diff --git a/doc/architecture.png b/doc/architecture.png index 497e9612..803f3d41 100644 Binary files a/doc/architecture.png and b/doc/architecture.png differ diff --git a/doc/architecture.svg b/doc/architecture.svg new file mode 100644 index 00000000..fa852121 --- /dev/null +++ b/doc/architecture.svg @@ -0,0 +1,4 @@ + + + +
Receive Hive Sensor data via SSH
 Port: 127.0.0.1:64305/tcp
Receive Hive Sensor data via SSH...
https://<ip>:64294, ssh://<ip>:64295
https://<ip>:64297
https://<ip>:64294, ssh://<ip>:64295...
Ports: 22/tcp, 23/tcp
Ports: 22/tcp, 23/tcp
Ports: 21, 42, 69/udp 8081:80, 135, 443, 445, 1433, 1723, 1883, 1900/udp, 3306, 5060/udp, 5061/udp
Ports: 21, 42, 69/udp 8081:80, 135, 443, 445, 1433, 1723, 18...
Ports: 5000/udp, 8443/tcp
Ports: 5000/udp, 8443/tcp
Ports: 80, 102, 161, 502, 623, 1025, 2404, 10001, 44818, 
47808, 50100
Ports: 80, 102, 161, 502, 623, 1025, 2404, 10001, 44818,...
Send honeypot logs to
https://community.sicherheitstacho.eu
Send honeypot logs to...
CiscoASA
Honeypot
CiscoASA...
Conpot
Conpot
Cowrie
Cowrie
Dionaea
Dionaea
ElasticPot
ElasticPot
Glutton
Glutton
Heralding
Heralding
Honeytrap
Honeytrap
Mailoney
Mailoney
Honeypots
Honeypots
FATT
FATT
p0f
p0f
Tools
Tools
Elastic-
Search
Elastic-...
Logstash
Input
Logstash...
Kibana
Kibana
Persist honeypot data for 30 days (/data folder), persist ELK data for 30 days (Kibana Index Lifecycle Management)
Persist honeypot data for 30 days (/data folder), persist ELK data for 30 days (Kibana Index Lifecycle Management)
EWS
Poster
EWS...
NGINX
NGINX
NSM
NSM
ELK Stack
ELK Stack
Port: 127.0.0.1:64296/tcp
Port: 127.0.0.1:64296/tcp
Honeypots
Honeypots
Tools
Tools
Start containers from images via docker-compose, mostly read-only
Start containers from images via docker-compose, mostly read-only
NSM
NSM
ELK Stack
ELK Stack
Elastic-
Search
Elastic-...
Logstash
Logstash
Kibana
Kibana
CiscoASA
Honeypot
CiscoASA...
Conpot
Conpot
Cowrie
Cowrie
Dionaea
Dionaea
ElasticPot
ElasticPot
Glutton
Glutton
Heralding
Heralding
FATT
FATT
p0f
p0f
EWS
Poster
EWS...
NGINX
NGINX
Honeytrap
Honeytrap
Mailoney
Mailoney
Build Multi-Arch (AMD64, ARM64) Docker images from Dockerfiles stored in Telekom-Security's GitHub repositories
Build Multi-Arch (AMD64, ARM64) Docker images from Dockerfiles stored in Telekom-Security's GitHub repositories
Port: 127.0.0.1:64298/tcp
Port: 127.0.0.1:64298/tcp
Port: 64297/tcp
Port: 64297/tcp
Based on Open Source
Debian 11x (AMD64, limited ARM64)
unattended install
Based on Open Source...
Hardware requirements 
RAM 8-16GB+
SSD 128GB+
Hardware requirements...
NFQ
NFQ
Ports: 21, 22, 23, 25, 80, 110, 143, 443, 993,
995, 1080, 5432, 5900
Ports: 21, 22, 23, 25, 80, 110, 143, 443, 993,...
Port: 9200/tcp
Port: 9200/tcp
NFQ
NFQ
Port: 25/tcp
Port: 25/tcp
Secured Access & Sensor Log Input
Secured Access & Sensor Log Input
Internet
Internet
Snare /
Tanner
Snare /...
Medpot
Medpot
Snare /
Tanner
Snare /...
Medpot
Medpot
Port: 80
Port: 80
Port: 2575/tcp
Port: 2575/tcp
Select a standalone edition (Standard, Industrial, Sensor, Medical, Mini), a distributed setup (Hive & Hive Sensor) or
adjust /opt/tpot/etc/tpot.yml to your needs and hardware for an optimized experience.
Select a standalone edition (Standard, Industrial, Sensor, Medical, Mini), a distributed setup (Hive & Hive Sensor) or...
ADBHoney
ADBHoney
ADBHoney
ADBHoney
Port: 5555/tcp
Port: 5555/tcp
qHoneypots
qHoneypots
qHoneypots
qHoneypots
Ports: 7, 8, 2048, 2323, 2324, 4096, 9200
Ports: 7, 8, 2048, 2323, 2324, 4096, 9200
Suricata
Suricata
Suricata
Suricata
Citrix
Honeypot
Citrix...
Citrix
Honeypot
Citrix...
Port: 443/tcp
Port: 443/tcp
Port: 11112/tcp
Port: 11112/tcp
Dicompot
Dicompot
Dicompot
Dicompot
IPPHoney
IPPHoney
IPPHoney
IPPHoney
Port: 631/tcp
Port: 631/tcp
Send Hive Sensor data via SSH
Port: 127.0.0.1:64305/tcp
Send Hive Sensor data via SSH...
Logstash
Output
Logstash...
Ports: 19/udp, 53/udp, 123/udp, 1900/udp
Ports: 19/udp, 53/udp, 123/udp, 1900/udp
Ddospot
Ddospot
Ddospot
Ddospot
Endlessh
Endlessh
Endlessh
Endlessh
Port: 22/tcp
Port: 22/tcp
Hellpot
Hellpot
Hellpot
Hellpot
Port: 80/tcp
Port: 80/tcp
Log4Pot
Log4Pot
Log4Pot
Log4Pot
Ports: 80/tcp, 443/tcp, 8080/tcp, 25565/tcp
Ports: 80/tcp, 443/tcp, 8080/tcp, 25565/tcp
Redis-
Honeypot
Redis-...
Redis-
Honeypot
Redis-...
Port: 6379/tcp
Port: 6379/tcp
Sentry
Peer
Sentry...
Sentry
Peer
Sentry...
Port: 5060/udp
Port: 5060/udp
Logstash
Logstash
Text is not SVG - cannot display
\ No newline at end of file