{"version":1,"type":"rich","provider_name":"Libsyn","provider_url":"https:\/\/www.libsyn.com","height":90,"width":600,"title":"7MS #730: Baby\u2019s First Project Swarm","description":"Hey friends! Still your grieving pal over here, but also your swarming friend and Protecting My Network Edge host \u2014 because this week I\u2019ve been tinkering with something called&amp;nbsp;Project Swarm&amp;nbsp;and I\u2019ve got my diapers on regarding it, but I really, really like what I see so far. Then, fair warning, I flip on the tangent light and verbally barf up some personal stuff at the end. I\u2019ll make the hand-off super clear, so if you want your free security podcast to do&amp;nbsp;exactly&amp;nbsp;what you want and nothing else \u2014 totally fair, and you won\u2019t offend me by hopping off. Here\u2019s what we cover:  What is Project Swarm?&amp;nbsp;This comes to us from our friends over at GreyNoise. It centers around little sensors you deploy to the edges of your network that you can dress up to look like just about anything \u2014 attracting flies to the honey, if you catch my drift. You get more enumeration, insight, and logging into whatever shenanigans those flies are using to poke at your edge. Setup was refreshingly easy:&amp;nbsp;You need a very low-powered VM or hardware device (my understanding is it even works on a Raspberry Pi) mapped to a public IP, plus a free GreyNoise account. You generate an API key, copy-paste a one-line install, and off it goes. I threw mine on a tiny Ubuntu VM. The part where I didn\u2019t read the flipping manual:&amp;nbsp;Mid-install my SSH connection dropped and I\u2019m going \u201cwhat the heck?!\u201d Turns out the installer intentionally moves your real SSH to some arbitrary high port \u2014 so you can run a fake SSH honeypot on 22 while your legit connection lives elsewhere. Once I spotted the new port in the console, a quick firewall tweak and I was back in. Profiles give me level 14 giggidies:&amp;nbsp;Once your sensor checks in, you assign it a profile. Vulnerable WordPress, Tomcat, a Cisco AnyConnect VPN, FTP honeypot, SSH honeypot \u2014 kind of all the honeypots. I went with a vulnerable WordPress instance. My one complaint: you can only assign one profile per sensor. My dream scenario of an SSH honeypot AND an FTP AND a vulnerable Tomcat all on one box will have to wait (or maybe that\u2019d look too suspicious and scare the baddies off \u2014 who knows). The results were wild:&amp;nbsp;Within a couple days I had&amp;nbsp;thousands&amp;nbsp;of connections, several flagged as malicious and tied to known botnets. I could see source IPs, malicious labels, whether they were residential or company or Google, and even download raw packet captures. There\u2019s clearly more telemetry to dig into (what people tried to spray into the login portal, etc.) \u2014 I meant to go deeper before recording and didn\u2019t, so consider this a \u201cto be continued.\u201d Why do I care, since I\u2019m not defending some huge infrastructure?&amp;nbsp;Honestly it started as a brain break. But I\u2019ve been testing a ton of external networks lately and nearly every company site is WordPress \u2014 which now powers around 43% of the internet. Running my own WordPress honeypot gives real oomph to those \u201cyour out-of-date WordPress&amp;nbsp;is&amp;nbsp;a big deal\u201d conversations, where I can say \u201cI run a WordPress honeypot and here\u2019s the aggressive password spraying and plugin\/theme enumeration I\u2019m seeing right now.\u201d See it, don\u2019t just hear it:&amp;nbsp;I show the actual portal, sensor config pages, and more over on&amp;nbsp;7MinSec.club&amp;nbsp;this week. Why not both, right? It\u2019s like that meme. GreyNoise also has a Project Swarm user webinar coming up \u2014 check their events page. And to be crystal clear: they are&amp;nbsp;not&amp;nbsp;a sponsor, this is all free, and I just think it\u2019s clever. Life update (the tangent portion):&amp;nbsp;About the time you hear this, I\u2019ll be on my way to my dad\u2019s funeral, where I\u2019m sharing some words and singing a song. I\u2019ve been practicing like a madman per advice from my music director friend and guitar teacher \u2014 including a little brain hack of focusing hard on my fingers to stay a half-step removed from the emotion. And if I cry my face off up there? Who cares. This isn\u2019t America\u2019s Got Talent; it\u2019s the gesture. I\u2019ll be honest, 2026 has been a&amp;nbsp;rough&amp;nbsp;one, but I promised two bright spots and here they are: my son Cam (about to finish paramedic school) has been keeping grandpa\u2019s spirit alive by wearing my dad\u2019s shirts, sunglasses, and Apple watch, and getting a Cessna tattoo with my dad\u2019s actual handwriting and birth year. And you all \u2014 the kind words, the offers to talk, the shared stories \u2014 reminded me there are a whole lot of good people out there. Thank you for that. One more thing on the horizon:&amp;nbsp;My brain\u2019s been a squirrel on pixie sticks, but for whatever reason I\u2019ve been happily grinding the&amp;nbsp;CARTP&amp;nbsp;as a little vacation for my mind. I might take a swing at the exam this week \u2014 start it in the evening, grind a few hours, sleep, finish in the morning (I\u2019m too old for 24 hours straight). I might pass, I might fail spectacularly. Either way I\u2019ll keep you posted, and if I get the cert, that\u2019s probably next week\u2019s topic!  ","author_name":"7 Minute Security","author_url":"https:\/\/7MinSec.com","html":"<iframe title=\"Libsyn Player\" style=\"border: none\" src=\"\/\/html5-player.libsyn.com\/embed\/episode\/id\/42037970\/height\/90\/theme\/custom\/thumbnail\/yes\/direction\/forward\/render-playlist\/no\/custom-color\/88AA3C\/\" height=\"90\" width=\"600\" scrolling=\"no\"  allowfullscreen webkitallowfullscreen mozallowfullscreen oallowfullscreen msallowfullscreen><\/iframe>","thumbnail_url":"https:\/\/assets.libsyn.com\/secure\/item\/42037970"}