Deceptive Elasticsearch cluster configuration catching unauthorized reconnaissance and data extraction
ElasticSearch

ElasticSearch honeypot dataset

I have uploaded a new ElasticSearch honeypot dataset. It appears there are a few individuals who are attempting to exploit a few 0days in ElasticSearch. All the more reason not

Key takeaways
  • Deception technology in distributed databases catches attackers during their initial reconnaissance phase.
  • Honey tokens inside index mappings provide zero-false-positive intrusion alerts.
  • Make your telemetry actively deceptive to raise adversary execution costs.

I have uploaded a new ElasticSearch honeypot dataset. It appears there are a few individuals who are attempting to exploit a few 0days in ElasticSearch. All the more reason not to expose non-battle hardened open source projects to the Internet.

https://github.com/lordappsec/datasets/blob/master/osint/ElasticHoney/elastichoney_logs.json