implementing-network-deception-with-honeypots

mukul975/implementing-network-deception-with-honeypots · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.8 KB
  • 📁scripts
  • ⚙️agent.py 8.3 KB
  • 📄LICENSE 11.0 KB

Related

  1. processing-stix-taxii-feeds · mukul975 bundle
    Processes STIX 2.1 threat intelligence bundles from TAXII 2.1 servers, normalizing objects into platform-native schemas and routing them to consuming systems.
    24.6k
    repo stars
  2. building-threat-feed-aggregation-with-misp · mukul975 bundle
    Deploy MISP to aggregate, correlate, and distribute threat intelligence feeds from multiple sources for centralized IOC management and automated SIEM integration.
    24.6k
    repo stars
  3. detecting-ransomware-precursors-in-network · mukul975 bundle
    Detects early-stage ransomware indicators in network traffic before encryption begins, using Zeek, Suricata, Arkime, SIEM correlation rules, and threat intelligence feeds to identify Cobalt Strike beacons, Mimikatz signatures, and RDP brute-force attempts.
    24.6k
    repo stars
  4. performing-dynamic-analysis-with-any-run · mukul975 bundle
    Performs interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution behavior, interact with malware prompts, and capture process trees, network traffic, and system changes.
    24.6k
    repo stars
  5. implementing-endpoint-detection-with-wazuh · mukul975 bundle
    Deploy and configure Wazuh SIEM/XDR for endpoint detection including agent management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, and automated response actions.
    24.6k
    repo stars
  6. configuring-suricata-for-network-monitoring · mukul975 bundle
    Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for real-time network traffic inspection, threat detection, and integration with SIEM platforms.
    24.6k
    repo stars

Frequently asked questions

How do I install the implementing-network-deception-with-honeypots skill?

Run npx skillmds add mukul975/implementing-network-deception-with-honeypots in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the implementing-network-deception-with-honeypots skill do?

Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance. It is listed under Security, DevOps & Infra, Incident Response, Vulnerability Scanning on SkillMD.

Is implementing-network-deception-with-honeypots safe to use?

SkillMD's automated safety review verdict for this skill is PASS. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with implementing-network-deception-with-honeypots?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is implementing-network-deception-with-honeypots free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published implementing-network-deception-with-honeypots?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.