diff --git a/compose/mini.yml b/compose/mini.yml index 7cad515f..2fca53e1 100644 --- a/compose/mini.yml +++ b/compose/mini.yml @@ -225,6 +225,7 @@ services: - "22:22" - "23:23" - "25:25" + - "67:67/udp" - "53:53/udp" - "80:80" - "110:110" diff --git a/compose/tarpit.yml b/compose/tarpit.yml index ef2ee8b4..d7fdb10b 100644 --- a/compose/tarpit.yml +++ b/compose/tarpit.yml @@ -104,19 +104,19 @@ services: networks: - heralding_local ports: - # - "21:21" + - "21:21" # - "22:22" - # - "23:23" - # - "25:25" + - "23:23" + - "25:25" # - "80:80" - "110:110" - "143:143" - # - "443:443" + - "443:443" - "465:465" - "993:993" - "995:995" - # - "3306:3306" - # - "3389:3389" + - "3306:3306" + - "3389:3389" - "1080:1080" - "5432:5432" - "5900:5900" diff --git a/compose/tpot_services.yml b/compose/tpot_services.yml index 2dc2cb25..f3b52b78 100644 --- a/compose/tpot_services.yml +++ b/compose/tpot_services.yml @@ -429,25 +429,25 @@ services: - ${TPOT_DATA_PATH}/galah/cert:/opt/galah/config/cert - ${TPOT_DATA_PATH}/galah/log:/opt/galah/log -# # Glutton service - # glutton: - # container_name: glutton - # restart: always - # depends_on: - # tpotinit: - # condition: service_healthy - # tmpfs: - # - /var/lib/glutton:uid=2000,gid=2000 - # - /run:uid=2000,gid=2000 - # network_mode: "host" - # cap_add: - # - NET_ADMIN - # image: ${TPOT_REPO}/glutton:${TPOT_VERSION} - # pull_policy: ${TPOT_PULL_POLICY} - # read_only: true - # volumes: - # - ${TPOT_DATA_PATH}/glutton/log:/var/log/glutton - # - ${TPOT_DATA_PATH}/glutton/payloads:/opt/glutton/payloads +# Glutton service + glutton: + container_name: glutton + restart: always + depends_on: + tpotinit: + condition: service_healthy + tmpfs: + - /var/lib/glutton:uid=2000,gid=2000 + - /run:uid=2000,gid=2000 + network_mode: "host" + cap_add: + - NET_ADMIN + image: ${TPOT_REPO}/glutton:${TPOT_VERSION} + pull_policy: ${TPOT_PULL_POLICY} + read_only: true + volumes: + - ${TPOT_DATA_PATH}/glutton/log:/var/log/glutton + - ${TPOT_DATA_PATH}/glutton/payloads:/opt/glutton/payloads # Go-pot service go-pot: @@ -514,19 +514,19 @@ services: networks: - heralding_local ports: - # - "21:21" - # - "22:22" - # - "23:23" - # - "25:25" - # - "80:80" + - "21:21" + - "22:22" + - "23:23" + - "25:25" + - "80:80" - "110:110" - "143:143" - # - "443:443" + - "443:443" - "465:465" - "993:993" - "995:995" - # - "3306:3306" - # - "3389:3389" + - "3306:3306" + - "3389:3389" - "1080:1080" - "5432:5432" - "5900:5900" @@ -572,6 +572,7 @@ services: - "23:23" - "25:25" - "53:53/udp" + - "67:67/udp" - "80:80" - "110:110" - "123:123" diff --git a/docker/elk/logstash/dist/http_output.conf b/docker/elk/logstash/dist/http_output.conf index eb243e53..0bbda4fc 100644 --- a/docker/elk/logstash/dist/http_output.conf +++ b/docker/elk/logstash/dist/http_output.conf @@ -518,6 +518,9 @@ filter { date { match => [ "timestamp", "ISO8601" ] } + mutate { + remove_field => ["ts"] + } } # Hellpot diff --git a/docker/elk/logstash/dist/logstash.conf b/docker/elk/logstash/dist/logstash.conf index f220bb0f..c1b450a4 100644 --- a/docker/elk/logstash/dist/logstash.conf +++ b/docker/elk/logstash/dist/logstash.conf @@ -510,6 +510,9 @@ filter { date { match => [ "timestamp", "ISO8601" ] } + mutate { + remove_field => ["ts"] + } } # Glutton diff --git a/docker/go-pot/Dockerfile b/docker/go-pot/Dockerfile index 87d0f194..5f410c61 100644 --- a/docker/go-pot/Dockerfile +++ b/docker/go-pot/Dockerfile @@ -3,18 +3,18 @@ RUN <