Limiting Exposure to Mass Scanners #1494
-
So, I went into the tpot.yml file and selected the honeypots I wanted to have active and which ports to be open to connection. However, the mass scanners out there such as nmap and online port scanners, list like 50+ ports being open on my machine, when I thought I only had 12? Has anyone found a work around for this and has an example on best practice to mitigate this unnecessary exposure to seem more legitimate? |
Beta Was this translation helpful? Give feedback.
Answered by
t3chn0m4g3
Mar 20, 2024
Replies: 1 comment 4 replies
-
You can activate the Blackhole feature. |
Beta Was this translation helpful? Give feedback.
4 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Then you need to disable
honeytrap
.