Overview
Imports HoneyLabs honeypot indicators (exploitation sources, CVE probers, malware infrastructure) into OpenCTI over TAXII 2.1, each linked to its captured evidence.
Imports evidence-backed indicators from HoneyLabs' own internet-facing honeypot sensors over TAXII 2.1: addresses that ran exploit or loader commands against the sensors, addresses probing specific CVEs (labelled with the CVE ids, paid plans), and the loader and command-and-control URLs extracted from captured payloads. Every indicator carries a confidence graded on observed activity and links to the captured evidence on honeylabs.net. Known research scanners are excluded, and indicators expire on their own as activity stops.