Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

ย 

History

38 Commits
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

๐Ÿ›ก๏ธ HoneyCloud Sentinel

AI-Driven Adaptive Honeypot Intelligence Platform

for Real-Time Cyber Threat Detection ...

IMPORTANT LINK for deploying https://honeycloud-api.onrender.com/ https://primary-production-7b22f.up.railway.app/webhook-test/honeypot-attack https://primary-production-7b22f.up.railway.app/workflow/HhMmL8biG5nRdzvr https://railway.com/project/c7b84d25-36c5-4c30-93dd-65f477134d8b?environmentId=b689c01c-cb5d-48c7-a97d-d1dd7c7d128a https://cloud.redpanda.com/clusters

Turning attacker behavior into actionable cyber intelligence.

Python FastAPI Next.js Kafka TensorFlow n8n License


Trained on 14.2 Million Real-World Attack Records from 4 Honeypot Datasets

Features โ€ข Architecture โ€ข Screenshots โ€ข Quick Start โ€ข ML Models โ€ข Datasets โ€ข API โ€ข n8n Workflow


๐Ÿ“ธ Screenshots

SOC Dashboard โ€” Live Attack Overview

Dashboard


๐ŸŒŸ Overview

HoneyCloud Sentinel is a production-grade cybersecurity platform that deploys AI-powered adaptive honeypots to attract, detect, analyze, and predict cyber attacks in real time.

The system captures attacker behavior through intelligent decoy services, streams attack data through Apache Kafka, runs four ML models trained on 14.2 million real attacks, enriches every HIGH/CRITICAL threat through an automated n8n intelligence pipeline, maps attacks to MITRE ATT&CK, and displays everything on a professional SOC-grade dashboard.

National Level Hackathon โ€” Blue Team Challenge Fully addresses all problem statement requirements: adaptive honeypots, ML threat detection, real-time visualization, threat intelligence provider collaboration, and AI orchestration framework (n8n).


โœจ Features

๐Ÿ Adaptive Honeypot Engine (New โ€” Phase B)

  • Behavioral Fingerprinter โ€” detects Hydra, Medusa, Nmap, Metasploit, Paramiko from client banners and timing
  • 6 Attacker Profiles โ€” Scanner, Script Kiddie, Botnet Node, Credential Stuffer, Targeted, APT Actor
  • 4 Deception Strategies โ€” deny fast / slow response (tarpit) / fake login / full fake environment
  • Honeytoken Planting โ€” fake AWS credentials, SSH keys, deploy scripts trap APT actors
  • Command Intelligence โ€” collects every command run in fake shell sessions
  • Rich Kafka Telemetry โ€” behavioral data, profile, strategy all flow to dashboard

๐ŸŒ n8n Orchestration Pipeline (New โ€” Phase C)

  • Visual workflow โ€” Webhook โ†’ Filter โ†’ AbuseIPDB โ†’ VirusTotal โ†’ Cross-Correlation โ†’ Decision โ†’ Callback
  • Processes every HIGH/CRITICAL attack automatically with no manual intervention
  • Cross-correlates 3 independent sources into single Threat Intel Score (0โ€“100)
  • Full audit trail in n8n Executions panel
  • n8n status badge in dashboard header โ€” shows ACTIVE + processed count live

๐Ÿ” Threat Intelligence Enrichment (New โ€” Phase A)

  • AbuseIPDB โ€” community confidence score, abuse reports, ISP, Tor/VPN/Proxy detection
  • VirusTotal โ€” 94 antivirus engine scan, reputation, categories
  • HoneyCloud ML โ€” behavioral cross-correlation from 14.2M trained model
  • Score breakdown โ€” AbuseIPDB (max 45) + VirusTotal (max 40) + ML (max 15) + corroboration bonus
  • 4-tier output: CONFIRMED THREAT / HIGH CONFIDENCE / SUSPICIOUS / LOW RISK
  • Evidence chain with numbered findings โ€” fully auditable

๐Ÿ”ด Real-Time Detection

  • SSH Honeypot โ€” captures brute force and credential attacks on port 2222
  • Kafka streaming pipeline โ€” zero-latency attack log processing
  • IP Geolocation โ€” maps every attacker to country and city in real time
  • Server-Sent Events โ€” dashboard updates instantly without polling
  • Risk Scorer โ€” background noise correctly scored LOW, real attacks escalated

๐Ÿค– ML / AI Engine

  • Isolation Forest โ€” detects zero-day anomalous attacks with no prior rules
  • Random Forest โ€” classifies 9 attack types with confidence scores
  • K-Means Clustering โ€” groups attacks into 8 coordinated campaign clusters
  • LSTM Neural Network โ€” predicts next likely attack from sequence of 10

๐ŸŽฏ MITRE ATT&CK Integration

  • Every attack auto-mapped to official MITRE technique ID and tactic
  • Interactive heatmap showing which tactics are most active right now
  • Clickable technique IDs open attack.mitre.org directly
  • Covers 9 attack classes across 5 MITRE tactics

๐Ÿ•ต๏ธ Multi-Agent Threat Investigation

  • Agent 1 โ€” Log Analyzer: extracts Indicators of Compromise
  • Agent 2 โ€” Threat Investigator: identifies campaigns and actor types
  • Agent 3 โ€” Risk Analyst: assesses business impact
  • Agent 4 โ€” Response Recommender: 5 numbered executable actions
  • Powered by Groq API (Llama 3.3 70B) โ€” on-demand only, rate limit safe

๐Ÿ“Š SOC Dashboard

  • Dark military-ops aesthetic โ€” JetBrains Mono + Rajdhani, cyan on #080c14
  • Resizable world map โ€” drag handles for width and height
  • LIVE / VIEW toggle on map โ€” LIVE shows attack lines, VIEW flies to attacker city
  • Custom React popup cards โ€” no Leaflet white borders
  • Clickable attack feed โ†’ highlights row + updates map + opens investigation
  • MITRE heatmap with drill-down to technique IDs
  • LSTM prediction panel with probability distribution per class
  • n8n status indicator in header
  • One-click AI report (HTML + PDF)

๐Ÿ“„ AI Report Generator

  • HTML report โ€” dark SOC theme, SVG risk gauge, bar charts, IoC section
  • PDF download โ€” professional threat intelligence document
  • LLM-written 7-section analysis including IoCs and campaign attribution

๐Ÿ—๏ธ Architecture

Internet Attackers
        โ”‚
        โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚         ADAPTIVE HONEYPOT ENGINE             โ”‚
โ”‚  Behavioral Fingerprinter                   โ”‚
โ”‚  Attacker Profiler (6 profiles)             โ”‚
โ”‚  Deception Strategy (4 strategies)          โ”‚
โ”‚  Honeytoken Planting                        โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                   โ”‚ Kafka: honeypot-attacks
                   โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚              APACHE KAFKA                    โ”‚
โ”‚         High-throughput log streaming        โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                   โ”‚
                   โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚           ML ENGINE (FastAPI)                โ”‚
โ”‚  Isolation Forest โ†’ Random Forest           โ”‚
โ”‚  K-Means โ†’ Risk Scorer โ†’ MITRE Mapper      โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
           โ”‚ HIGH/CRITICAL         โ”‚ All attacks
           โ–ผ                       โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚   n8n WORKFLOW       โ”‚  โ”‚   ATTACK STORE     โ”‚
โ”‚   AbuseIPDB          โ”‚  โ”‚   deque(200)       โ”‚
โ”‚   VirusTotal         โ”‚  โ”‚   REST API         โ”‚
โ”‚   Cross-Correlate    โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
โ”‚   Callback API       โ”‚            โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜            โ–ผ
                         โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
                         โ”‚  4-AGENT TI PIPELINE   โ”‚
                         โ”‚  (On-demand via Groq)  โ”‚
                         โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                                      โ”‚
                                      โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚               SOC DASHBOARD (Next.js 14)             โ”‚
โ”‚  Map ยท MITRE Heatmap ยท Attack Feed                  โ”‚
โ”‚  Investigation ยท Threat Intel ยท LSTM ยท Reports      โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

๐ŸŒ n8n Orchestration Pipeline

Webhook Trigger (POST from FastAPI)
        โ†“
Filter: HIGH or CRITICAL risk only
        โ†“
AbuseIPDB โ†’ VirusTotal โ†’ Cross-Correlation Engine
        โ†“
Score โ‰ฅ 75 โ†’ CONFIRMED THREAT  โ†’ block_recommended
Score โ‰ฅ 55 โ†’ HIGH CONFIDENCE   โ†’ watchlist_added
Score โ‰ฅ 30 โ†’ SUSPICIOUS        โ†’ monitoring_increased
Score < 30 โ†’ LOW RISK          โ†’ logged
        โ†“
POST /n8n/enrichment โ†’ FastAPI โ†’ Dashboard updated

Import n8n_workflow.json โ†’ add API keys in nodes โ†’ Activate.


๐Ÿ Adaptive Honeypot Profiles

Profile Detection Strategy Purpose
Scanner Single hit deny_fast Save resources
Script Kiddie Bot, wordlist deny_fast Immediate reject
Botnet Node Rapid, automated slow_response Tarpit attacker
Credential Stuffer Many user:pass fake_success Collect credentials
Targeted Human, specific fake_success Gather TTPs
APT Actor Slow, admin users full_fake_env Maximum intel

๐Ÿ“Š Training Dataset

Dataset Rows Type Source
CIC Honeynet 2023 13,767,678 Real network pcap (34 files) ciciot.unb.ca
AWS Honeypot 406,766 Cloud honeypot logs Kaggle
Dionaea Honeypot 27,529 Malware honeypot Kaggle
Hornet 40 8 locations ยท 40 days Geographic stats Mendeley
TOTAL 14,201,973 4 real-world sources

๐Ÿš€ Quick Start

Prerequisites

Python 3.10+   Node.js 18+   Docker Desktop   Git
Groq API key (free)   AbuseIPDB API key (free)   VirusTotal API key (free)

1. Clone

git clone https://github.com/YOUR_USERNAME/HoneyCloud-Sentinel.git
cd HoneyCloud-Sentinel

2. Python Environment

python -m venv venv
venv\Scripts\activate        # Windows
source venv/bin/activate     # Mac/Linux
pip install -r requirements.txt

3. Environment Variables

cp .env.example .env
GROQ_API_KEY=your-groq-key-here
ABUSEIPDB_API_KEY=your-abuseipdb-key-here
VIRUSTOTAL_API_KEY=your-virustotal-key-here
N8N_WEBHOOK_URL=http://localhost:5678/webhook/honeypot-attack

4. Start Infrastructure

docker-compose up -d    # Kafka + Zookeeper + n8n

5. Train ML Models

python -m scripts.extract_pcap_full     # Process CIC pcap files
python scripts/merge_datasets.py         # Merge all datasets
python scripts/train_all_models.py       # Train RF + IF + KMeans
python scripts/train_lstm.py             # Train LSTM predictor
python scripts/diagnose.py               # Verify all models loaded

6. Import n8n Workflow

1. Open http://localhost:5678
2. New Workflow โ†’ โ‹ฏ โ†’ Import from JSON โ†’ paste n8n_workflow.json
3. Open AbuseIPDB node โ†’ add API key in Header value
4. Open VirusTotal node โ†’ add API key in Header value
5. Save โ†’ Activate (green toggle)

7. Start Services

# Terminal 1 โ€” API
uvicorn api.threat_api:app --host 0.0.0.0 --port 8000

# Terminal 2 โ€” Dashboard
cd dashboard && npm install && npm run dev

# Terminal 3 โ€” Adaptive Honeypot
python -m honeypots.ssh_honeypot

8. Run Demo

python scripts/demo.py          # Full 5-phase demo (~3 min)
python scripts/demo.py --quick  # Quick 30-second demo

Open http://localhost:3000


๐Ÿง  ML Models

Random Forest โ€” Attack Classifier (9 Classes)

Class MITRE Technique Tactic Training Samples
Port Scan / Other T1046 Discovery 12,031,938
Web Exploit T1190 Initial Access 1,016,332
SSH Brute Force T1110.001 Credential Access 430,281
Database Attack T1078.001 Persistence 277,202
Telnet Attack T1021.004 Lateral Movement 194,055
DNS Attack T1071.004 Command & Control 128,538
SMB Attack T1021.002 Lateral Movement 81,510
FTP Attack T1071.002 Command & Control 31,248
Email Attack T1566.001 Initial Access 10,869

Isolation Forest โ€” Anomaly Detection

Trained on 14.2M samples (contamination=0.1). Detects zero-day attacks with no prior rules. Effective against novel attack patterns unseen in training.

K-Means Clustering โ€” Campaign Detection

8 clusters identifying coordinated botnets and APT campaigns across multiple IPs. Groups attacks by behavioral similarity patterns.

LSTM Neural Network โ€” Attack Prediction

Sequence length 10. Architecture: Embedding(16) โ†’ LSTM(64) โ†’ Dropout โ†’ LSTM(32) โ†’ Dropout โ†’ Dense(softmax). Outputs probability distribution across all 9 attack classes.

Risk Scorer โ€” 4-Tier Classification

Background noise (low attempts + low rate) โ†’ ๐ŸŸข LOW
Attack type weight + confidence + anomaly  โ†’ MEDIUM / HIGH / CRITICAL

๐ŸŒ API Endpoints

Method Endpoint Description
GET / API info
GET /health System health
POST /analyze Full ML pipeline analysis
GET /attacks Recent attacks (newest first)
GET /stats Aggregated statistics
GET /live SSE real-time attack stream
DELETE /attacks/clear Reset attack store
GET /mitre/heatmap ATT&CK tactic frequency
GET /mitre/detail/{type} Full MITRE entry
GET /investigations TI agent reports
POST /investigate Trigger AI investigation
GET /predict/next LSTM prediction
POST /predict/train Retrain LSTM
GET /report/html Visual HTML report
GET /report/generate Download PDF report
GET /intel/{ip} Manual threat intel lookup
GET /intel/stats/summary Enrichment statistics
POST /n8n/enrichment n8n callback receiver
GET /n8n/status n8n pipeline status
GET /honeypot/stats Adaptive honeypot stats

Interactive docs: http://localhost:8000/docs


๐Ÿ“ Project Structure

HoneyCloud-Sentinel/
โ”‚
โ”œโ”€โ”€ api/
โ”‚   โ”œโ”€โ”€ threat_api.py                # FastAPI โ€” 20 endpoints
โ”‚   โ””โ”€โ”€ attack_store.py              # Thread-safe attack + investigation store
โ”‚
โ”œโ”€โ”€ honeypots/
โ”‚   โ”œโ”€โ”€ ssh_honeypot.py              # Adaptive SSH honeypot
โ”‚   โ”œโ”€โ”€ behavioral_fingerprinter.py  # Tool detection + timing analysis
โ”‚   โ”œโ”€โ”€ attacker_profiler.py         # ML-based profile classifier
โ”‚   โ””โ”€โ”€ adaptive_response.py         # 4 deception strategy engines
โ”‚
โ”œโ”€โ”€ ml_models/
โ”‚   โ”œโ”€โ”€ feature_engineering.py       # 7-feature extractor
โ”‚   โ”œโ”€โ”€ anomaly_detection.py         # Isolation Forest
โ”‚   โ”œโ”€โ”€ attack_classifier.py         # Random Forest (9 classes)
โ”‚   โ”œโ”€โ”€ clustering.py                # K-Means (8 clusters)
โ”‚   โ”œโ”€โ”€ risk_scorer.py               # 0-100 risk scoring
โ”‚   โ””โ”€โ”€ PredictionEngine/
โ”‚       โ””โ”€โ”€ attack_predictor.py      # LSTM sequence predictor
โ”‚
โ”œโ”€โ”€ ai_agents/
โ”‚   โ”œโ”€โ”€ mitre_mapper.py              # MITRE ATT&CK mapping
โ”‚   โ”œโ”€โ”€ threat_intel_engine.py       # AbuseIPDB + VT + ML enrichment
โ”‚   โ”œโ”€โ”€ threat_intelligence_agent.py # 4-agent Groq pipeline
โ”‚   โ”œโ”€โ”€ threat_report_agent.py       # LLM report writer
โ”‚   โ”œโ”€โ”€ html_report_generator.py     # HTML report generator
โ”‚   โ””โ”€โ”€ pdf_generator.py             # PDF generator
โ”‚
โ”œโ”€โ”€ dashboard/                       # Next.js 14 frontend
โ”‚   โ”œโ”€โ”€ app/
โ”‚   โ”‚   โ”œโ”€โ”€ page.tsx                 # Main SOC dashboard
โ”‚   โ”‚   โ””โ”€โ”€ globals.css              # Dark military theme
โ”‚   โ””โ”€โ”€ components/
โ”‚       โ”œโ”€โ”€ Header.tsx               # n8n status + LIVE indicator
โ”‚       โ”œโ”€โ”€ StatCards.tsx            # Risk level stat cards
โ”‚       โ”œโ”€โ”€ AttackMap.tsx            # Leaflet map + LIVE/VIEW toggle
โ”‚       โ”œโ”€โ”€ Charts.tsx               # Attack type + country charts
โ”‚       โ”œโ”€โ”€ MitreHeatmap.tsx         # Interactive ATT&CK heatmap
โ”‚       โ”œโ”€โ”€ AttackFeed.tsx           # Clickable live attack feed
โ”‚       โ”œโ”€โ”€ InvestigationPanel.tsx   # 4-agent AI investigation
โ”‚       โ”œโ”€โ”€ ThreatIntelPanel.tsx     # Threat intel enrichment display
โ”‚       โ”œโ”€โ”€ PredictionPanel.tsx      # LSTM prediction engine
โ”‚       โ””โ”€โ”€ ReportButton.tsx         # HTML + PDF report buttons
โ”‚
โ”œโ”€โ”€ scripts/
โ”‚   โ”œโ”€โ”€ demo.py                      # 5-phase attack demonstration
โ”‚   โ”œโ”€โ”€ train_all_models.py          # Train RF + IF + KMeans
โ”‚   โ”œโ”€โ”€ train_lstm.py                # Train LSTM
โ”‚   โ”œโ”€โ”€ extract_pcap_test.py         # CIC Phase 2.1 test
โ”‚   โ”œโ”€โ”€ extract_pcap_full.py         # CIC Phase 2.2 full batch
โ”‚   โ”œโ”€โ”€ merge_datasets.py            # AWS + Dionaea merge
โ”‚   โ”œโ”€โ”€ merge_with_cic.py            # Add CIC test data
โ”‚   โ”œโ”€โ”€ merge_cic_full.py            # Final dataset merge
โ”‚   โ”œโ”€โ”€ fix_dionaea.py               # Fix corrupted CSV headers
โ”‚   โ””โ”€โ”€ diagnose.py                  # System health check
โ”‚
โ”œโ”€โ”€ datasets/
โ”‚   โ””โ”€โ”€ README.md                    # Dataset download links
โ”‚
โ”œโ”€โ”€ docs/
โ”‚   โ””โ”€โ”€ screenshots/                 # Dashboard screenshots
โ”‚
โ”œโ”€โ”€ logs/
โ”‚   โ””โ”€โ”€ ssh_adaptive.json            # Adaptive honeypot logs
โ”‚
โ”œโ”€โ”€ models/                          # Trained model files (.pkl, .keras)
โ”œโ”€โ”€ n8n_workflow.json                # Import directly into n8n
โ”œโ”€โ”€ docker-compose.yml               # Kafka + Zookeeper + n8n
โ”œโ”€โ”€ requirements.txt
โ”œโ”€โ”€ .env.example
โ””โ”€โ”€ README.md

๐ŸŽฌ Demo

Phase What Happens Risk Level
0 Background internet noise ๐ŸŸข LOW โ€” correctly filtered
1 Slow reconnaissance ๐ŸŸก MEDIUM โ€” port scan
2 Botnet wave โ€” 20 IPs ๐ŸŸ  HIGH โ€” campaign detected
3 APT โ€” multi-vector same IP ๐Ÿ”ด CRITICAL โ€” anomaly flagged
4 Mass flood โ€” 40 rapid attacks ๐Ÿ”ด CRITICAL โ€” feed scrolling
5 DB breach โ€” 3 simultaneous ๐Ÿ”ด CRITICAL โ€” MITRE T1078
python scripts/demo.py --quick   # 30 seconds
curl -X DELETE http://localhost:8000/attacks/clear   # reset

๐Ÿ” Ethical Considerations

  • Honeypots simulate vulnerable environments โ€” no real systems exposed
  • No offensive actions taken against attackers
  • Attack data anonymized in reports
  • API keys stored in .env โ€” never committed to repository
  • Complies with responsible cybersecurity research standards

๐Ÿ”ฎ Future Roadmap

  1. T-Pot Integration โ€” 20+ honeypot service types
  2. Global Honeypot Network โ€” multi-cloud deployment
  3. CERT-In Integration โ€” national threat signature sharing
  4. Shodan Enrichment โ€” exposed port data per attacker
  5. Automated Defense โ€” auto-update firewall from confirmed threats
  6. Full MITRE Coverage โ€” all 14 ATT&CK tactic categories

๐Ÿ› ๏ธ Tech Stack

Layer Technology Purpose
Honeypot Python sockets Adaptive SSH decoy
Streaming Apache Kafka 3.0 Event pipeline
Orchestration n8n Visual threat intel workflow
Backend Python 3.10, FastAPI 20 REST endpoints
ML Scikit-learn, TensorFlow 4 models, 14.2M samples
AI Investigation Groq API, Llama 3.3 70B On-demand 4-agent pipeline
Threat Intel AbuseIPDB, VirusTotal Live IP reputation
Frontend Next.js 14, Tailwind CSS SOC dashboard
Visualization Recharts, Leaflet Charts + world map
Reports ReportLab, HTML/CSS PDF + HTML generation
Containers Docker, Docker Compose Infrastructure
Framework MITRE ATT&CK Threat classification standard

๐Ÿ“ˆ Project Metrics

Training Records:      14,201,973
Datasets:              4
ML Models:             4
Attack Classes:        9
API Endpoints:         20
Deception Strategies:  4
Attacker Profiles:     6
Intel Sources:         3 (AbuseIPDB, VirusTotal, HoneyCloud ML)
n8n Workflow Nodes:    7
Dashboard Panels:      8

HoneyCloud Sentinel

Transforming attacker behavior into actionable cyber intelligence.

Built for the National Level Hackathon โ€” Blue Team Challenge

โญ Star this repo if you found it useful

About

team=hashBrownie

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages