aplura / Tango

Honeypot Intelligence with Splunk
GNU General Public License v2.0
255 stars 43 forks source link

Pivot on userdb #23

Open mackwage opened 9 years ago

mackwage commented 9 years ago

An idea for a new panel.

When a person logged into kippo creates a new account or changes the password, it adds the password to userdb.txt. So create a panel which shows all of the new passwords created in your sensors. Then you can click on a certain password and another panel shows you all of your sensors which have that password added and all of the IPs who have connected using that password.

brianwarehime commented 9 years ago

That's a great idea, would definitely help for potential campaign attribution.