Pwnypot HoneyClient

25 Sep 2012

Pwnypot is a High Interaction Client Honeypot. Despite other High-Interaction honeyClients which detect malicious servers based on system changes (file system and registery modifications, invoked/killed processes, …), Pwnypot uses a new approach. To accomplish this, Pwnypot uses exploit detection methods to detect drive-by downloads at exploitation stage and dump malware file. Using this approach, Pwnypot eliminates some limitations of current HoneyClients and improves the detection speed of High-Interaction client Honeypots.


Find Pwnypot here. </div>

This is imported from my old WP blog, some links might be broken, original post.