Welcome to the MITRE Honeyclient Project

A honeyclient is a dedicated host that drives specially instrumented applications to access remote servers to see if those servers are behaving in a malicious manner. Specifically, honeyclients can proactively detect exploits against client applications without known signatures.

The MITRE Honeyclient Project strives to educate the public about client application exploits and their attack mechanisms. This project is an open source framework, designed to create and manage implementations of Honeyclient systems.

Enjoy!
The MITRE Honeyclient Project Team

Added VM Hardening Guide

VMware has certainly improved its online resources for securing their product infrastructure, including high level explanations, white papers, and finally technical guides. However, VMware has yet to provide a central, definitive guide on what users can do to harden individual VMs by modifying the VM configuration file. Instead, users have to jump through various knowledge base articles and community posts to obtain them. As such, I've created a VM Hardening Guide which distills these settings that were published by VMware as well as by third party sources.


1.0.2 Released

Version 1.0.2 of the HoneyClient code has been released. New packages have been posted to the download page. You can also checkout the source code.

This release includes the following changes:

  • Real-time integrity checking (via a modified version of Capture-HPC)
  • Drone database / web service support - a Ruby on Rails application to keep track of malware and centralize URL processing across different honeyclients

(...)


Excellent articles on malicious webservers

Due to me not having posted in quite some time, I haven't mentioned this before, but back in August the Honeynet Project posted an excellent article about their findings related to searching for malicious webpages. Well, now they have released a followup article which deals specifically with the software used at some of these sites, which gives attackers rather advanced capability with very little difficulty. These are important reads to fully understand and appreciate the state of the art in browser-attacks.

Updated on 11/08/07 09:24:20

Older News...

Questions, comments, and/or suggestions?
Check our FAQ, User Guide, and issue list, to see if the topic has been addressed already.
If not, feel free to open a new ticket or email us directly at honeyclient@mitre.org.

Want to receive updates and/or talk about honeyclients?
We have a honeyclient mailing list that you can subscribe to.
There is also a discussion forum available if you would like to talk about honeyclients, client-side attacks, and honeyclient development.