Repository navigation
t-pot
- Website
- Wikipedia
T-Pot to AbuseIPDB (beta).
The Web Attackmap currently in T-Pot CE is not half bad, but it's really not optimized for running 24/7 on a dashboard monitor etc. This is just that. Scraped, tuned, optimized for running on big screen TV 24/7. Made in NodeJS, supports connecting directly to tpotce-map_redis for fast implementation
T-Pot Attack Map that follows ES honeypot events within T-Pot and parses IPs, ports and honeypot info to visualize events in real time.
config for using Elastalert2 to alert to T-pot events
Publish actionable honeypot IOCs (IPs, URLs, hashes) from T-Pot into AlienVault OTX as Pulses. Runs on a separate VM with a persistent SSH tunnel to T-Pot’s Elasticsearch. Includes dedupe (no duplicate Pulses), configurable filters, and automated systemd timer publishing every 24h.