AEGIS Nexus — Honeypot and SOC analysis platform
Bilingual IT/EN honeypot and SOC analysis platform: it collects telemetry from isolated decoys, correlates it into sessions and investigations and turns it into reports, with data provenance as a founding principle.
AEGIS Nexus is an evidence-first honeypot and SOC analysis platform: it runs deliberately limited decoy services (SSH, web, FTP, Telnet), collects their telemetry through authenticated channels and turns it into an investigation workflow. Attacker-supplied commands and payloads are never executed.
Principle: data provenance
Observed data, external enrichment, derived analysis and analyst hypotheses are kept separate. GeoIP, ASN, threat context, IOC extraction, MITRE ATT&CK mapping and CVE references are not presented as facts unless the stored evidence supports them.
Key features
- Isolated SSH, web, FTP and Telnet decoys, with per-sensor secrets, signed telemetry and single-use request nonces.
- A Flask/Gunicorn collector with bounded JSON ingestion, rate limits, hostile-input validation and SQLite persistence.
- Session correlation by decoy connection ID or Suricata flow identity, with a temporal fallback.
- SOC dashboard: global search, live feed, an attack map (from stored geolocation only), and views for IPs, countries, ASNs, ports, credentials, commands, payloads, IDS alerts, IOCs, MITRE/CVE and heatmaps.
- Evidence-preserving case management: notes, tags, audit trail and JSON/CSV/ Markdown reports.
- Offline GeoIP/ASN enrichment (MaxMind MMDB) and local threat context: captured indicators are never sent to third parties.
- Native Suricata EVE JSON ingestion and optional, operator-only PCAP capture.
Architecture and hardening
Separate internal management networks, non-root containers with read-only
filesystems, dropped capabilities, no-new-privileges, resource limits and a
DOCKER-USER egress guard that blocks decoy-initiated connections. The SOC
console binds to 127.0.0.1 by default.
Authorized use
Intended only for infrastructure you own or are explicitly authorized to monitor: a dedicated VM or VLAN, routes to production networks blocked, a defined purpose and retention. It does not automatically identify people, actors or campaigns. Source code licensed under GPL-3.0.