Susheel Thapa
Skip to content
>_ST
Threat IntelPythonDockerELKAWSSecurity

Distributed HoneyNet & Automated Threat Intelligence

Multi-region decoy sensor array trapping automated exploitation attempts, analyzing malware payloads, and publishing live threat feeds to SIEM.

Distributed HoneyNet Architecture Diagram

A production distributed honeypot grid deployed across multiple cloud availability zones to harvest adversarial reconnaissance, brute force, and zero-day exploitation attempts.

Telemetry Pipeline

    flowchart LR
  Adversary((Adversary / Botnet))

  subgraph Sensors ["Decoy Sensor Network"]
      Cowrie["Cowrie SSH / Telnet Decoy"]
      Dionaea["Dionaea Malware Traps"]
      HttpDecoy["Emulated Web API Sensor"]
  end

  subgraph Processing ["Ingestion & Analysis Plane"]
      Logstash["Logstash Normalizer"]
      PythonAnalyzer["Python IOC Enrichment Engine"]
      MISP["MISP Threat Sharing Platform"]
  end

  subgraph Defense ["Automated Response Actions"]
      WAF["AWS WAF IP Set Drop"]
      SIEM["Microsoft Sentinel Threat Intelligence"]
  end

  Adversary -->|Brute-Force & Scans| Sensors
  Sensors -->|Encrypted Syslog| Logstash
  Logstash --> PythonAnalyzer
  PythonAnalyzer -->|Tagged MITRE ATT&CK| MISP
  PythonAnalyzer -->|Automated Dynamic Block| WAF
  MISP --> SIEM
  

Technical Achievements

  • Low-Latency IOC Extraction: Automated Python parsing service transforms raw honeypot session dumps into standardized STIX 2.1 threat objects within 8 seconds of intrusion.
  • MITRE ATT&CK Mapping: Every recorded session is categorized automatically (e.g. T1110.001 Password Guessing, T1059 Command and Scripting Interpreter).
  • Zero Ingress to Production: Decoy networks reside in dedicated, isolated AWS accounts with VPC peering completely disabled and restricted IAM roles.