Skip to content

Charles-Roro/ManningAzureHoneypot

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 

Repository files navigation

  1. Creating VM in Azure for Tracking Threat Activities.

Screenshot 2024-09-17 at 12 22 14 AM Screenshot 2024-09-17 at 12 23 12 AM Screenshot 2024-09-17 at 12 23 29 AM Screenshot 2024-09-17 at 12 26 56 AM

Making a seperate security group with all ports open. This is to allow all traffic and pings to HIT the VM.

Screenshot 2024-09-17 at 12 32 57 AM Screenshot 2024-09-17 at 12 35 48 AM

Creating a Log in Log Analytics workspace to make a Geolocation Log to track location of Threat Actors locations and IP's

Screenshot 2024-09-17 at 12 42 26 AM

            Turning on Microsoft Defender to enable the ability to gather Logs. 

Screenshot 2024-09-17 at 12 49 03 AM Screenshot 2024-09-17 at 12 49 45 AM

                Connecting the Log to the created VM.

Screenshot 2024-09-17 at 12 53 03 AM Screenshot 2024-09-17 at 12 56 00 AM

          Setting up Microsoft Sentinel to visualize the attack data

Screenshot 2024-09-17 at 1 01 44 AM

  Logging in to the VM with Remote desktop to setup logging script and adjusting Firewall rules on the VM.

Screenshot 2024-09-17 at 1 04 59 AM

        Using Event Viewer in the VM to see failed Login attempts

Screenshot 2024-09-17 at 1 17 52 AM

    Pinging the VM on the main machine and setting up Firewall rules in the VM to allow attackers to find the VM faster through icmp echos

Screenshot 2024-09-17 at 1 21 24 AM Screenshot 2024-09-17 at 1 26 25 AM Screenshot 2024-09-17 at 1 29 28 AM Screenshot 2024-09-17 at 1 30 03 AM Screenshot 2024-09-17 at 1 30 10 AM Pings now working Screenshot 2024-09-17 at 1 31 27 AM

            Using Powershell ISE to run the geolocation script

Screenshot 2024-09-17 at 1 48 09 AM

          Script running and showing failed login attempts on the machine

Screenshot 2024-09-17 at 1 51 18 AM

  Creating a custom Log in Log Analytics workspace to help Sentinel visualize the data

Screenshot 2024-09-17 at 1 58 11 AM Screenshot 2024-09-17 at 2 04 41 AM Screenshot 2024-09-17 at 2 06 05 AM Screenshot 2024-09-17 at 2 06 31 AM

                        Setting up Microsoft Sentinel 

Screenshot 2024-09-17 at 4 15 17 AM

Screenshot 2024-09-17 at 4 15 51 AM

                        Setting up a new query in Sentinel workbook

Screenshot 2024-09-17 at 4 16 47 AM

                        Changing the Data to be visualize via Map

Screenshot 2024-09-17 at 4 19 18 AM

                Final RESULTS after letting the Honeypot run for 6 hours!!

Screenshot 2024-09-17 at 8 15 25 AM

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors