SSH Honeypot with Seccomp/AppArmor Confinement and ELK Monitoring
Published in , 2025
A secure SSH honeypot captures attack attempts on a fake SSH server, logs every connection and command, and is fully isolated with AppArmor and Seccomp protections. Brute-force attacks trigger real-time Telegram alerts, and all events are centralized and visualized using an ELK (Elasticsearch, Logstash, Kibana) stack running in Docker.
