Threat IntelPythonDockerELKAWSSecurity
Distributed HoneyNet & Automated Threat Intelligence
Multi-region decoy sensor array trapping automated exploitation attempts, analyzing malware payloads, and publishing live threat feeds to SIEM.
A production distributed honeypot grid deployed across multiple cloud availability zones to harvest adversarial reconnaissance, brute force, and zero-day exploitation attempts.
Telemetry Pipeline
flowchart LR
Adversary((Adversary / Botnet))
subgraph Sensors ["Decoy Sensor Network"]
Cowrie["Cowrie SSH / Telnet Decoy"]
Dionaea["Dionaea Malware Traps"]
HttpDecoy["Emulated Web API Sensor"]
end
subgraph Processing ["Ingestion & Analysis Plane"]
Logstash["Logstash Normalizer"]
PythonAnalyzer["Python IOC Enrichment Engine"]
MISP["MISP Threat Sharing Platform"]
end
subgraph Defense ["Automated Response Actions"]
WAF["AWS WAF IP Set Drop"]
SIEM["Microsoft Sentinel Threat Intelligence"]
end
Adversary -->|Brute-Force & Scans| Sensors
Sensors -->|Encrypted Syslog| Logstash
Logstash --> PythonAnalyzer
PythonAnalyzer -->|Tagged MITRE ATT&CK| MISP
PythonAnalyzer -->|Automated Dynamic Block| WAF
MISP --> SIEM
Technical Achievements
- Low-Latency IOC Extraction: Automated Python parsing service transforms raw honeypot session dumps into standardized STIX 2.1 threat objects within 8 seconds of intrusion.
- MITRE ATT&CK Mapping: Every recorded session is categorized automatically (e.g.
T1110.001Password Guessing,T1059Command and Scripting Interpreter). - Zero Ingress to Production: Decoy networks reside in dedicated, isolated AWS accounts with VPC peering completely disabled and restricted IAM roles.