Ecosyste.ms: Awesome
An open API service indexing awesome lists of open source software.
https://github.com/pwdrkeg/honeyport
A powershell script for creating a Windows honeyport.
https://github.com/pwdrkeg/honeyport
Last synced: 25 days ago
JSON representation
A powershell script for creating a Windows honeyport.
- Host: GitHub
- URL: https://github.com/pwdrkeg/honeyport
- Owner: Pwdrkeg
- Created: 2012-09-18T20:11:49.000Z (about 12 years ago)
- Default Branch: master
- Last Pushed: 2015-10-22T14:13:28.000Z (about 9 years ago)
- Last Synced: 2024-08-07T21:11:53.324Z (4 months ago)
- Language: PowerShell
- Size: 246 KB
- Stars: 87
- Watchers: 9
- Forks: 28
- Open Issues: 2
-
Metadata Files:
- Readme: README.md
Awesome Lists containing this project
- awesome-honeypot - **76**星
README
.SYNOPSIS
Block IP Addresses that connect to a specified port..DESCRIPTION
Creates a job that listens on TCP Ports specified and when
a connection is established, it can either simply log or
add a local firewall rule to block the host from further
connections.
Writes blocked/probed IPs to the event log named HoneyPort..PARAMETER Ports
List of Ports to listen in for connections..PARAMETER WhiteList
List of IP Addresses that should not be blocked..EXAMPLE
Example monitoring on different ports
PS C:\> .\honeyport.ps1 -Ports 70,79 -Verbose.EXAMPLE
Example monitoring on different ports and add whitelist of hosts
PS C:\> .\honeyport.ps1 -Ports 4444,22,21,23 -WhiteList 192.168.10.1,192.168.10.2 -Verbose.EXAMPLE
Example monitoring on one port and blocking on full TCP connect
PS C:\> .\honeyport.ps1 -Ports 21 -Block.NOTES
Authors: John Hoyt, Carlos Perez
Original Script Modified By: Greg FossStopping HoneyPort;
PS C:\> stop-job -name HoneyPort
PS C:\> remove-job -name HoneyPortListing Events;
PS C:\> get-eventlog HoneyPort