What Happens in the First 24 Hours After a New Asset Goes Live
The First 24 Hours: A Technical Timeline
T+5 to T+60 minutes: The scanners find it.
T+1 to T+6 hours: Enumeration begins.
T+6 to T+12 hours: Active probing.
T+12 to T+24 hours: Compromise.
They deployed 320 #honeypots across cloud providers (RDP, SSH, SMB, Postgres) to see what would happen. 80% were compromised within 24 hours.
https://www.bleepingcomputer.com/news/security/what-happens-in-the-first-24-hours-after-a-new-asset-goes-live/
#Security #ITSec #IT
What Happens in the First 24 Hours After a New Asset Goes Live

When a new asset goes live, attackers start scanning within minutes. Sprocket Security shows how automated attacks move from discovery to compromise in under 24 hours.

BleepingComputer

Launched a page dedicated to the malware payloads the honeypots receive, enriched by VirusTotal: https://honeylabs.net/payloads

#threatintel #cti #malware #opensource #honeypots

Cisco Talos built AI-powered honeypots that trap malicious AI agents. The same unawareness that makes agents dangerous also makes them easy to deceive.

The arms race just went symmetric.

New post in the April agent security cluster:
https://alexreed.srht.site/blog/ai-honeypots-talos.html

#AIsecurity #Honeypots #CiscoTalos #AgentSecurity

When the Honeypot Fights Back: AI Agents Are Easy to Trick

Cisco Talos weaponizes AI agent unawareness. Defenders now spin up deceptive environments that trap automated attacks.

Title: P3: Security and hacking: Honeypots [2024-11-03 Sun]
and /proc/cmdline, which contain UML-specific
information.
- strange HELLO or Banner on ports.

Example: https://www.shodan.io/host/43.203.236.174
#dailyreport #hack #hacking #honeypot #honeypots #infosec #security

Title: P2: P2: Security and hacking: Honeypots [2024-11-03 Sun]
RST, to an open port could solicit a reply from
Honeyd. No other machine on the Internet would reply to
such a packet.
- analyzing files such as /proc/mounts, /proc/interrupts, #dailyreport #hack #hacking #honeypot #honeypots #infosec #security
Title: P1: P2: Security and hacking: Honeypots [2024-11-03 Sun]
- fingerprint physical devices over the network
- use ping flood and calc latency correlation. -
“time-based TCP fingerprinting methods.”
- “discrepancies” a single TCP packet, with both SYN and #dailyreport #hack #hacking #honeypot #honeypots #infosec #security
Title: P1: Security and hacking: Honeypots [2024-11-03 Sun]
- too many open ports
- uncommon combination of open ports. ex. has server
ports: FTP, SSH, HTTP, and POP3 *and* Windows ports
- rarely used ports: 17300
- nmap is not able to identify the version of one
service because HELLO is not implemented.
- change password over time
- honeypot often virtual and exhibit several IP we can use: #dailyreport #hack #hacking #honeypot #honeypots #infosec #security

Title: P2: P0: Security and hacking: Honeypots [2024-11-03 Sun]
emulate IP subnet.

Honeypots may be detected, they:
- do not provide complete environment: ex. in shell not
implement commands
- have strange ports: #dailyreport #hack #hacking #honeypot #honeypots #infosec #security

Title: P1: P0: Security and hacking: Honeypots [2024-11-03 Sun]
I have been reading about honeypots. It is a popular
security tool to trap hackers and global botnets
detector.

They may be simple: just emitate open ports, complex:
have whole OS, distributed: forward connections, virtual: #dailyreport #hack #hacking #honeypot #honeypots #infosec #security

T-minus 10 days!!!

In #CyberSecurity terms, I'm about to deliberately walk into an entirely new threat landscape with no local threat intel, a foreign language I'm still actively patching. The attack surface has changed. The adversaries are now cobblestones, bureaucratic Portuguese, and the very real possibility that I will confidently order the wrong thing at a restaurant and just go with it. Threat level: manageable. Vibes: elevated!!

The honeypots aren't moving. They never do - that's the whole point. They stay scattered where they are, quietly doing their thing, collecting everything. The only thing changing is where the intel gets delivered. Starting April 29th, that's Porto.

I'm a little concerned they're going to start sending it in #Portuguese. 🤷‍♀️

Half my home lab is already there ahead of me. ZimaBoard, #opnsense the Pis - all running, all waiting, probably judging me for not arriving sooner. Home Assistant is next on the list once I land, which means I get to find out whether my automations survived the relocation or whether I'm about to have a very intimate conversation with Portuguese error messages. Could go either way.

And yes, I'm leaving behind the Chicago "L". The L. An elevated rail system so charmingly held together by decades of deferred maintenance and sheer Chicagoan stubbornness that honestly, it's kind of a security metaphor. I'm going to miss the ambiance of a train that sounds like it's actively negotiating with physics.

The Metro stop is literally across the street from my apartment. It's clean. It's modern. It's quiet. The trains run on time. I don't know how I'll cope. 👀

@sashatheflamingo is excited but has concerns about the cobblestones hurting her feet. I told her she can ride on my shoulder. Problem solved. The flamingo adapts. 🦩

And if you're in the security community and haven't looked at #BSidesPorto yet - June 26th and 27th - I don't know what to tell you except that you're going to miss an awesome event if you don't get your tickets - NOW! And come find me. I'll be the one who showed up 60 days before the conference and is still figuring out which bus/metro train goes where.

The operation doesn't stop. It just changes coordinates. The #honeypots already know. They figured it out before I told them. (That's kind of their whole thing.)