telekom-security / tpotce

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝
GNU General Public License v3.0
6.69k stars 1.07k forks source link

Source IP from binary uploaders #1500

Closed domingo13 closed 6 months ago

domingo13 commented 6 months ago

Is there a way to get the source ip of the clients uploading binaries into dionaea?

I can see a lot of uploads but I haven't found a way to correlated those binaries to and actual source ip. dionaea.json contains a lot of activity but most of them are just port scanners.