Get in touch

Cybersecurity

Active

AEGIS Nexus — Honeypot and SOC analysis platform

Bilingual IT/EN honeypot and SOC analysis platform: it collects telemetry from isolated decoys, correlates it into sessions and investigations and turns it into reports, with data provenance as a founding principle.

  • Honeypot & SOC
  • Python
  • Suricata
  • MITRE ATT&CK
  • Docker
  • Flask

AEGIS Nexus is an evidence-first honeypot and SOC analysis platform: it runs deliberately limited decoy services (SSH, web, FTP, Telnet), collects their telemetry through authenticated channels and turns it into an investigation workflow. Attacker-supplied commands and payloads are never executed.

Principle: data provenance

Observed data, external enrichment, derived analysis and analyst hypotheses are kept separate. GeoIP, ASN, threat context, IOC extraction, MITRE ATT&CK mapping and CVE references are not presented as facts unless the stored evidence supports them.

Key features

  • Isolated SSH, web, FTP and Telnet decoys, with per-sensor secrets, signed telemetry and single-use request nonces.
  • A Flask/Gunicorn collector with bounded JSON ingestion, rate limits, hostile-input validation and SQLite persistence.
  • Session correlation by decoy connection ID or Suricata flow identity, with a temporal fallback.
  • SOC dashboard: global search, live feed, an attack map (from stored geolocation only), and views for IPs, countries, ASNs, ports, credentials, commands, payloads, IDS alerts, IOCs, MITRE/CVE and heatmaps.
  • Evidence-preserving case management: notes, tags, audit trail and JSON/CSV/ Markdown reports.
  • Offline GeoIP/ASN enrichment (MaxMind MMDB) and local threat context: captured indicators are never sent to third parties.
  • Native Suricata EVE JSON ingestion and optional, operator-only PCAP capture.

Architecture and hardening

Separate internal management networks, non-root containers with read-only filesystems, dropped capabilities, no-new-privileges, resource limits and a DOCKER-USER egress guard that blocks decoy-initiated connections. The SOC console binds to 127.0.0.1 by default.

Authorized use

Intended only for infrastructure you own or are explicitly authorized to monitor: a dedicated VM or VLAN, routes to production networks blocked, a defined purpose and retention. It does not automatically identify people, actors or campaigns. Source code licensed under GPL-3.0.