Git Product home page Git Product logo

ansible-role-tpotce's Introduction

ansible-role-tpotce

This role is an ansible implementation of the t-pot installer script. It is limited to a sensor only configuration.

Role Variables

honeypot_list

Use this variable to specify which t-pot honeypots you want deployed to the system. The default settings specify the following honeypots:

  • ciscoasa
  • adbhoney
  • conpot
  • cowrie
  • dionaea
  • honeypy
  • glutton
  • heralding
  • mailoney
  • medpot
  • p0f
  • rdpy
  • suricata
  • tanner
  • fatt

You may choose from any of the following:

  • ciscoasa
  • adbhoney
  • conpot
  • cowrie
  • dicompot
  • dionaea
  • elasticpot
  • honeypy
  • honeysap
  • ipphoney
  • glutton
  • honeytrap
  • heralding
  • mailoney
  • medpot
  • p0f
  • rdpy
  • suricata
  • tanner
  • fatt
  • citrixhoneypot

The glutton and honeytrap honeypots can't be used on the same system.

logrotate_days

Use this variable to specify the number of days that logs are retained on the sensor. The default value is 30 days. Depending on the disk size of the honeypot and activity it receives, this value may require adjustment to prevent exhausting disk space.

Filebeat

If you would like to make use of filebeat to send your logs to logstash you need to run the honeynet/ansible-role-tpotce-filebeat role in addition to this one. You will need to add filebeat to the honeypot_list var.

filebeat_version

Use this variable to specify what version of filebeat you would like to use. The following are supported.

- 7.12.0
- 7.11.2
- 7.11.1
- 7.11.0
- 7.10.1
- 7.10.0
- 7.9.3
- 7.9.2
- 7.9.1
- 7.9.0
- 7.8.1
- 7.8.0
- 7.7.1
- 7.7.0
- 7.6.2
- 7.6.1
- 7.5.2
- 7.4.2
- 7.3.2
- 7.2.1
- 7.1.1
- 7.0.1

Example Playbook

- hosts: all
  become: true
  roles:
    - ansible-role-tpotce

Special Thanks

This project is supported by:

License

The role is licensed under GPLv3

ansible-role-tpotce's People

Contributors

dependabot[bot] avatar dpisano avatar

Stargazers

 avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar

ansible-role-tpotce's Issues

Update sshd config

Match Group tpotlogs
        PermitOpen 127.0.0.1:64305
        ForceCommand /usr/bin/false

Configure NTP

echo "### Ensure ntp.service is not listening to avoid potential port conflict with ddospot."
myNTP_IF_DISABLE="interface ignore wildcard
interface ignore 127.0.0.1
interface ignore ::1"

if [ "$(cat /etc/ntp.conf | grep "interface ignore wildcard" | wc -l)" != "1" ];
  then
    echo "### Found active ntp listeners and updating config."
    echo "$myNTP_IF_DISABLE" | tee -a /etc/ntp.conf
    echo "### Restarting ntp.service for changes to take effect."
    systemctl stop ntp.service
    systemctl start ntp.service
  else
    echo "### Found no active ntp listeners."
fi

SSH key deply to hive

sshpass -e ssh -4 -t -T -l "$MY_TPOT_USERNAME" -p 64295 "$MY_HIVE_IP" << EOF
echo "$SSHPASS" | sudo -S bash -c 'useradd -m -s /sbin/nologin -G tpotlogs "$MY_HIVE_USERNAME";
mkdir -p /home/"$MY_HIVE_USERNAME"/.ssh;
echo "$MY_POT_PUBLICKEY" >> /home/"$MY_HIVE_USERNAME"/.ssh/authorized_keys;
chmod 600 /home/"$MY_HIVE_USERNAME"/.ssh/authorized_keys;
chmod 755 /home/"$MY_HIVE_USERNAME"/.ssh;
chown "$MY_HIVE_USERNAME":"$MY_HIVE_USERNAME" -R /home/"$MY_HIVE_USERNAME"/.ssh'

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.