HoneyCreds network credential injection to detect responder and other network poisoners.
Requirements
smbprotocol
cffi
splunk-sdk
Installation
cd HoneyCreds
pip3 install -r requirements.txt
Running
Settings
It is advised that you change these settings to best suit your environment. Note: You can use an existing account, just change the password.
Change these in honeycreds.conf
Choose a legit looking username
This can match your current Short Domain
Make this whatever you want. Note: HTTP requests will send this in plaintext
The FQDN. Leave .local at the end.
The hostname that DOES NOT EXIST but looks legit.
The log file and location
Ability to turn SMB or HTTP on or off. Set to "OFF" to turn off.
The time to pause in seconds between requests.
HTTP_SLEEP = 12