Seeking Feedback: Developing a FOSS User-Friendly Honeypot Solution for Sysadmins

Posted by DrunkAlbatross@reddit | sysadmin | View on Reddit | 3 comments

Hey r/sysadmin! I'm currently working on an open-source project aimed at simplifying network security for sysadmins through a user-friendly honeypot solution. While there are several open-source honeypot solutions like T-pot available, I've noticed that many IT departments hesitate to implement these due to their complexity and time required for installation and maintenance. Key features I'm planning for the product: \- Easy Deployment: Think pre-configured VMDK or similar, making it accessible to all skill levels. \- Cloud-Based Dashboard: Monitor and manage honeypot instances from cloud-hosted dashboard, free of charge. Hosting the dashboard on-premises will also be an option. \- Real-Time Alerts: Immediate notifications of potential security breaches via SMTP, SNMP traps, or Syslog. \- Customizable: Tailor the solution to fit your specific network environment and requirements. \- Whitelisting: Provide the ability to whitelist noisy source such as vulnerability scanners or BAS products. I'm reaching out to gather insights from the community to ensure that this solution aligns with the needs of IT departments. Would a simplified, user-friendly, and open-source honeypot solution be something you'd consider deploying in your network? What features do you think are most critical for such a product? Your input and suggestions will play a crucial role in shaping this project for the community. Thank you in advance for sharing your thoughts! :)