honeypot-investigation

Analyze honeypot servers to identify attack patterns and generate executive security reports.

231|64|Updated Dec 16, 2025
One-click install
npx skills add https://github.com/SCStelz/security-investigator --skill honeypot-investigation
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: honeypot-investigation
Source: https://github.com/SCStelz/security-investigator/tree/main/.github/skills/honeypot-investigation
Command: npx skills add https://github.com/SCStelz/security-investigator --skill honeypot-investigation

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Honeypot environments are decoys that attract attackers and provide early visibility into attacker techniques and methods.

Core Features & Use Cases

  • Automated honeypot analysis: aggregates failed connections, inbound activity, and service usage to reveal attacker behavior.
  • Threat intelligence correlation: enriches attacker IPs with feeds, reputation, and threat context to prioritize responses.
  • Executive reporting: generates structured markdown reports suitable for leadership and incident response teams.

Quick Start

Run honeypot-investigation on a target honeypot (e.g., honeypot-server-01) for the last 48 hours to produce a comprehensive report.

Frequently Asked Questions about honeypot-investigation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I analyze honeypot attack patterns and generate an incident report?

Honeypot analysis aggregates failed connections, web activity, and IP enrichment to identify attack patterns and produce structured executive security reports for incident response teams.

What is the best way to map threat intelligence from honeypot servers?

Mapping threat intelligence from honeypot servers involves correlating attacker IPs with reputation feeds and threat context to prioritize responses and guide security analysis.

How do I prioritize threats using honeypot failed connection data?

Prioritizing threats from honeypot failed connection data requires aggregating inbound activity and enriching attacker IPs with threat intelligence feeds to rank response actions.

Can I use KQL for honeypot threat hunting and security analysis?

KQL supports honeypot threat hunting by querying network activity and failed connections to reveal attacker behavior and map security analysis for incident reporting.

Does honeypot investigation support parallel data collection for security analysis?

Honeypot investigation supports parallel data collection to aggregate web and network activity efficiently, enabling faster threat intelligence correlation and executive reporting.

When do I need to run a honeypot security analysis for executive reporting?

Run honeypot security analysis when you need to map threat intelligence, prioritize incident response, and deliver template-driven executive summaries from attacker behavior data.