<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Honeypot in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Honeypot/m-p/8109#M996</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For those of you who want to play a bit more with the various blades I recommend you create an isolated network on your (test) firewall. On it you can install&amp;nbsp;&lt;A href="http://dtag-dev-sec.github.io/mediator/feature/2017/11/07/t-pot-17.10.html"&gt;T-Pot&lt;/A&gt;&amp;nbsp;as honeypot farm.&lt;/P&gt;&lt;P&gt;Then start by natting unused IP addresses to your honeypot farm and allow all traffic to hit the honeypot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most interresting is to see the differences in hits per day between Threat prevention in detect mode and in blocking mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also once you have it open for a few days have a look at shodan.io and see how they start to map your honeypot for you. That in turn propably results in more traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="T-Pot results" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/74990_2018-11-23 13_04_15-RDS01 - rds01.ncc.qi.nl - Remote Desktop Connection.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have few IP's leading to this honeypot and they get hit from all over the globe:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="World map" class="image-2 jive-image j-img-original" src="/legacyfs/online/checkpoint/74991_2018-11-23 13_06_36-RDS01 - rds01.ncc.qi.nl - Remote Desktop Connection.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;T-Pot is a breeze to install and so much fun to bait. This way you can have more fun with your (test) firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 Nov 2018 12:08:30 GMT</pubDate>
    <dc:creator>Hugo_vd_Kooij</dc:creator>
    <dc:date>2018-11-23T12:08:30Z</dc:date>
    <item>
      <title>Honeypot</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Honeypot/m-p/8109#M996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For those of you who want to play a bit more with the various blades I recommend you create an isolated network on your (test) firewall. On it you can install&amp;nbsp;&lt;A href="http://dtag-dev-sec.github.io/mediator/feature/2017/11/07/t-pot-17.10.html"&gt;T-Pot&lt;/A&gt;&amp;nbsp;as honeypot farm.&lt;/P&gt;&lt;P&gt;Then start by natting unused IP addresses to your honeypot farm and allow all traffic to hit the honeypot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most interresting is to see the differences in hits per day between Threat prevention in detect mode and in blocking mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also once you have it open for a few days have a look at shodan.io and see how they start to map your honeypot for you. That in turn propably results in more traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="T-Pot results" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/74990_2018-11-23 13_04_15-RDS01 - rds01.ncc.qi.nl - Remote Desktop Connection.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have few IP's leading to this honeypot and they get hit from all over the globe:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="World map" class="image-2 jive-image j-img-original" src="/legacyfs/online/checkpoint/74991_2018-11-23 13_06_36-RDS01 - rds01.ncc.qi.nl - Remote Desktop Connection.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;T-Pot is a breeze to install and so much fun to bait. This way you can have more fun with your (test) firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Nov 2018 12:08:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Honeypot/m-p/8109#M996</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2018-11-23T12:08:30Z</dc:date>
    </item>
  </channel>
</rss>

