Methodology: kippo UHBS lab¶
UHBS: 4.2.2 · Graded ssh Low-Interaction decoy.
Quick 35.64 / F, full 35.64 / F.
Analyst trust notes¶
- Role: Classic Python/Twisted SSH cowrie predecessor with emulated filesystem; lab listens on 2222 with auto-generated host keys.
- Evidence primary sources:
full/SCORECARD.txt,full/report.json, this methodology, and the tutorial commands. - Air-gap / Safety: lab runs used
UHBS_AIRGAP_ATTESTED=1; still isolate honeypot networks in real deployments. - Not in scope: UHBS does not certify detection content packs, MITRE mappings, or production SIEM pipelines.
- Reading guide: READING-UHQS.md
Environment & containment¶
Labs use Docker network uhbs-lab with 127.0.0.1 host binds only. Module F uses source_root pointing at the cloned upstream tree under .local/labs/kippo.
Evidence hierarchy¶
full/SCORECARD.txt(human-readable proof)full/report.json(machine-readable)- This methodology (class, protocol scope, known limits)
- Tutorial commands (replication)
Quick runs are for iteration speed. Prefer full when publishing or comparing products.
What UHBS does not claim¶
Not a vulnerability assessment of every dependency CVE, not a guarantee of Internet engagement volume, not a SIEM content pack, and not an endorsement of the named open-source project.