cuckoosandbox / cuckoo

Cuckoo Sandbox is an automated dynamic malware analysis system
http://www.cuckoosandbox.org
Other
5.55k stars 1.71k forks source link

[Idea] Honeypot mode for Cuckoo #1608

Open Tigzy opened 7 years ago

Tigzy commented 7 years ago

Hello, With friends we were wondering if it could be possible to develop a special mode for Cuckoo (so-called "Honeypot mode" ), that would have the following behavior:

I don't think it would be impossible to do when I'm looking at the current code, but honestly everyone would love it !! :)

ghost commented 7 years ago

That would be a great feature to see

Tigzy commented 7 years ago

No feedback for this? :/ I can give a hand on this, I know python coding and I've spent countless hours customizing Cuckoo with modules :)

doomedraven commented 7 years ago

check long_cuckoo in @jbremer repos, that maybe kinda what you want, just my 2 cents ;)

Tigzy commented 7 years ago

Thanks, but I believe the fork is now completely out of sync with the current Cuckoo 2.0 ?

doomedraven commented 7 years ago

no idea i don't tracki the dev of that one, but that can help in dev if you will start do honey style cuckoo :)

jbremer commented 6 years ago

Sorry for the late reply, but yes, this would be an interesting project and is on our todo list. Whether we'll actually get to work on this next year, I'm not sure yet. Let's wait & see ;-)

jbremer commented 6 years ago

Just for your information, we are in fact working on this now. If you'd like to share/request some ideas/features on use-cases or implementation, then please do let us know. I can also invite you for our Slack btw (give me your email address or send me an email at jbr@cuckoo.sh).

Tigzy commented 6 years ago

@jbremer thanks, will send you my email for the Slack channel