Our friends over at BruteForce Labs decided to give us all a little present this holiday season. As I have spoke about on TekTip episodes in the past, BruteForce Labs has been working on a distro that combines many of the different honeypot projects and their addon modules. As Backtrack is to offense, and The Security Onion is to defense, HoneyDrive is the premiere honeypot distro.
HoneyDrive includes and is configured to run the following honeypots out of the box:
Kippo: Medium interaction SSH honeypot. Includes Kippo-Graph and Kippo2MySQL.
Honeyd: Low interaction flexible honeypot. Includes Honeyd2MySQL and Honeyd-Viz
Dionaea: Honeypot designed to collect malware and exploits.
Misc Honeypots: Sticky honeypot, Tiny honeypot, IIS Emulator (for Honeyd), InetSim, and SimH.
In addition to the honeypot software Honeydrive also includes a suite of tools for analysis, forensics, monitoring, and reverse engineering. Included in this list is our own tool Automater!