Tier 1 (upstream images): telnet (cowrie), smtp (mailoney), elasticsearch (elasticpot), conpot (Modbus/S7/SNMP ICS). Tier 2 (custom asyncio honeypots): pop3, imap, mysql, mssql, redis, mongodb, postgres, ldap, vnc, docker_api, k8s, sip, mqtt, llmnr, snmp, tftp — each with Dockerfile, entrypoint, and protocol-accurate handshake/credential capture. Adds 256 pytest cases covering registration, compose fragments, LOG_TARGET propagation, and Dockerfile presence for all 25 services. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
27 lines
770 B
Python
27 lines
770 B
Python
from decnet.services.base import BaseService
|
|
|
|
|
|
class ConpotService(BaseService):
|
|
"""ICS/SCADA honeypot covering Modbus (502), SNMP (161 UDP), and HTTP (80).
|
|
|
|
Uses the official honeynet/conpot image which ships a default ICS profile
|
|
that emulates a Siemens S7-200 PLC.
|
|
"""
|
|
|
|
name = "conpot"
|
|
ports = [502, 161, 80]
|
|
default_image = "honeynet/conpot"
|
|
|
|
def compose_fragment(self, decky_name: str, log_target: str | None = None) -> dict:
|
|
return {
|
|
"image": "honeynet/conpot",
|
|
"container_name": f"{decky_name}-conpot",
|
|
"restart": "unless-stopped",
|
|
"environment": {
|
|
"CONPOT_TEMPLATE": "default",
|
|
},
|
|
}
|
|
|
|
def dockerfile_context(self):
|
|
return None
|