Homelab Bölüm 7: Snort IDS ve T-Pot Honeypot Telemetry

Part 6 ile Wazuh temelini kurmuştum. Bu bölümde detection ve deception katmanı ekledim: pfSense üzerinde Snort, HONEYPOT VLAN içinde T-Pot. Amacım sadece tool çalıştırmak değildi. Anlamlı telemetry üretmek, bunun Wazuh’a ulaştığını görmek ve event kaybolursa nerede kaybolduğunu anlayabilmek istedim. Ne İnşa Ettim? Snort: pfSense package, IDS mode Interfaces: WAN and LAN Rules: Community + focused ET Open categories Honeypot: T-Pot in VLAN 50 Telemetry: T-Pot Suricata eve.json -> Wazuh agent Test source: Kali in VLAN 40 ‹ › ...

2026-05-28 · 3 dk · plumy