Skip to content
Snippets Groups Projects
Pavel Valach's avatar
opened issue #2 "Cowrie: Move redirected/stdin content from Malware event to the Intrusion.UserCompromise event" at 713 / Warden / Warden Connectors
Pavel Valach's avatar
commented on merge request !10 "cowrie/wardenfiler: Store credentials for both successful and unsuccessful attempts" at 713 / Warden / Warden Connectors

Tested the latest revision on real traffic, works as designed. Ready for review.

Pavel Valach's avatar
  • 79d88b42 · cowrie/wardenfiler: Fix spurious aggregated "Credentials" with valu...
Pavel Valach's avatar
  • cccd60d7 · cowrie/wardenfiler: Credentials - change "Accepted: True" to Type: ...
Pavel Valach's avatar
Pavel Valach's avatar
commented on merge request !10 "cowrie/wardenfiler: Store credentials for both successful and unsuccessful attempts" at 713 / Warden / Warden Connectors

Marking as draft because it sends events with invalid credential assignment (Src IP address, where the credentials are recorded, does not match the...

Pavel Valach's avatar
opened merge request !10 "cowrie/wardenfiler: Store credentials for both successful and unsuccessful attempts" at 713 / Warden / Warden Connectors
Pavel Valach's avatar
Pavel Valach's avatar
commented on merge request !9 "Dionaea: Move credentials in IDEA to a top-level key "Credentials"" at 713 / Warden / Warden Connectors

Changed the "User" key to more widely used "Username".

Pavel Valach's avatar
  • 4ad6b3a8 · Dionaea: Move credentials in IDEA to a top-level key "Credentials"
Pavel Valach's avatar
commented on merge request !9 "Dionaea: Move credentials in IDEA to a top-level key "Credentials"" at 713 / Warden / Warden Connectors

Tested with FTP, MySQL and MSSQL, that Dionaea adheres to the structure described above.

Pavel Valach's avatar
Pavel Valach's avatar
  • 31d21903 · Dionaea: Removed note from credentials
Pavel Valach's avatar
opened merge request !9 "Dionaea: Move credentials in IDEA to a top-level key "Credentials"" at 713 / Warden / Warden Connectors
Pavel Valach's avatar
Pavel Valach's avatar
deleted branch cowrie-dio-only-log-global-ip at 713 / Warden / Warden Connectors
Daniel Studený's avatar
accepted merge request !6 "Cowrie, Dionaea: in the connectors, only output IDEA events with globally routable source IPs" at 713 / Warden / Warden Connectors
Daniel Studený's avatar
Pavel Valach's avatar
deleted branch cowrie_lstrip_fix at 713 / Warden / Warden Connectors
Daniel Studený's avatar
accepted merge request !8 "cowrie/wardenfiler: Replace lstrip with startswith and slicing" at 713 / Warden / Warden Connectors