2026-06-03 RDP #Honeypot IOCs - 12681 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
159.223.36.55 - 7620
152.42.212.128 - 4827
193.169.194.14 - 27

Top ASNs:
AS14061 - 12459
AS396982 - 36
AS132203 - 30

Top Accounts:
hello - 12489
142.93.8.59 - 75
(empty) - 27

Top ISPs:
DigitalOcean, LLC - 12459
Google LLC - 36
Berdiev Ruslan Mukhabatovich - 27

Top Clients:
Unknown - 12681

Top Software:
Unknown - 12681

Top Keyboards:
Unknown - 12681

Top IP Classification:
hosting - 12543
Unknown - 117
hosting & proxy - 18

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-06-03 RDP #Honeypot IOCs - 12680 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
159.223.36.55 - 7620
152.42.212.128 - 4826
193.169.194.14 - 27

Top ASNs:
AS14061 - 12458
AS396982 - 36
AS132203 - 30

Top Accounts:
hello - 12488
142.93.8.59 - 75
(empty) - 27

Top ISPs:
DigitalOcean, LLC - 12458
Google LLC - 36
Berdiev Ruslan Mukhabatovich - 27

Top Clients:
Unknown - 12680

Top Software:
Unknown - 12680

Top Keyboards:
Unknown - 12680

Top IP Classification:
hosting - 12542
Unknown - 117
hosting & proxy - 18

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-06-03 RDP #Honeypot IOCs - 12679 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
159.223.36.55 - 7620
152.42.212.128 - 4825
193.169.194.14 - 27

Top ASNs:
AS14061 - 12457
AS396982 - 36
AS132203 - 30

Top Accounts:
hello - 12487
142.93.8.59 - 75
(empty) - 27

Top ISPs:
DigitalOcean, LLC - 12457
Google LLC - 36
Berdiev Ruslan Mukhabatovich - 27

Top Clients:
Unknown - 12679

Top Software:
Unknown - 12679

Top Keyboards:
Unknown - 12679

Top IP Classification:
hosting - 12541
Unknown - 117
hosting & proxy - 18

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-06-02 RDP #Honeypot IOCs - 15252 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
159.223.36.55 - 7521
152.42.212.128 - 4839
165.22.106.154 - 2334

Top ASNs:
AS14061 - 15048
AS135918 - 66
AS396982 - 36

Top Accounts:
hello - 15120
(empty) - 33
root - 18

Top ISPs:
DigitalOcean, LLC - 15048
CONTABO - 66
Google LLC - 36

Top Clients:
Unknown - 15252

Top Software:
Unknown - 15252

Top Keyboards:
Unknown - 15252

Top IP Classification:
hosting - 15099
Unknown - 138
hosting & proxy - 9

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-06-02 RDP #Honeypot IOCs - 15251 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
159.223.36.55 - 7520
152.42.212.128 - 4839
165.22.106.154 - 2334

Top ASNs:
AS14061 - 15047
AS135918 - 66
AS396982 - 36

Top Accounts:
hello - 15119
(empty) - 33
root - 18

Top ISPs:
DigitalOcean, LLC - 15047
CONTABO - 66
Google LLC - 36

Top Clients:
Unknown - 15251

Top Software:
Unknown - 15251

Top Keyboards:
Unknown - 15251

Top IP Classification:
hosting - 15098
Unknown - 138
hosting & proxy - 9

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-06-02 RDP #Honeypot IOCs - 15250 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
159.223.36.55 - 7519
152.42.212.128 - 4839
165.22.106.154 - 2334

Top ASNs:
AS14061 - 15046
AS135918 - 66
AS396982 - 36

Top Accounts:
hello - 15118
(empty) - 33
root - 18

Top ISPs:
DigitalOcean, LLC - 15046
CONTABO - 66
Google LLC - 36

Top Clients:
Unknown - 15250

Top Software:
Unknown - 15250

Top Keyboards:
Unknown - 15250

Top IP Classification:
hosting - 15097
Unknown - 138
hosting & proxy - 9

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

HARDENING UI — Localhost Linux Endpoint Security Control Panel
Running as a single, lightweight .py file (no heavy SaaS, no npm/pip sprawling dependencies), Hardening UI bridges the gap between low-level kernel security and operational firewalld management.
Why it’s more than just a firewall utility:
• SYN Flood & DoS Mitigation: One-click injection of hardened sysctl profiles—enabling net.ipv4.tcp_syncookies and tuning network queues directly in the kernel.
• Spoofing & Route Protection: Automatically drops ICMP and secure redirects, and forces net.ipv4.conf.all.log_martians=1 to flag impossible or spoofed source routing.
• Real-Time Socket Triage: Leverages elevated socket diagnostics (ss) to pull absolute ground-truth network state. It maps listening sockets and established connections, explicitly flagging what is unblocked vs. dropped.
• Hypervisor Profiling: Built-in VMware orchestration profiles. Instantly locks down or exposes ports 902, 903, and 912 based on the hypervisor modules (vmnet, vmmon) detected on your host machine.
• Privacy Service Toggles: Direct systemctl state control for core privacy tunnels and remote shells (SSH, Tor, Tailscale, NordVPN, AnyDesk, Cloudflared).
THE SYNERGY: How it links with GODSEYE
When you are using GODSEYE to crawl the deep web, route traceroutes, or probe exposed targets, your intelligence platform is staring outward. Hardening UI acts as the shield facing inward.
By running both on your collection host:
1. Hardening UI sets your firewalld profile to a strict target=DROP policy and disables default public-facing vectors.
2. The sysctl layer protects your machine from retaliatory SYN floods, network mapping amplifier tricks, or spoofed boundary traps.
3. Your host is locked down while GODSEYE safely pipes threat telemetry over Tor SOCKS5h routing behind the perimeter.
Access is free but rigorously vetted via a signed Acceptable Use Agreement. Vetted operators will be manually added to the private repository. Unauthorized redistribution is treated as software theft.
DM me or head to securitycyber.uk to request access.
#LinuxHardening #CyberSecurity #Firewalld #Sysctl #SecOps #ThreatIntelligence #Infosec #DevSecOps

If you're doing #SecOps across multiple orgs with @limacharlieio (💪), you'll definitely want to learn about this: https://blog.reconinfosec.com/cross-org-visibility-for-limacharlie

(If you just want to sleep better knowing someone else is worrying about security operations, let's talk 😉)

Cross-Org Visibility for LimaCharlie

Discover how Recon InfoSec enhances security operations with LimaCharlie, offering cross-org visibility through a Prometheus exporter for unified insights.

2026-06-01 RDP #Honeypot IOCs - 10629 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
159.223.36.55 - 3414
165.22.106.154 - 2964
152.42.212.128 - 2391

Top ASNs:
AS14061 - 10503
AS396982 - 36
AS214576 - 30

Top Accounts:
hello - 10506
(empty) - 33
administrator - 15

Top ISPs:
DigitalOcean, LLC - 10503
Google LLC - 36
Berdiev Ruslan Mukhabatovich - 30

Top Clients:
Unknown - 10629

Top Software:
Unknown - 10629

Top Keyboards:
Unknown - 10629

Top IP Classification:
hosting - 10554
Unknown - 57
hosting & proxy - 18

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security

2026-06-01 RDP #Honeypot IOCs - 10628 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec

Top IPs:
159.223.36.55 - 3414
165.22.106.154 - 2963
152.42.212.128 - 2391

Top ASNs:
AS14061 - 10502
AS396982 - 36
AS214576 - 30

Top Accounts:
hello - 10505
(empty) - 33
administrator - 15

Top ISPs:
DigitalOcean, LLC - 10502
Google LLC - 36
Berdiev Ruslan Mukhabatovich - 30

Top Clients:
Unknown - 10628

Top Software:
Unknown - 10628

Top Keyboards:
Unknown - 10628

Top IP Classification:
hosting - 10553
Unknown - 57
hosting & proxy - 18

Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key

#CyberSec #SOC #Blueteam #SecOps #Security