seedata.io DOCS
  • Welcome
  • Getting Started
    • What is seedata.io?
    • Core Concepts
    • Quick Start
    • Get Help
    • Subscriptions
  • Features
    • Dashboard
    • Alerts
    • Integrations
      • AWS
      • Webhook
    • Deployments
    • Seeds
      • Email
      • URL
      • Person
      • Microsoft Document (XLSX, DOCX)
      • PDF Document
      • HTML Page
      • SVG Image
      • AWS Credential
      • Virtual Machine Honeypot
      • EC2 Honeypot
    • Events
    • Intel
    • Settings
      • Whitelists
      • Users & Tokens
      • Profiles
  • Tutorials
    • Managing your alerts
      • Webhook
      • Webforms
      • Teams
      • Syslog
      • Slack
      • ServiceNow
      • Jira
      • Email
      • Elasticsearch
      • Datadog
    • Registering for a new account
    • Planting a VM honeypot seed
    • Preparing a VM Honeypot host
    • Planting an EC2 honeypot seed
    • Planting AWS Serverless Seeds
  • API reference
    • Activities
    • Api tokens
    • Copilot
      • Assessment
    • Data widgets
    • Deployments
    • Events
      • Next
      • Previous
      • Alert
      • Journal
    • Integrations
    • Intel
    • Notification recipients
      • Test
    • Seeds
      • Bulk
      • Retire
      • Test
      • Next
      • Previous
    • Stats
    • Whitelisted sources
Powered by GitBook
On this page
  • Format
  • Capabilities
  • Usage

Was this helpful?

  1. Features
  2. Seeds

EC2 Honeypot

Format

Amazon EC2 instance configured as a honeypot, designed to detect and log malicious activity. Issued as a CloudFormation script to install our image within your tenant, with configuration to select a personality from the following options:

- Windows server 2016 - ports 135, 139, 445, 3389

- Windows 10 workstation - ports 80, 137, 138, 443, 445, 3389, 5353

- Microsoft Active Directory Domain Controller 2019 - ports 21, 53, 69, 88, 135, 139, 389, 445, 464, 636, 3268, 3269, 3389

- Linux 5.0 - ports 22, 80, 443

- Printer - ports 80, 443, 515, 631, 9100

- FreeNAS storage device - ports 139, 445

- Siemens Simatic S7-300 PLC - port 102

- Cisco Catalyst 2950 Switch - port 22

Capabilities

  1. Activity Logging: Continuous logging and monitoring of all interactions with the EC2 honeypot, the seedata.io platform raises an event each time the EC2 honeypot is accessed. Each event includes detailed threat analysis of the accessing entity and their activities.

Usage

Deploy our EC2 honeypots within your AWS environment to attract and detect malicious actors, providing early warning and detailed insights into attack methods.

PreviousVirtual Machine HoneypotNextEvents

Last updated 7 months ago

Was this helpful?