mimicry: active deception in exploitation and post-exploitation

Mimicry

Mimicry is a security tool developed by Chaitin Technology for active deception in exploitation and post-exploitation.

Active deception can live to migrate the attacker to the honeypot without awareness. We can achieve a higher security level at a lower cost with Active deception.

Tool

Web-Deception – Fake vulnerabilities in web applications

Network Architecture

Webshell-Deception – live migrate webshell to the honeypot

Shell-Deception – live migrate ReverseShell/BindShell to the honeypot

Quick Start

1. Make sure docker, and docker-compose is installed correctly on the machine

docker info
docker-compose version

2. Install honeypot service

docker-compose build
docker-compose up -d

3. Deploy deception tool on other machines

update config.yaml,replace ${honeypot_public_ip} to the public IP of honeypot service

4. Perform Webshell deceiving

./mimicry-tools webshell -c config.yaml -t php -p webshell_path

Source: https://github.com/chaitin/

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply