threat.gg-agent

command module
v0.0.0-...-61b1b2a Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: GPL-3.0 Imports: 50 Imported by: 0

README

threat.gg Agent

The honeypot agent for threat.gg, a honeypot-as-a-service platform for collecting and analyzing real-world attack data.

Overview

The agent is a Go binary that runs on honeypot nodes and emulates multiple network services. When attackers connect and interact with these fake services, the agent captures their activity (commands, credentials, payloads) and reports it to the threat.gg server via gRPC.

Supported Honeypots

Service Default Port Description
SSH 22 Captures brute-force credentials, shell commands, proxy requests, and malware drops
PostgreSQL 5432 Emulates a PostgreSQL server, captures authentication attempts and SQL queries
Microsoft SQL Server 1433 Emulates TDS 7.x, captures LOGIN7 credentials/client metadata and SQL batches
FTP 21 Captures FTP login attempts and file transfer commands
Elasticsearch 9200 Emulates an Elasticsearch REST API, captures search and index requests
HTTP 8080 Web server honeypot capturing HTTP request payloads
Kubernetes API 6443 Emulates the Kubernetes API server
Kubelet 10250 Emulates the node HTTPS API, including pods, metrics, logs, stats, and exec/run capture
Consul 8500 Emulates service discovery, health, KV, session, and ACL-token HTTP APIs
RabbitMQ / AMQP 5672 Negotiates AMQP 0-9-1, captures SASL credentials, topology, publish, and consume activity
Android Debug Bridge 5555 Emulates an authenticated Android device, shell services, and bounded sync uploads
OpenClaw 18789 WebSocket-based honeypot for custom protocol interactions
Kafka 9092 Emulates an Apache Kafka broker, captures client reconnaissance and SASL/PLAIN credentials
VNC 5900 Emulates VNC/RFB handshake and captures auth challenge-response + client preferences

Architecture

Each honeypot implements the honeypots.Honeypot interface (Start() + Name()) and is registered in main.go. Honeypots run concurrently as goroutines, listening on their respective ports.

Captured attack data is sent asynchronously to the threat.gg server via gRPC with TLS and API key authentication. The server stores the data in PostgreSQL and broadcasts events to the real-time dashboard feed via Redis pub/sub.

Building

make build        # Cross-compile static Linux binaries (amd64 + arm64)
make proto        # Regenerate protobuf code from the server's honeypot.proto
make test         # Run tests

Deployment

The agent binary is deployed to honeypot nodes at /root/honeypot and managed via systemd. An auto-updater checks GitHub Releases every 15 minutes for new versions (calver tags).

Configuration

Environment variables:

Variable Description Default
API_KEY API key for server authentication required
GO_ENV Set to development for local testing production
SSH_PORT SSH honeypot port 22
KAFKA_PORT Kafka honeypot port 9092
MSSQL_HONEYPOT_PORT Microsoft SQL Server honeypot port 1433
KUBELET_HONEYPOT_PORT Kubelet HTTPS honeypot port 10250
CONSUL_HONEYPOT_PORT Consul HTTP API honeypot port 8500
AMQP_HONEYPOT_PORT RabbitMQ-compatible AMQP honeypot port 5672
ADB_HONEYPOT_PORT Android Debug Bridge device honeypot port 5555

The MSSQL honeypot intentionally advertises ENCRYPT_NOT_SUP so it can observe LOGIN7 reconnaissance and reversibly obfuscated SQL-auth attempts. Run honeypot nodes on an isolated capture network; do not place legitimate credentials or production database traffic on the listener's network path.

Documentation

The Go Gopher

There is no documentation for this package.

Directories

Path Synopsis
Package adb emulates a bounded Android Debug Bridge device transport.
Package adb emulates a bounded Android Debug Bridge device transport.
Package amqp emulates bounded RabbitMQ-compatible AMQP 0-9-1 sessions and records AMQP 1.0 probes.
Package amqp emulates bounded RabbitMQ-compatible AMQP 0-9-1 sessions and records AMQP 1.0 probes.
Package cmdresp is the shared client side of the admin-editable command_responses override.
Package cmdresp is the shared client side of the admin-editable command_responses override.
Package consul emulates a bounded subset of the Consul HTTP API.
Package consul emulates a bounded subset of the Consul HTTP API.
ftp
Package icscore holds the pieces of an ICS/SCADA protocol honeypot that do not belong to any single protocol: deriving the per-attacker state key from a connection (RemoteHost), a bounded per-attacker-IP state map (Store), and the session/capture scaffolding a protocol emulator accumulates one connection's activity into before persisting it (Session).
Package icscore holds the pieces of an ICS/SCADA protocol honeypot that do not belong to any single protocol: deriving the per-attacker state key from a connection (RemoteHost), a bounded per-attacker-IP state map (Store), and the session/capture scaffolding a protocol emulator accumulates one connection's activity into before persisting it (Session).
Package icsprobe is a passive measurement instrument, not a honeypot: it binds otherwise-unused industrial-protocol ports, accepts a TCP connection, records the first bytes the client sends plus timing, and closes.
Package icsprobe is a passive measurement instrument, not a honeypot: it binds otherwise-unused industrial-protocol ports, accepts a TCP connection, records the first bytes the client sends plus timing, and closes.
internal
kubetls
Package kubetls creates self-signed server certificates for Kubernetes API and Kubelet personas.
Package kubetls creates self-signed server certificates for Kubernetes API and Kubelet personas.
Package kubelet emulates the authenticated HTTPS API exposed by a Kubernetes node agent.
Package kubelet emulates the authenticated HTTPS API exposed by a Kubernetes node agent.
Package llmcore holds the shared HTTP machinery for the LLM-serving honeypots (vLLM, Ollama, Ray, LocalAI, llama.cpp, ComfyUI, LM Studio): request capture with a body cap, JSON/error helpers, and the dynamic completion generators.
Package llmcore holds the shared HTTP machinery for the LLM-serving honeypots (vLLM, Ollama, Ray, LocalAI, llama.cpp, ComfyUI, LM Studio): request capture with a body cap, JSON/error helpers, and the dynamic completion generators.
promptrules
Package promptrules is the agent half of PRD 034's server-pushed LLM prompt-rule corpus: the allowlists, the load-time validator, the prompt normalization the matcher is contracted to use, and the immutable compiled bundle the inference path reads through an atomic.Pointer.
Package promptrules is the agent half of PRD 034's server-pushed LLM prompt-rule corpus: the allowlists, the load-time validator, the prompt normalization the matcher is contracted to use, and the immutable compiled bundle the inference path reads through an atomic.Pointer.
Package lmstudio emulates LM Studio 0.4.x on its signature port.
Package lmstudio emulates LM Studio 0.4.x on its signature port.
Package mcp is a honeypot that emulates an exposed, unauthenticated Model Context Protocol (MCP) server.
Package mcp is a honeypot that emulates an exposed, unauthenticated Model Context Protocol (MCP) server.
Package modbus emulates a Schneider Electric Modicon M221 logic controller (a TM221CE40T) speaking Modbus/TCP on port 502.
Package modbus emulates a Schneider Electric Modicon M221 logic controller (a TM221CE40T) speaking Modbus/TCP on port 502.
Package ollama emulates an exposed, unauthenticated Ollama server (default port 11434) — the port internet scanners hunt for reachable LLM inference, and by volume the busiest of the LLM-infra honeypots.
Package ollama emulates an exposed, unauthenticated Ollama server (default port 11434) — the port internet scanners hunt for reachable LLM inference, and by volume the busiest of the LLM-infra honeypots.
Package s3 emulates an exposed MinIO-compatible S3 service and captures enumeration, credential, object, and upload activity without storing objects.
Package s3 emulates an exposed MinIO-compatible S3 service and captures enumeration, credential, object, and upload activity without storing objects.
Package s7comm emulates a Siemens S7-300 class PLC speaking classic S7comm over TCP/102 (TPKT + ISO-COTP + S7 PDUs).
Package s7comm emulates a Siemens S7-300 class PLC speaking classic S7comm over TCP/102 (TPKT + ISO-COTP + S7 PDUs).
Package sqlai is the agent half of AI answers for the SQL honeypots: when to ask the server, how long to wait, how a session learns that AI is live, and making server text safe for the wire.
Package sqlai is the agent half of AI answers for the SQL honeypots: when to ask the server, how long to wait, how a session learns that AI is live, and making server text safe for the wire.
Package termsafe makes server-supplied text safe to write to an attacker's terminal: no colour or cursor control, no OSC (title/clipboard/hyperlink), no stray control bytes, and CRLF line endings the terminal expects.
Package termsafe makes server-supplied text safe to write to an attacker's terminal: no colour or cursor control, no OSC (title/clipboard/hyperlink), no stray control bytes, and CRLF line endings the terminal expects.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL