Respotter is an open source honeypot, designed to detect hackers when they activate Responder in your environment.

This application actively identifies Responder instances, exploiting its behavior when responding to any DNS query. Respotter leverages the LLMNR, mDNS, and NBNS protocols to query a non-existent hostname (default: Loremipsumdolorsitamet). If any of these requests receive a response, it is likely that Responder is running on your network.
Read more: LoadMaster vulnerability allows hackers to execute arbitrary code
Respotter has the ability to send webhooks to Slack, Teams , or Discord. Additionally, it supports sending events to a syslog server, making it easier to ingest them into a SIEM.

“I wanted to create a lightweight and enjoyable open source Responder Honeypot. Since I couldn’t find an ideal solution, I decided to write a script based on my efforts working with the Red-teaming team at Respotter. I designed it with specific features, and that was intentional,” Baden Erb, creator of Respotter, told Help Net Security.
Respotter, the open-source honeypot for detecting hackers, is available for free on GitHub.
Source: helpnetsecurity
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
