Skip to content
/ ennorm Public

The Enrichment and Normalization tool for sofah

Notifications You must be signed in to change notification settings

sofahd/ennorm

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

30 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

SOFAH ENNORM Module

The ENrichment NORMalization (ENNORM) module is a pivotal component of the SOFAH (Speedy Open Framework for Automated Honeypot-development) framework, tasked with automating the configuration and deployment of honeypot services based on collected reconnaissance data. By analyzing and normalizing this data, ENNORM plays a critical role in tailoring the honeypot's behavior to effectively simulate real-world systems and attract potential attackers.

Overview

ENNORM enhances the SOFAH framework's adaptability and effectiveness by processing reconnaissance information to automatically generate configurations for various honeypot services, including API simulations, port spoofing, and more. This module ensures that the honeypots are dynamically configured to reflect the latest threat intelligence, making them more realistic and engaging for attackers.

Key Features

  • Data Normalization: Transforms raw reconnaissance data into a standardized format suitable for processing by other SOFAH services.
  • Configuration Generation: Automatically generates service configurations, including simulated APIs, open ports, and other network characteristics.
  • Integration with SOFAH Services: Seamlessly interacts with other components of the SOFAH framework, ensuring cohesive and automated deployment of the honeypot environment.

About

The Enrichment and Normalization tool for sofah

Resources

Stars

Watchers

Forks

Packages

No packages published