oates-Lee    - daniel.oates-lee@punksecurity.co.uk\n\n## Credit\n\n* **ip2location** :\nWe make use of the IP2Location LITE Country database to provide geographically relevant IP addresses.\n\nThis product includes IP2Location LITE data available from [https://lite.ip2location.com](https://lite.ip2location.com)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fpunk-security%2Fpwnspoof","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fpunk-security%2Fpwnspoof","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fpunk-security%2Fpwnspoof/lists"}