HoneyCreds - Network Credential Injection To Detect Responder And Other Network Poisoners

3 years ago 149
BOOK THIS SPACE FOR AD
ARTICLE AD


HoneyCreds network credential injection to detect responder and other network poisoners. 

Requirements

Requires Python 3.6+ (tested on Python 3.9)
smbprotocol
cffi
splunk-sdk

Installation

git clone https://github.com/Ben0xA/HoneyCreds.git
cd HoneyCreds
pip3 install -r requirements.txt

Running

Settings

It is advised that you change these settings to best suit your environment. Note: You can use an existing account, just change the password.

Change these in honeycreds.conf

Choose a legit looking username

def_username = 'honeycreds'

This can match your current Short Domain

Make this whatever you want. Note: HTTP requests will send this in plaintext

def_password = 'This is a honey cred account.'

The FQDN. Leave .local at the end.

The hostname that DOES NOT EXIST but looks legit.

def_hostname = 'HNECRD01'

The log file and location

def_logfile = 'honeycreds.log'

Ability to turn SMB or HTTP on or off. Set to "OFF" to turn off.

The time to pause in seconds between requests.

SMB_SLEEP = 5
HTTP_SLEEP = 12

HoneyCreds - Network Credential Injection To Detect Responder And Other Network Poisoners HoneyCreds - Network Credential Injection To Detect Responder And Other Network Poisoners Reviewed by Zion3R on 8:30 AM Rating: 5

Read Entire Article