alphasoc / flightsim

A utility to safely generate malicious network traffic patterns and evaluate controls.
https://alphasoc.com
Other
1.25k stars 132 forks source link

New module: imposter #10

Closed tg closed 2 years ago

tg commented 5 years ago

Would be useful to have an imposter module, so one can generate traffic to domains impersonating well known brands, e.g. offiec365.com, console.amazonaws-ec2.net etc.

chrisforce1 commented 5 years ago

I have a plan for this that involves using the classifiers @ioj is working on to generate imposter domains automatically every 30 days and rotate through these (letting them lapse after a year) so that we consistently have a list of young domains to use. We can pull them from the API in the same way we do sinkholes, etc, and also use them within the demo site.

kmroz commented 2 years ago

Closing via: https://github.com/alphasoc/flightsim/pull/43