bhdresh / Dejavu

DejaVU - Open Source Deception Framework
https://www.camolabs.io
Other
393 stars 97 forks source link

about documentation #33

Closed fullzlop closed 2 years ago

fullzlop commented 2 years ago

Hello, Dejavu Deception framework is working nice but do you guys building some quick start quide or some manual for this.? so why am I asking this cuz need some information how is working, how services are working etc ..

bhdresh commented 2 years ago

Hello, yes, we are working on getting the preliminary documents out by the end of this month.

fullzlop commented 2 years ago

Hello, Thanks for the reply. Good luck for your further

fullzlop commented 2 years ago

one question, I'm using hydra tool to brute-forcing the decoy server and Dejavu's result is not showing its brute force, it's showing like Nmap result. please see from below. image image

bhdresh commented 2 years ago

Can you share information about the services configured in the decoy?

fullzlop commented 2 years ago

hello, please see from below image. image

fullzlop commented 2 years ago

other question is how to clean logs?

fullzlop commented 2 years ago

one question, I'm using hydra tool to brute-forcing the decoy server and Dejavu's result is not showing its brute force, it's showing like Nmap result. please see from below. image image

For this how to differentiate the attack types. etc: brute force, nmap scanning ...

bhdresh commented 2 years ago

You should receive failed FTP authentication alerts like below to derive performed activity. Click on magnifier icon next to the alert to analyze the PCAP.

Screenshot from 2022-01-02 02-42-24

PS: Ensure your instance is upgraded to latest version v14.