/projects/shardlure

ShardLure

Attacker identity engine for SSH honeypot telemetry.

About

SSH honeypot that clusters bots by HASSH and username playbook instead of IP. Cowrie + journal ingest, intent classification, live globe dashboard, stealth persona with bait files, and STIX 2.1 IOC export.

Features

  1. 01Actor clustering by HASSH fingerprint + username taste profiles
  2. 027-provider IP enrichment (AbuseIPDB, VirusTotal, GreyNoise, Shodan)
  3. 03MalwareBazaar payload submission with auto-classification
  4. 04Live globe dashboard with real-time attack arcs
  5. 05Stealth persona with bait files and fake services
  6. 06STIX 2.1 IOC export for threat intelligence sharing

Stack

  • Go
  • Python
  • SQLite
  • Cowrie
  • HASSH
  • STIX

Enrichment Pipeline

1SSH session captured via Cowrie / journalctl
2HASSH fingerprint + username playbook extraction
37-provider IP enrichment (AbuseIPDB, VT, GreyNoise, Shodan...)
4Actor clustering and intent classification
5STIX 2.1 IOC export + globe dashboard