Advertisement
DShield Honeypot TTY Log Analysis Reveals Common Crontab Attacks
Runtime Rebel analyzes SANS ISC's report on TTY log collection from DShield honeypots, revealing common crontab commands executed by over 3,130 unique actors.
DShield SIEM Update: ELK Stack 8.19.15 and Enhanced Logging
SANS ISC updates the DShield SIEM to ELK stack 8.19.15, introducing enhanced logging capabilities and new dashboards for improved honeypot data analysis.
DShield Sensor Analysis: A Year of Observed Threat Upload Trends
Runtime Rebel analyzes a year of file uploads to DShield sensors, revealing peak threat activity from December 2025 to February 2026 and subsequent decline.
DShield Honeypot Updates: Ensuring Timely Threat Data Collection
SANS ISC announces upcoming updates for DShield honeypots. Learn why these automatic updates are crucial for maintaining effective threat intelligence collection.
Emerging Reconnaissance: Attackers Actively Probe AI Models
DShield sensors detect increasing scanning activity targeting popular AI models like Claude and Hugging Face, signaling a potential new attack vector for threat actors.
Cowrie Honeypot Analysis: Detecting Automated Session Disconnects
Analyze DShield Cowrie honeypot data to distinguish between automated bot traffic and manual actor activity through session duration and exit commands.
Advertisement
Analysis of 'iranbot' Message in Cowrie Honeypot Logs
A peculiar 'iranbot_was_here' message, alongside Telnet logins and portscans, was observed in Cowrie honeypot logs, signaling potential reconnaissance activity.
Optimizing Honeypot Log Analysis Using AI and LLM Orchestration
An analysis of how AI-assisted log processing reduces noise in DShield and Cowrie honeypot data, enabling analysts to identify sophisticated threat patterns.