← projectsLive
/projects/shardlure
ShardLure
Attacker identity engine for SSH honeypot telemetry.
About
SSH honeypot that clusters bots by HASSH and username playbook instead of IP. Cowrie + journal ingest, intent classification, live globe dashboard, stealth persona with bait files, and STIX 2.1 IOC export.
Features
- 01Actor clustering by HASSH fingerprint + username taste profiles
- 027-provider IP enrichment (AbuseIPDB, VirusTotal, GreyNoise, Shodan)
- 03MalwareBazaar payload submission with auto-classification
- 04Live globe dashboard with real-time attack arcs
- 05Stealth persona with bait files and fake services
- 06STIX 2.1 IOC export for threat intelligence sharing
Stack
- Go
- Python
- SQLite
- Cowrie
- HASSH
- STIX
Enrichment Pipeline
1SSH session captured via Cowrie / journalctl
2HASSH fingerprint + username playbook extraction
37-provider IP enrichment (AbuseIPDB, VT, GreyNoise, Shodan...)
4Actor clustering and intent classification
5STIX 2.1 IOC export + globe dashboard