mirror of
https://github.com/andreicscs/HoneyWire
synced 2026-06-26 12:39:53 +00:00
update sensor manifests to reflect manifests.dev.json
This commit is contained in:
@@ -4,7 +4,7 @@
|
||||
"schema_version": "1.0",
|
||||
"min_hub_version": "1.0.0",
|
||||
"min_wizard_version": "1.0.0",
|
||||
"name": "File Canary (FIM) TEST",
|
||||
"name": "File Canary (FIM)",
|
||||
"category": "file",
|
||||
"osi_layer": "Host Level",
|
||||
"icon_svg": "M9 12h6m-6 4h6m2 5H7a2 2 0 01-2-2V5a2 2 0 012-2h5.586a1 1 0 01.707.293l5.414 5.414a1 1 0 01.293.707V19a2 2 0 01-2 2z",
|
||||
@@ -16,19 +16,18 @@
|
||||
"title": "Features",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Zero-Dependency Execution: Runs as a statically compiled binary without requiring external interpreters or libraries.",
|
||||
"Safe Permissions Handling: Uses Access Control Lists (ACLs) to securely read target directories without altering host ownership.",
|
||||
"Context-Aware Lures: Automatically generates realistic trap files based on detected services (database backups, config files, etc.).",
|
||||
"Real-time Monitoring: Instant alerts on file access, modification, or deletion."
|
||||
"Context-Aware Lures: Automatically generates realistic trap files based on detected host services (database backups, web config files, etc.).",
|
||||
"Safe Permissions Handling: Uses Access Control Lists (ACLs) to securely read target directories without altering original host ownership.",
|
||||
"Real-time Alerting: Instant telemetry transmission on file access, modification, or deletion."
|
||||
]
|
||||
},
|
||||
{
|
||||
"title": "Security Architecture",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Unprivileged Execution: Runs entirely as a non-root user (UID 65532).",
|
||||
"Kernel Capability Stripping: Drops ALL Linux kernel capabilities.",
|
||||
"Read-Only Access: Monitors files without write permissions to prevent accidental data corruption."
|
||||
"Global Sandbox Baseline: Enforced by the HoneyWire Hub. Drops ALL default Linux kernel capabilities, enforces a read-only filesystem, and applies strict log rotation.",
|
||||
"Execution Privilege: Runs completely unprivileged as UID 65532 to prevent system-level modifications even in the event of a breach.",
|
||||
"Required Capabilities: DAC_OVERRIDE, operates purely through monitored Volume Mounts."
|
||||
]
|
||||
}
|
||||
]
|
||||
@@ -49,19 +48,18 @@
|
||||
"go"
|
||||
]
|
||||
},
|
||||
"recommendation_reason": "Runtime/app service detected. Deploy to catch malicious file scraping."
|
||||
"recommendation_reason": "Application runtime detected. Deploying a file integrity monitor is highly recommended to catch suspicious canary file interactions or ransomware activity."
|
||||
},
|
||||
"deployment": {
|
||||
"image": "192.168.1.11:5000/honeywire-filecanary:dev",
|
||||
"network_mode": "host",
|
||||
"user": "65532:65532",
|
||||
"init_containers": [
|
||||
{
|
||||
"name": "decoy-provisioner",
|
||||
"name": "fim-decoy-provisioner",
|
||||
"image": "192.168.1.11:5000/honeywire-filecanary:dev",
|
||||
"command": "/app/file-canary init",
|
||||
"user": "0:0",
|
||||
"cap_drop": [
|
||||
"ALL"
|
||||
],
|
||||
"cap_add": [
|
||||
"DAC_OVERRIDE"
|
||||
],
|
||||
@@ -75,10 +73,7 @@
|
||||
"target_prefix": "/host",
|
||||
"read_only": false
|
||||
}
|
||||
],
|
||||
"image_repository": "192.168.1.11:5000/honeywire-filecanary",
|
||||
"image_tag": "latest",
|
||||
"image_digest": ""
|
||||
]
|
||||
}
|
||||
],
|
||||
"volume_mounts": [
|
||||
@@ -114,6 +109,22 @@
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_SEVERITY",
|
||||
"description": "Alert severity sent to the Hub.",
|
||||
"default": "critical",
|
||||
"type": "string",
|
||||
"required": false,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_TEST_MODE",
|
||||
"description": "Enable CI/CD synthetic alerts.",
|
||||
"default": "false",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_ALERT_ON_OPEN",
|
||||
"description": "Generate alerts when a file is simply read or opened (noisier).",
|
||||
@@ -130,9 +141,6 @@
|
||||
"required": false,
|
||||
"hidden": false
|
||||
}
|
||||
],
|
||||
"image_repository": "192.168.1.11:5000/honeywire-filecanary",
|
||||
"image_tag": "latest",
|
||||
"image_digest": ""
|
||||
]
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -16,28 +16,30 @@
|
||||
"title": "Features",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Passive Monitoring: Listens for ICMP traffic without generating responses.",
|
||||
"Passive Monitoring: Listens for ICMP traffic directly on the host interface without generating responses.",
|
||||
"Detailed Logging: Captures source IP, TTL, packet size, and timing information.",
|
||||
"Network Discovery Detection: Identifies internal subnet scanning and host enumeration."
|
||||
"Network Discovery Detection: Identifies internal subnet scanning and host enumeration instantly."
|
||||
]
|
||||
},
|
||||
{
|
||||
"title": "Security Architecture",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Raw Socket Access: Requires NET_RAW capability for packet inspection.",
|
||||
"Host Network Mode: Direct access to host network interfaces.",
|
||||
"Zero External Dependencies: Self-contained monitoring solution."
|
||||
"Global Sandbox Baseline: Enforced by the HoneyWire Hub. Drops ALL default Linux kernel capabilities, enforces a read-only filesystem, and applies strict log rotation.",
|
||||
"Execution Privilege: Runs as container root (UID 0) strictly to initialize the raw network socket.",
|
||||
"Required Capabilities: Adds 'NET_RAW' to allow direct packet inspection bypassing traditional NIDS frameworks."
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
"heuristics": {
|
||||
"triggers": {},
|
||||
"recommendation_reason": "Core Network Sensor. Generates 'Info' severity events to track subnet mapping without triggering alert fatigue from legitimate uptime monitors."
|
||||
"recommendation_reason": "Core Network Sensor, tracks stealthy subnet mapping. Might generate false positives in noisy environments (e.g., Uptime Kuma)."
|
||||
},
|
||||
"deployment": {
|
||||
"image": "192.168.1.11:5000/honeywire-icmpcanary:dev",
|
||||
"network_mode": "host",
|
||||
"user": "0:0",
|
||||
"cap_add": [
|
||||
"NET_RAW"
|
||||
],
|
||||
@@ -65,10 +67,23 @@
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_SEVERITY",
|
||||
"description": "Alert severity sent to the Hub.",
|
||||
"default": "info",
|
||||
"type": "string",
|
||||
"required": false,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_TEST_MODE",
|
||||
"description": "Enable CI/CD synthetic alerts.",
|
||||
"default": "false",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
}
|
||||
],
|
||||
"image_repository": "192.168.1.11:5000/honeywire-icmpcanary",
|
||||
"image_tag": "latest",
|
||||
"image_digest": ""
|
||||
]
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -16,29 +16,30 @@
|
||||
"title": "Features",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Threshold-Based Detection: Configurable scan detection parameters.",
|
||||
"Multiple Scan Types: Detects SYN scans, UDP sweeps, and banner grabbing.",
|
||||
"Intelligent Filtering: Excludes legitimate internal services from scan detection.",
|
||||
"Source Tracking: Logs internal attacker IP addresses and scan patterns."
|
||||
"Threshold-Based Detection: Configurable scan detection parameters for noisy environments.",
|
||||
"Intelligent Filtering: Automatically ignores legitimate internal services to prevent false positives.",
|
||||
"Source Tracking: Logs internal attacker IP addresses and precise scan patterns."
|
||||
]
|
||||
},
|
||||
{
|
||||
"title": "Security Architecture",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Raw Socket Monitoring: Uses packet-level inspection for accuracy.",
|
||||
"Host Network Access: Direct visibility into all network traffic.",
|
||||
"Configurable Sensitivity: Adjustable detection thresholds."
|
||||
"Global Sandbox Baseline: Enforced by the HoneyWire Hub. Drops ALL default Linux kernel capabilities, enforces a read-only filesystem, and applies strict log rotation.",
|
||||
"Execution Privilege: Runs as container root (UID 0) strictly to initialize the raw network socket.",
|
||||
"Required Capabilities: Adds 'NET_RAW' to allow deep packet-level inspection of TCP headers."
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
"heuristics": {
|
||||
"triggers": {},
|
||||
"recommendation_reason": "Core Network Sensor. Highly recommended to silently detect lateral Nmap sweeps and horizontal port scanning across the network interface."
|
||||
"recommendation_reason": "Core Network Sensor, tracks stealthy subnet mapping. Might generate false positives in noisy environments."
|
||||
},
|
||||
"deployment": {
|
||||
"image": "192.168.1.11:5000/honeywire-networkscandetector:dev",
|
||||
"network_mode": "host",
|
||||
"user": "0:0",
|
||||
"cap_add": [
|
||||
"NET_RAW"
|
||||
],
|
||||
@@ -67,6 +68,22 @@
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_SEVERITY",
|
||||
"description": "Alert severity sent to the Hub.",
|
||||
"default": "high",
|
||||
"type": "string",
|
||||
"required": false,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_TEST_MODE",
|
||||
"description": "Enable CI/CD synthetic alerts.",
|
||||
"default": "false",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_SCAN_THRESHOLD",
|
||||
"description": "Number of ports that must be scanned to trigger detection.",
|
||||
@@ -91,9 +108,6 @@
|
||||
"required": false,
|
||||
"hidden": false
|
||||
}
|
||||
],
|
||||
"image_repository": "192.168.1.11:5000/honeywire-networkscandetector",
|
||||
"image_tag": "latest",
|
||||
"image_digest": ""
|
||||
]
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -16,17 +16,18 @@
|
||||
"title": "Features",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Connection Exhaustion: Holds malicious lateral connections open for extended periods.",
|
||||
"Banner Spoofing: Mimics legitimate internal services to attract rogue scanning.",
|
||||
"Resource Denial: Consumes attacker threads and bandwidth silently."
|
||||
"Connection Exhaustion: Holds malicious lateral connections open for extended periods to stall automated tools.",
|
||||
"Banner Spoofing: Mimics legitimate internal services (like SSH or MySQL) to attract rogue scanning.",
|
||||
"Resource Denial: Consumes attacker threads and bandwidth silently without risking host exhaustion."
|
||||
]
|
||||
},
|
||||
{
|
||||
"title": "Security Architecture",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Host Network Mode: Direct access to host networking for port binding.",
|
||||
"Isolated Execution: No persistent data or external dependencies."
|
||||
"Global Sandbox Baseline: Enforced by the HoneyWire Hub. Drops ALL default Linux kernel capabilities, enforces a read-only filesystem, and applies strict log rotation.",
|
||||
"Execution Privilege: Runs as container root (UID 0) strictly to bind to low-numbered decoy ports.",
|
||||
"Required Capabilities: Adds 'NET_BIND_SERVICE' to allow binding to ports below 1024 without needing full host network control."
|
||||
]
|
||||
}
|
||||
]
|
||||
@@ -56,10 +57,15 @@
|
||||
2379
|
||||
]
|
||||
},
|
||||
"recommendation_reason": "Database or SSH service detected. Deploy tarpit to isolate and stall internal lateral movement."
|
||||
"recommendation_reason": "Critical datastore or SSH service detected. Deploy tarpit to isolate and stall internal lateral movement attempts targeting these specific services."
|
||||
},
|
||||
"deployment": {
|
||||
"image": "192.168.1.11:5000/honeywire-tcptarpit:dev",
|
||||
"network_mode": "host",
|
||||
"user": "0:0",
|
||||
"cap_add": [
|
||||
"NET_BIND_SERVICE"
|
||||
],
|
||||
"env_vars": [
|
||||
{
|
||||
"name": "HW_HUB_ENDPOINT",
|
||||
@@ -85,6 +91,22 @@
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_SEVERITY",
|
||||
"description": "Alert severity sent to the Hub.",
|
||||
"default": "high",
|
||||
"type": "string",
|
||||
"required": false,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_TEST_MODE",
|
||||
"description": "Enable CI/CD synthetic alerts.",
|
||||
"default": "false",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_DECOY_PORTS",
|
||||
"description": "Comma-separated list of internal ports to tarpit.",
|
||||
@@ -95,7 +117,7 @@
|
||||
},
|
||||
{
|
||||
"name": "HW_TARPIT_MODE",
|
||||
"description": "Tarpit behavior mode.",
|
||||
"description": "Tarpit behavior mode (hold, echo, close).",
|
||||
"default": "hold",
|
||||
"type": "string",
|
||||
"required": false,
|
||||
@@ -109,9 +131,6 @@
|
||||
"required": false,
|
||||
"hidden": false
|
||||
}
|
||||
],
|
||||
"image_repository": "192.168.1.11:5000/honeywire-tcptarpit",
|
||||
"image_tag": "latest",
|
||||
"image_digest": ""
|
||||
]
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -16,17 +16,18 @@
|
||||
"title": "Features",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Router Simulation: Mimics popular router brands (Netgear, TP-Link, Cisco).",
|
||||
"Credential Logging: Captures attempted login credentials from internal threats.",
|
||||
"Browser Fingerprinting: Logs user-agent and request patterns."
|
||||
"Router Simulation: Mimics popular router brands (Netgear, TP-Link, Cisco) to trick attackers.",
|
||||
"Credential Logging: Captures and alerts on attempted login credentials from internal threats.",
|
||||
"Browser Fingerprinting: Logs user-agent and request patterns for forensic analysis."
|
||||
]
|
||||
},
|
||||
{
|
||||
"title": "Security Architecture",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Bridge Network Mode: Isolated networking with port mapping.",
|
||||
"Stateless Design: No persistent storage of sensitive data."
|
||||
"Global Sandbox Baseline: Enforced by the HoneyWire Hub. Drops ALL default Linux kernel capabilities, enforces a read-only filesystem, and applies strict log rotation.",
|
||||
"Execution Privilege: Runs as container root (UID 0) to allow bridging network modes.",
|
||||
"Required Capabilities: None required. Relies purely on isolated internal container routing."
|
||||
]
|
||||
}
|
||||
]
|
||||
@@ -52,10 +53,12 @@
|
||||
9000
|
||||
]
|
||||
},
|
||||
"recommendation_reason": "Web server detected. Deploy fake admin panel to catch internal network snooping."
|
||||
"recommendation_reason": "Live web proxy or HTTP server detected. Deploy a fake administrative panel to catch internal network snooping and directory brute-forcing."
|
||||
},
|
||||
"deployment": {
|
||||
"network_mode": "bridge",
|
||||
"image": "192.168.1.11:5000/honeywire-webrouterdecoy:dev",
|
||||
"network_mode": "host",
|
||||
"user": "0:0",
|
||||
"env_vars": [
|
||||
{
|
||||
"name": "HW_HUB_ENDPOINT",
|
||||
@@ -81,6 +84,22 @@
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_SEVERITY",
|
||||
"description": "Alert severity sent to the Hub.",
|
||||
"default": "critical",
|
||||
"type": "string",
|
||||
"required": false,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_TEST_MODE",
|
||||
"description": "Enable CI/CD synthetic alerts.",
|
||||
"default": "false",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_BIND_PORT",
|
||||
"description": "Port to bind the decoy web server.",
|
||||
@@ -97,9 +116,6 @@
|
||||
"required": false,
|
||||
"hidden": false
|
||||
}
|
||||
],
|
||||
"image_repository": "192.168.1.11:5000/honeywire-webrouterdecoy",
|
||||
"image_tag": "latest",
|
||||
"image_digest": ""
|
||||
]
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1,535 +0,0 @@
|
||||
[
|
||||
{
|
||||
"id": "hw-sensor-tcp-tarpit",
|
||||
"version": "1.0.0",
|
||||
"schema_version": "1.0",
|
||||
"min_hub_version": "1.0.0",
|
||||
"min_wizard_version": "1.0.0",
|
||||
"name": "TCP Tarpit (Credential Trap)",
|
||||
"category": "network",
|
||||
"osi_layer": "Network Layer",
|
||||
"icon_svg": "M12 8v4l3 3m6-3a9 9 0 11-18 0 9 9 0 0118 0z",
|
||||
"description": "Slows credential brute-force attacks by holding connections open indefinitely.",
|
||||
"documentation": {
|
||||
"summary": "The TCP Tarpit acts as a credential trap for internal network sweeps and compromised devices attempting to pivot. It responds to connection attempts on decoy ports with slow, hanging responses that consume the attacker's resources.",
|
||||
"sections": [
|
||||
{
|
||||
"title": "Features",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Connection Exhaustion: Holds malicious lateral connections open for extended periods.",
|
||||
"Banner Spoofing: Mimics legitimate internal services to attract rogue scanning.",
|
||||
"Resource Denial: Consumes attacker threads and bandwidth silently."
|
||||
]
|
||||
},
|
||||
{
|
||||
"title": "Security Architecture",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Host Network Mode: Direct access to host networking for port binding.",
|
||||
"Isolated Execution: No persistent data or external dependencies."
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
"heuristics": {
|
||||
"triggers": {
|
||||
"processes": [
|
||||
"mysqld",
|
||||
"postgres",
|
||||
"redis-server",
|
||||
"mongod",
|
||||
"mariadb",
|
||||
"sshd",
|
||||
"docker-proxy",
|
||||
"memcached",
|
||||
"rabbitmq",
|
||||
"etcd"
|
||||
],
|
||||
"ports": [
|
||||
3306,
|
||||
5432,
|
||||
6379,
|
||||
27017,
|
||||
22,
|
||||
11211,
|
||||
5672,
|
||||
2379
|
||||
]
|
||||
},
|
||||
"recommendation_reason": "Database or SSH service detected. Deploy tarpit to isolate and stall internal lateral movement."
|
||||
},
|
||||
"deployment": {
|
||||
"network_mode": "host",
|
||||
"env_vars": [
|
||||
{
|
||||
"name": "HW_HUB_ENDPOINT",
|
||||
"description": "The URL of your central HoneyWire Hub.",
|
||||
"default": "__HUB_ENDPOINT__",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_HUB_KEY",
|
||||
"description": "The shared Node Key.",
|
||||
"default": "__HUB_KEY__",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_SENSOR_ID",
|
||||
"description": "Unique identifier for this specific trap.",
|
||||
"default": "hw-sensor-tcp-tarpit",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_DECOY_PORTS",
|
||||
"description": "Comma-separated list of internal ports to tarpit.",
|
||||
"default": "2222,3306",
|
||||
"type": "string",
|
||||
"required": false,
|
||||
"hidden": false
|
||||
},
|
||||
{
|
||||
"name": "HW_TARPIT_MODE",
|
||||
"description": "Tarpit behavior mode.",
|
||||
"default": "hold",
|
||||
"type": "string",
|
||||
"required": false,
|
||||
"hidden": false
|
||||
},
|
||||
{
|
||||
"name": "HW_TARPIT_BANNER",
|
||||
"description": "Service banner to spoof.",
|
||||
"default": "SSH-2.0-OpenSSH_8.2p1\\r\\n",
|
||||
"type": "string",
|
||||
"required": false,
|
||||
"hidden": false
|
||||
}
|
||||
],
|
||||
"image_repository": "ghcr.io/andreicscs/honeywire-tcptarpit",
|
||||
"image_tag": "latest",
|
||||
"image_digest": ""
|
||||
}
|
||||
},
|
||||
{
|
||||
"id": "hw-sensor-web-router-decoy",
|
||||
"version": "1.0.0",
|
||||
"schema_version": "1.0",
|
||||
"min_hub_version": "1.0.0",
|
||||
"min_wizard_version": "1.0.0",
|
||||
"name": "Web Router Decoy",
|
||||
"category": "web",
|
||||
"osi_layer": "Application Layer",
|
||||
"icon_svg": "M5 12h14M5 12a2 2 0 01-2-2V6a2 2 0 012-2h14a2 2 0 012 2v4a2 2 0 01-2 2M5 12a2 2 0 00-2 2v4a2 2 0 002 2h14a2 2 0 002-2v-4a2 2 0 00-2-2m-2-4h.01M17 16h.01",
|
||||
"description": "Fake internal admin panel that logs reconnaissance attempts.",
|
||||
"documentation": {
|
||||
"summary": "The Web Router Decoy mimics vulnerable internal administration interfaces to catch rogue insiders or compromised network assets scanning the LAN for easy targets.",
|
||||
"sections": [
|
||||
{
|
||||
"title": "Features",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Router Simulation: Mimics popular router brands (Netgear, TP-Link, Cisco).",
|
||||
"Credential Logging: Captures attempted login credentials from internal threats.",
|
||||
"Browser Fingerprinting: Logs user-agent and request patterns."
|
||||
]
|
||||
},
|
||||
{
|
||||
"title": "Security Architecture",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Bridge Network Mode: Isolated networking with port mapping.",
|
||||
"Stateless Design: No persistent storage of sensitive data."
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
"heuristics": {
|
||||
"triggers": {
|
||||
"processes": [
|
||||
"nginx",
|
||||
"apache2",
|
||||
"httpd",
|
||||
"lighttpd",
|
||||
"docker-proxy",
|
||||
"traefik",
|
||||
"caddy",
|
||||
"envoy",
|
||||
"haproxy"
|
||||
],
|
||||
"ports": [
|
||||
80,
|
||||
443,
|
||||
8080,
|
||||
8443,
|
||||
9000
|
||||
]
|
||||
},
|
||||
"recommendation_reason": "Web server detected. Deploy fake admin panel to catch internal network snooping."
|
||||
},
|
||||
"deployment": {
|
||||
"network_mode": "bridge",
|
||||
"env_vars": [
|
||||
{
|
||||
"name": "HW_HUB_ENDPOINT",
|
||||
"description": "The URL of your central HoneyWire Hub.",
|
||||
"default": "__HUB_ENDPOINT__",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_HUB_KEY",
|
||||
"description": "The shared Node Key.",
|
||||
"default": "__HUB_KEY__",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_SENSOR_ID",
|
||||
"description": "Unique identifier for this specific trap.",
|
||||
"default": "hw-sensor-web-router-decoy",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_BIND_PORT",
|
||||
"description": "Port to bind the decoy web server.",
|
||||
"default": "{{ availablePort 8080 }}",
|
||||
"type": "int",
|
||||
"required": false,
|
||||
"hidden": false
|
||||
},
|
||||
{
|
||||
"name": "HW_ROUTER_BRAND",
|
||||
"description": "Router brand to simulate.",
|
||||
"default": "Netgear",
|
||||
"type": "string",
|
||||
"required": false,
|
||||
"hidden": false
|
||||
}
|
||||
],
|
||||
"image_repository": "ghcr.io/andreicscs/honeywire-webdecoy",
|
||||
"image_tag": "latest",
|
||||
"image_digest": ""
|
||||
}
|
||||
},
|
||||
{
|
||||
"id": "hw-sensor-file-canary",
|
||||
"version": "1.0.0",
|
||||
"schema_version": "1.0",
|
||||
"min_hub_version": "1.0.0",
|
||||
"min_wizard_version": "1.0.0",
|
||||
"name": "File Canary (FIM)",
|
||||
"category": "file",
|
||||
"osi_layer": "Host Level",
|
||||
"icon_svg": "M9 12h6m-6 4h6m2 5H7a2 2 0 01-2-2V5a2 2 0 012-2h5.586a1 1 0 01.707.293l5.414 5.414a1 1 0 01.293.707V19a2 2 0 01-2 2z",
|
||||
"description": "Honeypot and File Integrity Monitor. Watches files/directories for unauthorized modifications.",
|
||||
"documentation": {
|
||||
"summary": "The File Canary acts as both a Honeypot and a File Integrity Monitor (FIM). It watches a specified directory or file on the host machine for unauthorized access, modifications, or encryption attempts (e.g., Ransomware spreading across the LAN).",
|
||||
"sections": [
|
||||
{
|
||||
"title": "Features",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Zero-Dependency Execution: Runs as a statically compiled binary without requiring external interpreters or libraries.",
|
||||
"Safe Permissions Handling: Uses Access Control Lists (ACLs) to securely read target directories without altering host ownership.",
|
||||
"Context-Aware Lures: Automatically generates realistic trap files based on detected services (database backups, config files, etc.).",
|
||||
"Real-time Monitoring: Instant alerts on file access, modification, or deletion."
|
||||
]
|
||||
},
|
||||
{
|
||||
"title": "Security Architecture",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Unprivileged Execution: Runs entirely as a non-root user (UID 65532).",
|
||||
"Kernel Capability Stripping: Drops ALL Linux kernel capabilities.",
|
||||
"Read-Only Access: Monitors files without write permissions to prevent accidental data corruption."
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
"heuristics": {
|
||||
"triggers": {
|
||||
"processes": [
|
||||
"python3",
|
||||
"node",
|
||||
"java",
|
||||
"nginx",
|
||||
"apache2",
|
||||
"httpd",
|
||||
"php-fpm",
|
||||
"docker-proxy",
|
||||
"ruby",
|
||||
"perl",
|
||||
"go"
|
||||
]
|
||||
},
|
||||
"recommendation_reason": "Runtime/app service detected. Deploy to catch malicious file scraping."
|
||||
},
|
||||
"deployment": {
|
||||
"network_mode": "host",
|
||||
"user": "65532:65532",
|
||||
"init_containers": [
|
||||
{
|
||||
"name": "decoy-provisioner",
|
||||
"command": "/app/file-canary init",
|
||||
"user": "0:0",
|
||||
"cap_drop": [
|
||||
"ALL"
|
||||
],
|
||||
"cap_add": [
|
||||
"DAC_OVERRIDE"
|
||||
],
|
||||
"security_opt": [
|
||||
"no-new-privileges:true"
|
||||
],
|
||||
"volume_mounts": [
|
||||
{
|
||||
"type": "dynamic_dir_bind",
|
||||
"source_env": "HW_DECOY_FILES",
|
||||
"target_prefix": "/host",
|
||||
"read_only": false
|
||||
}
|
||||
],
|
||||
"image_repository": "ghcr.io/andreicscs/honeywire-filecanary",
|
||||
"image_tag": "latest",
|
||||
"image_digest": ""
|
||||
}
|
||||
],
|
||||
"volume_mounts": [
|
||||
{
|
||||
"type": "dynamic_file_bind",
|
||||
"source_env": "HW_DECOY_FILES",
|
||||
"target_prefix": "/canaries",
|
||||
"read_only": true
|
||||
}
|
||||
],
|
||||
"env_vars": [
|
||||
{
|
||||
"name": "HW_HUB_ENDPOINT",
|
||||
"description": "The URL of your central HoneyWire Hub.",
|
||||
"default": "__HUB_ENDPOINT__",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_HUB_KEY",
|
||||
"description": "The shared Node Key.",
|
||||
"default": "__HUB_KEY__",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_SENSOR_ID",
|
||||
"description": "Unique identifier for this specific trap.",
|
||||
"default": "hw-sensor-file-canary",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_ALERT_ON_OPEN",
|
||||
"description": "Generate alerts when a file is simply read or opened (noisier).",
|
||||
"default": "false",
|
||||
"type": "string",
|
||||
"required": false,
|
||||
"hidden": false
|
||||
},
|
||||
{
|
||||
"name": "HW_DECOY_FILES",
|
||||
"description": "Comma-separated list of absolute file paths to deploy and monitor.",
|
||||
"default": "{{ if .HasWeb }}/var/www/html/.backup-config.php{{ else if .HasDB }}/var/lib/db/dump.sql.bak{{ else }}/opt/.env.backup{{ end }}{{ if gt (len .MatchedServices) 1 }},/home/admin/vpn_keys.txt{{ end }}",
|
||||
"type": "string",
|
||||
"required": false,
|
||||
"hidden": false
|
||||
}
|
||||
],
|
||||
"image_repository": "ghcr.io/andreicscs/honeywire-filecanary",
|
||||
"image_tag": "latest",
|
||||
"image_digest": ""
|
||||
}
|
||||
},
|
||||
{
|
||||
"id": "hw-sensor-icmp-canary",
|
||||
"version": "1.0.0",
|
||||
"schema_version": "1.0",
|
||||
"min_hub_version": "1.0.0",
|
||||
"min_wizard_version": "1.0.0",
|
||||
"name": "ICMP Canary",
|
||||
"category": "network",
|
||||
"osi_layer": "Network Layer",
|
||||
"icon_svg": "M5.121 17.804A13.937 13.937 0 0112 16c2.5 0 4.847.655 6.879 1.804M15 10a3 3 0 11-6 0 3 3 0 016 0zm6 2a9 9 0 11-18 0 9 9 0 0118 0z",
|
||||
"description": "Detects internal network discovery (ping sweeps) from compromised assets.",
|
||||
"documentation": {
|
||||
"summary": "The ICMP Canary monitors for Internet Control Message Protocol (ICMP) Echo Request packets. In secure enterprise environments, receiving an internal ping on an isolated workload is highly indicative of a compromised asset performing subnet mapping.",
|
||||
"sections": [
|
||||
{
|
||||
"title": "Features",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Passive Monitoring: Listens for ICMP traffic without generating responses.",
|
||||
"Detailed Logging: Captures source IP, TTL, packet size, and timing information.",
|
||||
"Network Discovery Detection: Identifies internal subnet scanning and host enumeration."
|
||||
]
|
||||
},
|
||||
{
|
||||
"title": "Security Architecture",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Raw Socket Access: Requires NET_RAW capability for packet inspection.",
|
||||
"Host Network Mode: Direct access to host network interfaces.",
|
||||
"Zero External Dependencies: Self-contained monitoring solution."
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
"heuristics": {
|
||||
"triggers": {},
|
||||
"recommendation_reason": "Core Network Sensor. Generates 'Info' severity events to track subnet mapping without triggering alert fatigue from legitimate uptime monitors."
|
||||
},
|
||||
"deployment": {
|
||||
"network_mode": "host",
|
||||
"cap_add": [
|
||||
"NET_RAW"
|
||||
],
|
||||
"env_vars": [
|
||||
{
|
||||
"name": "HW_HUB_ENDPOINT",
|
||||
"description": "The URL of your central HoneyWire Hub.",
|
||||
"default": "__HUB_ENDPOINT__",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_HUB_KEY",
|
||||
"description": "The shared Node Key.",
|
||||
"default": "__HUB_KEY__",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_SENSOR_ID",
|
||||
"description": "Unique identifier for this specific trap.",
|
||||
"default": "hw-sensor-icmp-canary",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
}
|
||||
],
|
||||
"image_repository": "ghcr.io/andreicscs/honeywire-icmpcanary",
|
||||
"image_tag": "latest",
|
||||
"image_digest": ""
|
||||
}
|
||||
},
|
||||
{
|
||||
"id": "hw-sensor-network-scan-detector",
|
||||
"version": "1.0.0",
|
||||
"schema_version": "1.0",
|
||||
"min_hub_version": "1.0.0",
|
||||
"min_wizard_version": "1.0.0",
|
||||
"name": "Network Scan Detector",
|
||||
"category": "network",
|
||||
"osi_layer": "Network Layer",
|
||||
"icon_svg": "M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z M10 7v3m0 0v3m0-3h3m-3 0H7",
|
||||
"description": "Detects horizontal port scanning (Nmap sweeps) across the LAN.",
|
||||
"documentation": {
|
||||
"summary": "The Network Scan Detector identifies compromised internal machines performing horizontal port scans. By silently tracking SYN packets on the network interface, it catches internal Nmap sweeps before they map out the local network.",
|
||||
"sections": [
|
||||
{
|
||||
"title": "Features",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Threshold-Based Detection: Configurable scan detection parameters.",
|
||||
"Multiple Scan Types: Detects SYN scans, UDP sweeps, and banner grabbing.",
|
||||
"Intelligent Filtering: Excludes legitimate internal services from scan detection.",
|
||||
"Source Tracking: Logs internal attacker IP addresses and scan patterns."
|
||||
]
|
||||
},
|
||||
{
|
||||
"title": "Security Architecture",
|
||||
"type": "list",
|
||||
"content": [
|
||||
"Raw Socket Monitoring: Uses packet-level inspection for accuracy.",
|
||||
"Host Network Access: Direct visibility into all network traffic.",
|
||||
"Configurable Sensitivity: Adjustable detection thresholds."
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
"heuristics": {
|
||||
"triggers": {},
|
||||
"recommendation_reason": "Core Network Sensor. Highly recommended to silently detect lateral Nmap sweeps and horizontal port scanning across the network interface."
|
||||
},
|
||||
"deployment": {
|
||||
"network_mode": "host",
|
||||
"cap_add": [
|
||||
"NET_RAW"
|
||||
],
|
||||
"env_vars": [
|
||||
{
|
||||
"name": "HW_HUB_ENDPOINT",
|
||||
"description": "The URL of your central HoneyWire Hub.",
|
||||
"default": "__HUB_ENDPOINT__",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_HUB_KEY",
|
||||
"description": "The shared Node Key.",
|
||||
"default": "__HUB_KEY__",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_SENSOR_ID",
|
||||
"description": "Unique identifier for this specific trap.",
|
||||
"default": "hw-sensor-network-scan-detector",
|
||||
"type": "string",
|
||||
"required": true,
|
||||
"hidden": true
|
||||
},
|
||||
{
|
||||
"name": "HW_SCAN_THRESHOLD",
|
||||
"description": "Number of ports that must be scanned to trigger detection.",
|
||||
"default": "5",
|
||||
"type": "int",
|
||||
"required": false,
|
||||
"hidden": false
|
||||
},
|
||||
{
|
||||
"name": "HW_SCAN_WINDOW",
|
||||
"description": "Time window in seconds for scan detection.",
|
||||
"default": "5",
|
||||
"type": "int",
|
||||
"required": false,
|
||||
"hidden": false
|
||||
},
|
||||
{
|
||||
"name": "HW_IGNORE_PORTS",
|
||||
"description": "Comma-separated list of ports to exclude from scan detection.",
|
||||
"default": "{{ if .IgnorePorts }}{{ .IgnorePorts }}{{ else }}22,80,443{{ end }}",
|
||||
"type": "string",
|
||||
"required": false,
|
||||
"hidden": false
|
||||
}
|
||||
],
|
||||
"image_repository": "ghcr.io/andreicscs/honeywire-networkscandetector",
|
||||
"image_tag": "latest",
|
||||
"image_digest": ""
|
||||
}
|
||||
}
|
||||
]
|
||||
Reference in New Issue
Block a user