Back to Programs

Security

The Honeynet Project

Honeypots and Threat Intelligence R&D

backenddevopsdjangodockergojavascriptpythonweb

Participation history

11 GSoC years

2026

8 projects

Official year page

GreedyBear: Dashboard Modularization

This project aims to refactor GreedyBear's dashboard into a fully configuration-driven widget system, giving administrators the power to tailor the...

GreedyBear Injection Event Collector API

This project proposes a secure, scalable push-based API designed to transform GreedyBear into an open data sink for the global honeypot community....

IntelOwl: Integrating a Self-Deployed LLM Chatbot for Threat Intelligence

This project aims to transform how analysts interact with threat intelligence data in IntelOwl by introducing a conversational AI interface....

Hardening EventHorizon with OpenTelemetry and Bio Inspired Deception Across IoT Protocol Tarpits

EventHorizon is a multi protocol IoT tarpit framework designed to trap automated network scanners. However, its current static deception mechanisms...

Greedybear: Access payload files

The goal of this project is to improve GreedyBear’s threat intelligence capabilities by incorporating honeypot payload files received from T-Pot....

Expanding Artemis Coverage with Improved Discovery and Vulnerability Detection

Artemis currently requires all targets to go through the full discovery pipeline even when the HTTP endpoint is already known, lacks deep crawling...

IntelOwl: Integration Ecosystem & Connector Optimization

This project aims to harden IntelOwl's connector ecosystem - the critical egress layer for routing threat intelligence data by resolving Django ORM...

Improving the DICOMHawk Medical Honeypot: Profile-Driven Deception with Fingerprinting & Sandbox

DICOMHawk is an open-source honeypot that emulates a vulnerable DICOM medical imaging server to attract and log unauthorized access attempts. The...

2025

9 projects

Official year page

Extending the Artemis scanner

This project aims to enhance Artemis, a modular vulnerability scanner, by automating technology-specific scans, expanding vulnerability detection,...

IntelOwl Improvements: Analyzers and Integrations

This project aims to add more analyzers to Intelowl further enhancing it's capabilities and refactoring the old ones which are not working as per...

Improving the DICOMHawk medical honeypot

DICOMHawk is a honeypot system designed to emulate a vulnerable DICOM (Digital Imaging and Communications in Medicine) server, primarily to detect,...

Improving the SweetCam IP camera honeypot

Problem: IP cameras are frequent targets for cyberattacks due to their widespread use and often weak security. Current honeypots like SweetCam lack...

Alerting Module Enhancement: Standardization, Customization, and Improvements

This project aims to enhance BuffaLogs alerting system by integrating new alerters, standardizing configurations, and introducing advanced features...

Glutton : Refactoring protocol parsers originally written in Go into Spicy

The proposed project aims to develop Spicy-based protocol parsers for HTTP and DNS. Although Go is an efficient language used for system programming...

BuffaLogs: Developing BuffaCLI for Command-Line Management and BuffaWatch for Real-Time Log Tracking

BuffaLogs is a tool designed to detect anomalous login activities. However, it currently lacks real-time analysis of login data and only offers a web...

IntelOwl improvements: refactor analyzer tests

This project aims to improve the testing framework for IntelOwl analyzers by transitioning from the existing monkeypatch-based approach to a more...

Implementing Protocol Parsers for Glutton Using Spicy

This project addresses the challenge of enhancing Glutton's protocol parsing capabilities by implementing HTTP and DNS parsers using Spicy, a...

2024

9 projects

Official year page

New Analyzers for IntelOwl

With this, we're diving deep into data! The vibrant security-analysts user base of intel owl has an active fleet of in demand analyzers (around 50...

Extending The Artemis Scanner

The proposal aims to enhance Artemis' vulnerability detection capabilities while optimizing performance and providing a modern, accessible user...

Improving the Functionality of Honeyscanner: A Honeypot Vulnerability Analyzer.

My proposal aims to do several objectives in enhancing the Honeyscanner tool's effectiveness with network security assessments on honeypots. Firstly,...

ML-based web attack classification project for TANNER

The rise of sophisticated web attacks poses significant challenges to current detection mechanisms, often relying on traditional regex-based...

Proposal for New Documentation Site for IntelOwl and friends

This project aims to enhance the documentation infrastructure of IntelOwl by migrating from ReadTheDocs to Mkdocs and leveraging GitHub Pages for...

Improving the functionality of Honeyscanner: a honeypot vulnerability analyzer

I want to improve a Honeyscanner, which is a honeypot vulnerability analyzer. It automatically attacks a given honeypot, to determine if the honeypot...

Extending the DRAKVUF Sandbox analytic pipeline

This project aims at enhancing the current DRAKVUF Sandbox by: - extracting common TTPs and displaying them in accordance with the MITTRE ATT&CK...

Improve features for DNS and HTTP3 in mitmproxy

The projects' main focus is to debug and fix/improve various missing bits in DNS/HTTP3. Features implemented include adding support for DNS-over-TCP...

Improve the onboarding experience on mitmweb

I propose enhancing the visibility and user-friendliness of switching proxy modes and improving the local mode experience in `mitmweb`. To begin...

2023

6 projects

Official year page

Frontend Improvements for BuffaLogs, Intelowl.

I propose to improvising frontend for BuffaLogs, implementing graphs, maps for better data visualisations plus authentications using JWT. I would...

Honeyscanner: a vulnerability analysis tool for honeypots

A honeypot is a security resource that mimics a vulnerable system and is used to lure and trap cyber-attackers. Over the last decade, many...

Riotpot: improving the IoT/OT honeypot

I plan to enhance the RIoTPot by adding new emulated protocols (HTTPS, SFTP, SNMP). I also plan to increase RIoTPot's ability to evade being detected...

mitmproxy - transparent mode on Linux and OSx in Rust

The problem to solve is the implementation of a truly transparent mode on mitmproxy both in OSx and Linux (Issue #1261 unsolved since 2016). I plan...

Ochi usability improvements

Ochi project is used for presenting events in real-time which are generated by Glutton. The existing tool has limited functionality and will benefit...

Import / Export of HAR files addition to mitmproxy

My proposal aims to add HAR file support to mitmproxy. This will include the new feature in mitmproxy that allows users to import HAR files into the...

2022

6 projects

Official year page

Bridge Qiling with other static analysis software

My entire project aims to bridge Qiling with other static analysis software, thus providing users with high-level concepts like stack frame, CFG and...

RIoTPot: A Shapeshifting honeypot

# Advance Device Profiles --- To enhance RIoTPot with pre-set and custom device profiles. The profiles will be displayed using an interface that...

IntelOwl v4 improvements

Improve existing functionalities and add new ones to IntelOwl for release of v4. - Allow plugin secrets to be stored and managed from GUI #978 -...

QUIC Support in mitmproxy

mitmproxy is a superb tool for security and privacy forensics. It currently supports HTTP/1 and HTTP/2, but lacks support for QUIC and HTTP/3. This...

Creating Playbooks for IntelOwl

I propose working on a new component for IntelOwl this summer - Playbooks which would help people share and run automatically, the exact...

Intelowl Go Client

I propose making a robust Go client library for OSINT Threat Intelligence Platform IntelOwl that easily communicates with their API. The Intelowl Go...

2021

11 projects

Official year page

PcapMonkey Improvements

PcapMonkey provides an easy way to analyze .pcap using Suricata, Zeek, and Elastic SIEM. The goal of this proposal is to improve and enhance...

IntelOwl Connectors Manager and Integrations

IntelOwl is an Open Source Intelligence (OSINT) solution designed with the intent to help the community to get threat intelligence data about an...

RIoTPot - Honeypot for IOT/OT devices

A honeypot for IOT/OT protocols with a dynamic response system that records the attack data. A tool which can help securing IOT/OT infrastructure and...

Extending DRAKVUF by an I/O-emulation module in order to camouflage its sandbox nature

To be a reliable black-box malware analysis system DRAKVUF has to mitigate the observer effect, which can be accomplished by defeating...

IntelOwl Improvements

This project proposes a new, more robust way of verifying Analyzers’ configurations via strict rules through database models/serializers and a new...

New Rule Generation Technique & Make Quark Everywhere Among Security Open Source Projects

Quark-Engine is a rule-based android malware detection tool, However, as a contributor of both Quark and its side projects (quark-rule-generate,...

Cloning and compatibility improvements for Snare

I plan to work heavily on improving the cloning capabilities of Snare, modify and upgrade aiohttp to be compatible with Tanner (v3.7.4) and add...

Replacing the core library of Quark-Engine

In this proposal, I mainly focus on two dimensions provided by Quark-Engine, including resilience and performance. According to the mentor, there are...

Make mitmweb’s UI rich and easy to use

Mitmproxy provides a lot of features for debugging, testing, and penetration testing. Mitmproxy is already a really awesome tool at this moment, but...

Implementing Linux support in Drakvuf-Sandbox

Drakvuf-sandbox is a malware analysis tool that is used to analyze the behavior of the malware in a contained environment. It uses the Drakvuf engine...

A Stitch In Time (saves nine)

This proposal tackles several smaller/simpler challenges of the HosTaGe application. It focusses on addressing Logging, API Key Maintenance and...

2020

11 projects

Official year page

Improve cloning & serving functionality for Snare

In this project, my focus will be on improving the snare's ability to clone and serve the pages. Also, I will add support for serving pages with TLS....

libmicrovmi – full bindings to Xen and KVM

Today the VMI ecosystem is made of a multitude of applications, targeting one hypervisor or emulator, with their own semantic library, which makes...

Svmidbg: developing a Stealthy Hypervisor based VM Introspection Debugger

Svmidbg will be a debugger using virtual machine introspection (VMI) that tries to be stealthy by leveraging hypervisor technologies to create...

Improving the usability of mitmproxy with new features

I propose three independent projects that improve the usability of mitmproxy for new and existing users. The first project aims to improve the...

HosTaGe: a mobile honeypot

Adding new features including New Protocols Simulation and Systems Simulation. Also support for hpfeeds integration and use on Unrooted devices....

Analytical malware classification

The Cuckoo sandbox is currently undergoing a complete redesign and the goal of the project is to build a proof of concept module that uses an...

New Web Interface for IntelOwl & Adding New Analyzers

Intel Owl is an Open Source Intelligence, or OSINT solution to get threat intelligence data about a specific file, an IP or a domain from a single...

Expanding Clang-Tidy to include AUTOSAR compliance

Clang-tidy is one of the best linters for C++. It currently provides static analysis for several groups of checks, including Google and Android...

Tenjint Orchestration framework

Tenjint is a framework for VM Introspection developed in Python. The project aims at providing user with a Web API for the submission of samples to...

Enhance detection capabilities: Improve the MITRE ATT&CK coverage in Monkey by adding post-breach actions

As of now, Monkey covers 24 attack techniques from the MITRE ATT&CK matrix. This project aims at increasing the number of techniques by adding 11 new...

LibVMI as a Unikraft Application

Virtual Machine Introspection applications often execute on the same privilege level as the hypervisor, which can have disastrous security...

2019

9 projects

Official year page

Implementing behavioral analysis for Android

Being an open-source operating system, Android is more vulnerable to attacks. This project is about adding support for automated malware analysis of...

Operating-system fuzzing with a hypervisor

This project deals with extending DRAKVUF for fuzzing the operating system using hypervisor and libinjector in DRAKVUF. libinjector will be used to...

SSH Proxy for Cowrie

This project’s objective is to add an SSH proxy for the Cowrie (https://www.cowrie.org/) honeypot. Currently, Cowrie emulates an SSH server using...

Injecting function-calls to Linux through a hypervisor

This project is of type Improving an existing tool that includes cleaning up the existing codebase and adding the process injection support for Linux.

Adding (Updating) macOS support to Cuckoo SandBox

Cuckoo Sandbox is a malware analysis platform which performs basic static file analysis to in-depth dynamic analysis of binaries. Even though macOS...

Operating System Fuzzing With a Hypervisor: OSFuzz

Fuzzing has been a very useful technique to find bugs and vulnerabilities. Fuzzing operating systems however has been problematic when the operating...

Heralding: RDP and VNC implementation

Heralding is essentially a credentials Honeypot. It can log credentials(username & password) for many protocols, but some protocols do not transmit...

Adding Privilege escalation functionality to the monkey

New non-destructive privilege escalation exploits likerunc container escape (CVE-2019-5736) and Dirty sock (CVE-2019-7304) and Dirty cow ...

SNARE/TANNER: Improvements

The aim is of the project is to improve SNARE/TANNER over the summer. The major goals of the project are - Implement new emulators to support...

2018

17 projects

Official year page

Honeypot Detection Tool

The goal of this project is to create a tool that can scan a system for features which would let an attacker know prematurely it is a honeypot. This...

SNARE/TANNER

SNARE is a web application honeypot sensor attracting all sort of maliciousness from the Internet. The web page is generated by cloning a real web...

Google Protocol Buffers Serialization

The basic idea behind the project is to shift mitmproxy serialization process to a new, clean standard format. Using Google Protocol Buffers will...

Semi-automated DroidBot: Semi-automated Android UI testing

The solution will consist of an Android app, that will read the input provided by the user, and generate an interaction model, which can be read by...

Implementing Yara rules in Honeytrap

Yara is a pattern-matching DSL developed to describe malware families; in this project, it is used to describe malicious actors interacting with a...

LibVMI extensions: Bareflank hypervisor support

Hypervisor (Virtual Machine Monitor) is a software that runs one or more virtual machines. Other than virtualization in cloud, they are also used in...

Droidbot with AI

The major task to be tackled in this project is to increase the code coverage using AI. Currently droidbot performs black box testing using the GUI...

DRAKVUF - Stealthiness Improvement

DRAKVUF (https://drakvuf.com) is an agent-less and virtualization based black-box binary analysis system. It allows users to analyze any binaries and...

Port LibVMI to Xen MiniOS

In this project, the core functionalities of the LibVMI will be ported to Xen MiniOS. After ported, Xen MiniOS will have the basic capabilities of...

#9 - DRAKVUF: Support for Dynamic Malware Analysis on ARM

The relevance of ARM processors is rising. Especially since ARM recently started targeting the servers and desktop market, thus going beyond the...

Thug: Python 3 Port and PyV8 Replacement

Thug is a Python low-interaction honeyclient aimed at mimicking the behavior of a web browser in order to detect and emulate malicious contents. This...

Automated Malware Relationship Mining

Since last year, Holmes-Processing has acquired a large dataset of labeled malware samples, which can be used for deep learning based malware...

DRAKVUF : Process Injector Enhancement

DRAKVUF allows to inject a binary directly into a running virtual machine. The current implementation uses either CreateProcessA() or ShellExecuteA()...

#15 - CONPOT: Protocols Wave #2

Conpot is an ICS/SCADA honeypot that supports a number of industrial protocols and environments. For Conpot to emulate industrial devices better,...

Trusted Execution Environment Based Dynamic Analysis on ARM

The purpose of this project is to constructure a monitor (like eBPF in the latest version linux kernel) in the “secure world” which can collect...

Mitmproxy improvements

There is one big and very interesting task. I need to Implement DSL for commands. Current implementation of Mitmproxy commands fulfills its duties,...

New exploiters in Infection Monkey

New non-destructive vulnerabilites Oracle WebLogic vulnerability (CVE-2017-10271) and Struts RCE vulnerability (S2-045) will be added to Infection...

2017

12 projects

Official year page

Android Sandbox Detection and Countermeasure Proposal

Many Android apps are using sandbox-detection techniques, and here is an example. To make things worse, there are malware using the sandbox-detection...

Conpot improvements

Conpot is a honeypot that handles a number of protocols (including IPMI, SNMP, BACnet, modbus and s7comm), which are usually used in industrial...

Automated Malware Relationships Detection Tool

The increase in volume and diversity of malware attacks has created a difficult situation for security analysts. Now more than ever, automatic...

Protocol and adversary identification in Go

When a client is connecting to a honeypot server, it is usually not legitimate traffic. However, as malware is always trying to be stealthy, the...

Glutton Enhancement

Author of glutton have proposed some new functionalities to be added in Glutton, like: Spawn Containers Support of YARA I will make code for those...

Proposal to the Honeynet Project.

Hello! Eventually it happened! I am happy to present you my final version of proposal. I have worked on it for last 2 weeks. I did all I could to...

Mitmweb Improve

Mitmweb is now shipped with our releases, supporting most of the fundamental features. However, some important features have not been brought to...

SNARE/TANNER

SNARE is a web application honeypot sensor attracting all sort of maliciousness from the Internet. The web page is generated by cloning a real web...

Holmes Framework to Automate Advanced Analytics

In this project I will design and develop a semi-generic interface that enables Holmes Processing to manage the execution of advanced statistical and...

Building examples services for Holmes processing

Holmes processing is a platform for large scale malware analysis. To allow for scaling and performance gains, this has required multiple techniques...

Long term analysis

Integrating the existing Longcuckoo into the latest version of Cuckoo Sandbox so that Cuckoo Sandbox long term analysis will be available to all...

Mitmproxy Core

Project type Improve existing tool Project goal Spend the summer working on mitmproxy's core and its addons! Improving mitmproxy. Adding various...

2016

11 projects

Official year page

Foundations for DRAKVUF on ARM

Dynamic malware analysis techniques assist to fully understand the cause, intention, and extent of damage caused by malicious applications....

Improving mitmproxy

Improve mitmproxy by adding features like SQLite based flow storage, TCPflows etc. and Port pathod & mitmproxy to Python 3.

Rumal Dennis Parchkov

Rumal's aim is to present visually the result from Thug, a tool for studying exploit kits. The currently available version requires some tweaks to...

Context based fuzzy clustering of malware

CuckooML will deliver a mechanism to find similarities between malware through analysing reports about them. Additionally, the software will be able...

Integrate DroidBOT into Cuckoo Sandbox

Cuckcoo Sandbox is an extensible automated malware analysis tool written in Python. Although Cuckcoo Sandbox begins supporting Android OS since v2.0,...

Centralized Service Configuration for Holmes

Holmes Processing (http://holmesprocessing.github.io) is a system used for automated malware analysis of huge volumes of malware samples, which...

Improving the coverage of DroidBot

DroidBot is an Android application exerciser like Monkey. It is better than Monkey in malware detection because it is aware of the static information...

YAPDNS

Collect Passive DNS data from various sources; display, correlate and analyze them.

Web Interface and Generic API Development for Holmes Processing

The Holmes Project is a modern, modular, and scalable environment for collaborative malware analysis and storage. Despite the relatively young age of...

[MITMProxy] Clemens Brunner

MITMproxy is a console tool that allows interactive examination and modification of HTTP traffic. The aim of this project is to improve the...

Vulnerability emulation for SNARE and TANNER

SNARE is a web application honeypot sensor attracting all sort of maliciousness from the Internet. The web page is generated by cloning a real web...