Loading...
KSI Digital

Threat Research

We run honeypot sensors, analyse what they capture in an isolated lab, and share vetted indicators of compromise with the security community.

How Our Research Works

Real attacks, captured and analysed, with the results shared openly

1

Capture

Two sensors run continuously: a WordPress bait with deliberately outdated plugins, behind a web application firewall that retains full request bodies, and a Cowrie SSH/Telnet honeypot that records the commands attackers run and keeps every file they download or upload.

2

Analyse

Samples are examined offline in an isolated lab on a separate machine, reset to a clean snapshot after every run. We record what a sample tries to do: the names it resolves and the addresses it reaches for.

3

Share

Vetted indicators go to community threat-intelligence platforms. Write-ups, indicator lists and detection rules (YARA, Suricata, Sigma) are published openly under CC BY 4.0.

Published Findings

Each finding has a write-up, an indicator list and detection rules in our public repository.

Published

"Ancient": a Linux IoT botnet with a custom ANCT C2 protocol

A botnet family captured by our Telnet honeypot that looks up its command-and-control (C2) server over DNS-over-TLS and uses its own ANCT protocol rather than Mirai's. We documented three versions of its dropper and confirmed the C2 server live in a single, controlled 10-minute session.

Published

RedTail: a reused SFTP client key links its web and SSH delivery

The same embedded ed25519 SSH client key appeared in RedTail's web dropper and in its SSH loader, tying both delivery vectors to one operator. Both were captured passively; no attacker system was contacted.

Published

PerlBot "Dred": a PBot-derived IRC DDoS bot and its C2

A Perl IRC flood bot dropped on our SSH honeypot. The sample and its download URL were already on public feeds, but its hard-coded IRC C2 server was not; we identified it from the sample's configuration and reported it.

Published

XorDDoS: the 15th C2 domain the public set was missing

Offline sandbox analysis of a XorDDoS sample uploaded to our SSH honeypot showed lookups for 15 C2 domains. Fourteen were already listed on ThreatFox; we reported the one that was not.

Where We Contribute

We share indicators on these community platforms as ksi_digital.

abuse.ch Community

ksi_digital

Our contributor profile across the abuse.ch platforms: ThreatFox, URLhaus and MalwareBazaar.

View public profile

ThreatFox

@ksi_digital

Command-and-control (C2) servers and domains.

View public profile

URLhaus

@ksi_digital

URLs serving malware payloads.

View public profile

MalwareBazaar

@ksi_digital

Malware samples captured by our sensors.

No public profile page

AbuseIPDB

ksi_digital

Addresses seen brute-forcing and logging in to our honeypot.

View public profile

SANS ISC DShield

ksi_digital

Sensor logs contributed to the SANS Internet Storm Center's DShield network.

No public profile page

Spamhaus Threat Intel Community

KSI Digital

IP addresses of command-and-control (C2) servers.

No public profile page

CrowdSec

Submitted

ksi-digital/cowrie

Our Security Engine shares attack signals with the CrowdSec network. A Hub collection for parsing Cowrie honeypot logs has been submitted and is awaiting review.

View submission

GitHub

ksi-digital

Write-ups, indicators and detection rules.

View on GitHub

Methodology and Ethics

How we handle what we capture

Capture over contact

Our sensors record what attackers send to them. We never connect to attacker infrastructure outside the lab, never reuse harvested credentials or keys, and never scan or probe third-party hosts.

Offline, isolated analysis

Samples are analysed only in an isolated lab with no route to any production network. Its egress is fail-closed through an encrypted tunnel: if the tunnel drops, nothing leaves.

C2 contact only when necessary

A command-and-control (C2) server is contacted only when necessary to confirm it is live, for a short, time-boxed window, with only that single destination reachable and all other traffic blocked.

No binaries published

We never publish malware binaries. Samples are referenced by SHA-256 hash, and scripts are defanged before publication.

Vetted, deduplicated indicators

Indicators are checked against existing feeds before submission, so we report what is new rather than duplicating others. Confidence reflects how each indicator was observed.

Corrections welcome

'Not found publicly' is not the same as 'novel'. We say when we have simply not located prior reporting, and we correct our work when we get something wrong.

Contact, Disclosure and Citation

Research contact

For questions about our findings, corrections, or related observations you would like to share, email us. You can also open an issue on the repository.

christophe@ksi-digital.comOpen an issue

Security contact

Our security contact details are published in a standard security.txt file (RFC 9116).

View security.txt

Citing our work

The repository includes a CITATION.cff file with citation details. Content is licensed CC BY 4.0, so you may reuse it with attribution.

View CITATION.cff