{"repo":"straightchlorine/honeywatch","free":true,"listed":false,"github":"https://github.com/straightchlorine/honeywatch","clone":"git clone https://github.com/straightchlorine/honeywatch.git","description":"SSH honeypot with real-time attack visualization and threat analysis.","language":"Python","stars":12,"topics":["cowrie-honeypot","cowrie-ssh","dashboard","docker-compose","flask","honeypot","k8s","maxmind","ssh-honeypot","vue"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"Honeywatch SSH honeypot with attack visualization and threat analysis. Health Uptime (24h) ----------- :------: :------------: Dashboard API Architecture The honeypot VPS runs Cowrie, ingestor, Postgres, Flask API, and an internal nginx that binds only to the Headscale tailnet interface. Cowrie has no direct internet egress; outbound traffic is forced through a tinyproxy sidecar ( egress-proxy ). The dashboard routes /api/ through a Tailscale egress pod across the tailnet to the honeypot's nginx. All k8s manifests, including the ArgoCD Application , live in k8s/ . What It Does - Runs a Cowrie SSH honeypot that captures brute-force attempts - Captures SSH client intel: client HASSH, offered public-key fingerprints, and direct-tcpip (port-forward / relay) attempts for clustering and threat analysis - Ingests Cowrie's JSON event log into PostgreSQL - Analyses captured credentials: top username/password pairs, distributed-botnet IP fan-out, password length/charset composition, and Cowrie accept-rate - Serves a Vue 3 dashboard - Exposes a public read-only REST API (Flask + flask-smorest, OpenAPI 3.1) Running Locally Prerequisites: Docker, just, uv, pnpm 10.x. Dashboard development See justfile for the full command list. URLs - Dashboard: http://localhost:8080 - API: http://localhost:5000 (docs at /api/v1/swagger and /api/v1/redoc ) Attributions This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com.","default_branch":null,"files":null,"tree":[],"storefront":"/r/straightchlorine","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/straightchlorine/honeywatch/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}