-
Notifications
You must be signed in to change notification settings - Fork 1.1k
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Tanner "Detection Type" shows only index, unknown and xss #1560
Comments
Please provide JSON examples from |
Based on the logs you provided everything works as expected. All the logs you provided indicate type |
Okey strange, do you know what could be the reason for this? Because I have also tried other attack techniques but tanner does not recognise them accordingly |
At this point I recommend to open an upstream issue with the developers of snare / tanner. Once this is a confirmed and subsequently fixed issue we can update snare / tanner accordingly. |
All right, thank you very much for your time. Could you find more than just XSS-Attacks or. would Tanner normaly detect more attack types? |
Successfully raise an issue
Before you post your issue make sure it has not been answered yet and provide⚠️ BASIC SUPPORT INFORMATION (as requested below) if you come to the conclusion it is a new issue.
root
)We happily take the time to improve T-Pot and take care of things, but we need you to take the time to create an issue that provides us with all the information we need.
~/install_tpot.log
, attach the log and highlight the errors.dps
)? VM is currently shut downsystemctl status tpot
)? VM is currently shut downHello everyone,
I have a quick question about the results of the Snare/Tanner Honeypot. On the Kibana dashboard, I see that the Tanner Sensor only detected XSS attacks, while categorizing the rest as index or unknown. However, when I analyzed the log data, I found that other attack techniques were also conducted on the honeypot. Do you know why this is happening?
I would greatly appreciate any feedback, as I am currently working on my bachelor's thesis and need to validate the results of the T-POT system. I am unsure why the results turned out this way. Maybe I did something wrong, but I didn't change anything besides the config file and added a custom Snare page for my use case. I also tried it with the default pages provided, same result. Any insights that I can include in my thesis would be extremely helpful.
Thank you very much in advance and a nice weekend!
The text was updated successfully, but these errors were encountered: