pwnlandia / mhn

Modern Honey Network
GNU Lesser General Public License v2.1
2.43k stars 629 forks source link

Add more information on splunk log #499

Open jjjan opened 6 years ago

jjjan commented 6 years ago

Hello, Please add CVE ID of attack, description of rules that system detect and more usable log in splunk log.

d1str0 commented 6 years ago

What would you consider more usable? What information are you looking for? I'm unaware of any honeypots (off the top of my head) that are able to detect CVEs like this.

Pull requests welcome.

jjjan commented 6 years ago

Suricata and snort have CVE at rule just make fields to show the CVE of rule that trigger in attack time.