IMPORTANT LINK for deploying https://honeycloud-api.onrender.com/ https://primary-production-7b22f.up.railway.app/webhook-test/honeypot-attack https://primary-production-7b22f.up.railway.app/workflow/HhMmL8biG5nRdzvr https://railway.com/project/c7b84d25-36c5-4c30-93dd-65f477134d8b?environmentId=b689c01c-cb5d-48c7-a97d-d1dd7c7d128a https://cloud.redpanda.com/clusters
Turning attacker behavior into actionable cyber intelligence.
Trained on 14.2 Million Real-World Attack Records from 4 Honeypot Datasets
Features โข Architecture โข Screenshots โข Quick Start โข ML Models โข Datasets โข API โข n8n Workflow
HoneyCloud Sentinel is a production-grade cybersecurity platform that deploys AI-powered adaptive honeypots to attract, detect, analyze, and predict cyber attacks in real time.
The system captures attacker behavior through intelligent decoy services, streams attack data through Apache Kafka, runs four ML models trained on 14.2 million real attacks, enriches every HIGH/CRITICAL threat through an automated n8n intelligence pipeline, maps attacks to MITRE ATT&CK, and displays everything on a professional SOC-grade dashboard.
National Level Hackathon โ Blue Team Challenge Fully addresses all problem statement requirements: adaptive honeypots, ML threat detection, real-time visualization, threat intelligence provider collaboration, and AI orchestration framework (n8n).
- Behavioral Fingerprinter โ detects Hydra, Medusa, Nmap, Metasploit, Paramiko from client banners and timing
- 6 Attacker Profiles โ Scanner, Script Kiddie, Botnet Node, Credential Stuffer, Targeted, APT Actor
- 4 Deception Strategies โ deny fast / slow response (tarpit) / fake login / full fake environment
- Honeytoken Planting โ fake AWS credentials, SSH keys, deploy scripts trap APT actors
- Command Intelligence โ collects every command run in fake shell sessions
- Rich Kafka Telemetry โ behavioral data, profile, strategy all flow to dashboard
- Visual workflow โ Webhook โ Filter โ AbuseIPDB โ VirusTotal โ Cross-Correlation โ Decision โ Callback
- Processes every HIGH/CRITICAL attack automatically with no manual intervention
- Cross-correlates 3 independent sources into single Threat Intel Score (0โ100)
- Full audit trail in n8n Executions panel
- n8n status badge in dashboard header โ shows ACTIVE + processed count live
- AbuseIPDB โ community confidence score, abuse reports, ISP, Tor/VPN/Proxy detection
- VirusTotal โ 94 antivirus engine scan, reputation, categories
- HoneyCloud ML โ behavioral cross-correlation from 14.2M trained model
- Score breakdown โ AbuseIPDB (max 45) + VirusTotal (max 40) + ML (max 15) + corroboration bonus
- 4-tier output: CONFIRMED THREAT / HIGH CONFIDENCE / SUSPICIOUS / LOW RISK
- Evidence chain with numbered findings โ fully auditable
- SSH Honeypot โ captures brute force and credential attacks on port 2222
- Kafka streaming pipeline โ zero-latency attack log processing
- IP Geolocation โ maps every attacker to country and city in real time
- Server-Sent Events โ dashboard updates instantly without polling
- Risk Scorer โ background noise correctly scored LOW, real attacks escalated
- Isolation Forest โ detects zero-day anomalous attacks with no prior rules
- Random Forest โ classifies 9 attack types with confidence scores
- K-Means Clustering โ groups attacks into 8 coordinated campaign clusters
- LSTM Neural Network โ predicts next likely attack from sequence of 10
- Every attack auto-mapped to official MITRE technique ID and tactic
- Interactive heatmap showing which tactics are most active right now
- Clickable technique IDs open attack.mitre.org directly
- Covers 9 attack classes across 5 MITRE tactics
- Agent 1 โ Log Analyzer: extracts Indicators of Compromise
- Agent 2 โ Threat Investigator: identifies campaigns and actor types
- Agent 3 โ Risk Analyst: assesses business impact
- Agent 4 โ Response Recommender: 5 numbered executable actions
- Powered by Groq API (Llama 3.3 70B) โ on-demand only, rate limit safe
- Dark military-ops aesthetic โ JetBrains Mono + Rajdhani, cyan on #080c14
- Resizable world map โ drag handles for width and height
- LIVE / VIEW toggle on map โ LIVE shows attack lines, VIEW flies to attacker city
- Custom React popup cards โ no Leaflet white borders
- Clickable attack feed โ highlights row + updates map + opens investigation
- MITRE heatmap with drill-down to technique IDs
- LSTM prediction panel with probability distribution per class
- n8n status indicator in header
- One-click AI report (HTML + PDF)
- HTML report โ dark SOC theme, SVG risk gauge, bar charts, IoC section
- PDF download โ professional threat intelligence document
- LLM-written 7-section analysis including IoCs and campaign attribution
Internet Attackers
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ADAPTIVE HONEYPOT ENGINE โ
โ Behavioral Fingerprinter โ
โ Attacker Profiler (6 profiles) โ
โ Deception Strategy (4 strategies) โ
โ Honeytoken Planting โ
โโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Kafka: honeypot-attacks
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ APACHE KAFKA โ
โ High-throughput log streaming โ
โโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ML ENGINE (FastAPI) โ
โ Isolation Forest โ Random Forest โ
โ K-Means โ Risk Scorer โ MITRE Mapper โ
โโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโ
โ HIGH/CRITICAL โ All attacks
โผ โผ
โโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโ
โ n8n WORKFLOW โ โ ATTACK STORE โ
โ AbuseIPDB โ โ deque(200) โ
โ VirusTotal โ โ REST API โ
โ Cross-Correlate โ โโโโโโโโโโโฌโโโโโโโโโโโ
โ Callback API โ โ
โโโโโโโโโโโโโโโโโโโโโโโโ โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4-AGENT TI PIPELINE โ
โ (On-demand via Groq) โ
โโโโโโโโโโโโโโฌโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ SOC DASHBOARD (Next.js 14) โ
โ Map ยท MITRE Heatmap ยท Attack Feed โ
โ Investigation ยท Threat Intel ยท LSTM ยท Reports โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Webhook Trigger (POST from FastAPI)
โ
Filter: HIGH or CRITICAL risk only
โ
AbuseIPDB โ VirusTotal โ Cross-Correlation Engine
โ
Score โฅ 75 โ CONFIRMED THREAT โ block_recommended
Score โฅ 55 โ HIGH CONFIDENCE โ watchlist_added
Score โฅ 30 โ SUSPICIOUS โ monitoring_increased
Score < 30 โ LOW RISK โ logged
โ
POST /n8n/enrichment โ FastAPI โ Dashboard updated
Import n8n_workflow.json โ add API keys in nodes โ Activate.
| Profile | Detection | Strategy | Purpose |
|---|---|---|---|
| Scanner | Single hit | deny_fast |
Save resources |
| Script Kiddie | Bot, wordlist | deny_fast |
Immediate reject |
| Botnet Node | Rapid, automated | slow_response |
Tarpit attacker |
| Credential Stuffer | Many user:pass | fake_success |
Collect credentials |
| Targeted | Human, specific | fake_success |
Gather TTPs |
| APT Actor | Slow, admin users | full_fake_env |
Maximum intel |
| Dataset | Rows | Type | Source |
|---|---|---|---|
| CIC Honeynet 2023 | 13,767,678 | Real network pcap (34 files) | ciciot.unb.ca |
| AWS Honeypot | 406,766 | Cloud honeypot logs | Kaggle |
| Dionaea Honeypot | 27,529 | Malware honeypot | Kaggle |
| Hornet 40 | 8 locations ยท 40 days | Geographic stats | Mendeley |
| TOTAL | 14,201,973 | 4 real-world sources |
Python 3.10+ Node.js 18+ Docker Desktop Git
Groq API key (free) AbuseIPDB API key (free) VirusTotal API key (free)
git clone https://github.com/YOUR_USERNAME/HoneyCloud-Sentinel.git
cd HoneyCloud-Sentinelpython -m venv venv
venv\Scripts\activate # Windows
source venv/bin/activate # Mac/Linux
pip install -r requirements.txtcp .env.example .envGROQ_API_KEY=your-groq-key-here
ABUSEIPDB_API_KEY=your-abuseipdb-key-here
VIRUSTOTAL_API_KEY=your-virustotal-key-here
N8N_WEBHOOK_URL=http://localhost:5678/webhook/honeypot-attackdocker-compose up -d # Kafka + Zookeeper + n8npython -m scripts.extract_pcap_full # Process CIC pcap files
python scripts/merge_datasets.py # Merge all datasets
python scripts/train_all_models.py # Train RF + IF + KMeans
python scripts/train_lstm.py # Train LSTM predictor
python scripts/diagnose.py # Verify all models loaded1. Open http://localhost:5678
2. New Workflow โ โฏ โ Import from JSON โ paste n8n_workflow.json
3. Open AbuseIPDB node โ add API key in Header value
4. Open VirusTotal node โ add API key in Header value
5. Save โ Activate (green toggle)
# Terminal 1 โ API
uvicorn api.threat_api:app --host 0.0.0.0 --port 8000
# Terminal 2 โ Dashboard
cd dashboard && npm install && npm run dev
# Terminal 3 โ Adaptive Honeypot
python -m honeypots.ssh_honeypotpython scripts/demo.py # Full 5-phase demo (~3 min)
python scripts/demo.py --quick # Quick 30-second demo| Class | MITRE Technique | Tactic | Training Samples |
|---|---|---|---|
| Port Scan / Other | T1046 | Discovery | 12,031,938 |
| Web Exploit | T1190 | Initial Access | 1,016,332 |
| SSH Brute Force | T1110.001 | Credential Access | 430,281 |
| Database Attack | T1078.001 | Persistence | 277,202 |
| Telnet Attack | T1021.004 | Lateral Movement | 194,055 |
| DNS Attack | T1071.004 | Command & Control | 128,538 |
| SMB Attack | T1021.002 | Lateral Movement | 81,510 |
| FTP Attack | T1071.002 | Command & Control | 31,248 |
| Email Attack | T1566.001 | Initial Access | 10,869 |
Trained on 14.2M samples (contamination=0.1). Detects zero-day attacks with no prior rules. Effective against novel attack patterns unseen in training.
8 clusters identifying coordinated botnets and APT campaigns across multiple IPs. Groups attacks by behavioral similarity patterns.
Sequence length 10. Architecture: Embedding(16) โ LSTM(64) โ Dropout โ LSTM(32) โ Dropout โ Dense(softmax). Outputs probability distribution across all 9 attack classes.
Background noise (low attempts + low rate) โ ๐ข LOW
Attack type weight + confidence + anomaly โ MEDIUM / HIGH / CRITICAL
| Method | Endpoint | Description |
|---|---|---|
| GET | / |
API info |
| GET | /health |
System health |
| POST | /analyze |
Full ML pipeline analysis |
| GET | /attacks |
Recent attacks (newest first) |
| GET | /stats |
Aggregated statistics |
| GET | /live |
SSE real-time attack stream |
| DELETE | /attacks/clear |
Reset attack store |
| GET | /mitre/heatmap |
ATT&CK tactic frequency |
| GET | /mitre/detail/{type} |
Full MITRE entry |
| GET | /investigations |
TI agent reports |
| POST | /investigate |
Trigger AI investigation |
| GET | /predict/next |
LSTM prediction |
| POST | /predict/train |
Retrain LSTM |
| GET | /report/html |
Visual HTML report |
| GET | /report/generate |
Download PDF report |
| GET | /intel/{ip} |
Manual threat intel lookup |
| GET | /intel/stats/summary |
Enrichment statistics |
| POST | /n8n/enrichment |
n8n callback receiver |
| GET | /n8n/status |
n8n pipeline status |
| GET | /honeypot/stats |
Adaptive honeypot stats |
Interactive docs: http://localhost:8000/docs
HoneyCloud-Sentinel/
โ
โโโ api/
โ โโโ threat_api.py # FastAPI โ 20 endpoints
โ โโโ attack_store.py # Thread-safe attack + investigation store
โ
โโโ honeypots/
โ โโโ ssh_honeypot.py # Adaptive SSH honeypot
โ โโโ behavioral_fingerprinter.py # Tool detection + timing analysis
โ โโโ attacker_profiler.py # ML-based profile classifier
โ โโโ adaptive_response.py # 4 deception strategy engines
โ
โโโ ml_models/
โ โโโ feature_engineering.py # 7-feature extractor
โ โโโ anomaly_detection.py # Isolation Forest
โ โโโ attack_classifier.py # Random Forest (9 classes)
โ โโโ clustering.py # K-Means (8 clusters)
โ โโโ risk_scorer.py # 0-100 risk scoring
โ โโโ PredictionEngine/
โ โโโ attack_predictor.py # LSTM sequence predictor
โ
โโโ ai_agents/
โ โโโ mitre_mapper.py # MITRE ATT&CK mapping
โ โโโ threat_intel_engine.py # AbuseIPDB + VT + ML enrichment
โ โโโ threat_intelligence_agent.py # 4-agent Groq pipeline
โ โโโ threat_report_agent.py # LLM report writer
โ โโโ html_report_generator.py # HTML report generator
โ โโโ pdf_generator.py # PDF generator
โ
โโโ dashboard/ # Next.js 14 frontend
โ โโโ app/
โ โ โโโ page.tsx # Main SOC dashboard
โ โ โโโ globals.css # Dark military theme
โ โโโ components/
โ โโโ Header.tsx # n8n status + LIVE indicator
โ โโโ StatCards.tsx # Risk level stat cards
โ โโโ AttackMap.tsx # Leaflet map + LIVE/VIEW toggle
โ โโโ Charts.tsx # Attack type + country charts
โ โโโ MitreHeatmap.tsx # Interactive ATT&CK heatmap
โ โโโ AttackFeed.tsx # Clickable live attack feed
โ โโโ InvestigationPanel.tsx # 4-agent AI investigation
โ โโโ ThreatIntelPanel.tsx # Threat intel enrichment display
โ โโโ PredictionPanel.tsx # LSTM prediction engine
โ โโโ ReportButton.tsx # HTML + PDF report buttons
โ
โโโ scripts/
โ โโโ demo.py # 5-phase attack demonstration
โ โโโ train_all_models.py # Train RF + IF + KMeans
โ โโโ train_lstm.py # Train LSTM
โ โโโ extract_pcap_test.py # CIC Phase 2.1 test
โ โโโ extract_pcap_full.py # CIC Phase 2.2 full batch
โ โโโ merge_datasets.py # AWS + Dionaea merge
โ โโโ merge_with_cic.py # Add CIC test data
โ โโโ merge_cic_full.py # Final dataset merge
โ โโโ fix_dionaea.py # Fix corrupted CSV headers
โ โโโ diagnose.py # System health check
โ
โโโ datasets/
โ โโโ README.md # Dataset download links
โ
โโโ docs/
โ โโโ screenshots/ # Dashboard screenshots
โ
โโโ logs/
โ โโโ ssh_adaptive.json # Adaptive honeypot logs
โ
โโโ models/ # Trained model files (.pkl, .keras)
โโโ n8n_workflow.json # Import directly into n8n
โโโ docker-compose.yml # Kafka + Zookeeper + n8n
โโโ requirements.txt
โโโ .env.example
โโโ README.md
| Phase | What Happens | Risk Level |
|---|---|---|
| 0 | Background internet noise | ๐ข LOW โ correctly filtered |
| 1 | Slow reconnaissance | ๐ก MEDIUM โ port scan |
| 2 | Botnet wave โ 20 IPs | ๐ HIGH โ campaign detected |
| 3 | APT โ multi-vector same IP | ๐ด CRITICAL โ anomaly flagged |
| 4 | Mass flood โ 40 rapid attacks | ๐ด CRITICAL โ feed scrolling |
| 5 | DB breach โ 3 simultaneous | ๐ด CRITICAL โ MITRE T1078 |
python scripts/demo.py --quick # 30 seconds
curl -X DELETE http://localhost:8000/attacks/clear # reset- Honeypots simulate vulnerable environments โ no real systems exposed
- No offensive actions taken against attackers
- Attack data anonymized in reports
- API keys stored in
.envโ never committed to repository - Complies with responsible cybersecurity research standards
- T-Pot Integration โ 20+ honeypot service types
- Global Honeypot Network โ multi-cloud deployment
- CERT-In Integration โ national threat signature sharing
- Shodan Enrichment โ exposed port data per attacker
- Automated Defense โ auto-update firewall from confirmed threats
- Full MITRE Coverage โ all 14 ATT&CK tactic categories
| Layer | Technology | Purpose |
|---|---|---|
| Honeypot | Python sockets | Adaptive SSH decoy |
| Streaming | Apache Kafka 3.0 | Event pipeline |
| Orchestration | n8n | Visual threat intel workflow |
| Backend | Python 3.10, FastAPI | 20 REST endpoints |
| ML | Scikit-learn, TensorFlow | 4 models, 14.2M samples |
| AI Investigation | Groq API, Llama 3.3 70B | On-demand 4-agent pipeline |
| Threat Intel | AbuseIPDB, VirusTotal | Live IP reputation |
| Frontend | Next.js 14, Tailwind CSS | SOC dashboard |
| Visualization | Recharts, Leaflet | Charts + world map |
| Reports | ReportLab, HTML/CSS | PDF + HTML generation |
| Containers | Docker, Docker Compose | Infrastructure |
| Framework | MITRE ATT&CK | Threat classification standard |
Training Records: 14,201,973
Datasets: 4
ML Models: 4
Attack Classes: 9
API Endpoints: 20
Deception Strategies: 4
Attacker Profiles: 6
Intel Sources: 3 (AbuseIPDB, VirusTotal, HoneyCloud ML)
n8n Workflow Nodes: 7
Dashboard Panels: 8
HoneyCloud Sentinel
Transforming attacker behavior into actionable cyber intelligence.
Built for the National Level Hackathon โ Blue Team Challenge
โญ Star this repo if you found it useful
