Phillipp

Phillipp

Hello,

I just published version 0.1.0 of Suspicidy. It aims to detect suspicious web requests made by crawlers.

It all started when I naively set up prometheus_ex and its companion package for Plug to have rich request metrics in Grafana. It was quickly filled up with random requests made by crawlers who searched for .env files, config files, database dumps, and even bitcoin wallets. In the end, it took my Prometheus server down after executing a rather complex query.

I set up some honeypots to collect all activities that are made from these crawlers and up to this point, collected almost 800 unique paths that were called by them.

Currently, Suspicidy only matches on these collected paths and tells you whether a given path is suspicious or not.

For the future, I would like to implement checks by certain patterns to gain a bit more coverage and maybe also check some other data like user-agent or request headers.

I also plan to publish my honeypot application and the collected data.

You can find Suspicidy here:
https://github.com/suspicidy/suspicidy

Not sure how helpful this will be in a real production environment where one could just ignore all request paths that are not defined by the application but it’s definitely a fun project.

Showing Posts 1 to 2

Phillipp

Phillipp OP

I just pushed my honeypot logs to a separate repository. In case someone wants to do any analysis on it.

https://github.com/suspicidy/dataset

Phillipp

Phillipp OP

I update the dataset every few days. If anyone does some analysis on it, please let me know, I am very interested in the results.

— All posts loaded —

Where Next? Top

Trending in Announcing Top

restlessronin
The repo is at GitHub - cyberchitta/openai_ex: Community maintained Elixir library for OpenAI API · GitHub. Docs are at OpenaiEx User Gu...
152 12366 136
New
type1fool
WebAuthnLiveComponent WebAuthnComponents See this post about renaming the package. Passwordless authentication for Phoenix LiveView app...
New
GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
woylie
I released Doggo, a collection of unstyled Phoenix components. https://github.com/woylie/doggo Features Unstyled Phoenix components....
New
ahamez
Hi everyone, I’ve been working on this protobuf library for 3 years. We use it in the company I work for, EasyMile, to communicate with ...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
kip
I’ll shortly be launching Text, a nascent text analysis library. Current functionality In this early version (not ready for prime time) ...
New

Other Trending Topics Top

budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New
KristerV
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
juhalehtonen
There has been a thread to discuss the Stack Overflow Developer Survey on this forum every year since 2018, so here’s yet another one for...
New
budgie
I love Elixir. It’s one of 2 programming languages I’ve ever fallen in love with. But I don’t use it anymore. Serverless was the promis...
New
Null-logic-0
What IDE or editor are you using for Elixir development? Personally, I use Zed, and I really like it, but sometimes I wish there were a ...
New
type1fool
I just stumbled on a newly redesigned elixir-lang.org. :tada: It looks like @Software_Mansion did the work, and I think it is generally a...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews