Honeypot and Packet Capture Using Wireshark and tcpdump

In addition to performing penetration tests, some organizations choose to run wargame exercises that pit teams of security professionals against each other in a cyber defense scenario. These exercises are typically performed in simulated environments,rather than on production networks, and seek to improve the skills of security professionals on both sides by exposing them to the
tools and techniques used by attackers.

Three teams are involved inmost cybersecurity wargames:

The red team plays the role of the attacker and uses reconnaissance and exploitation tools to attempt to gain access to the protected network. The red team’s work is similar to that of the testers during a penetration test.

The blue team is responsible for securing the targeted environment and keeping the red team out by building, maintaining, and monitoring a comprehensive set of security controls.

The white team coordinates the exercise and serves as referees, arbitrating disputes between the team, maintaining the technical environment, and monitoring the results. Cybersecurity wargames can be an effective way to educate security professionals on modern attack and defense tactics

There's a free Honeypot software called HoneyBot that you could install on a Windows machine. Just follow the HoneyBot installation wizard.

You can customize the Honeypot settings by clicking Options (two gear icons).

You can also edit the Services (ports) run by the Honeypot by going to View > Services.

You'll need to start the Honeypot service by going to File > Start. Or just click the Start (play) icon.

Click Allow access on Windows Firewall pop-up in order to allow the opened services or ports on the honeypot.

You can test the Honeypot ( by scanning for opened ports or services using Nmap (or Zenmap) on Kali Linux ( The Nmap scan took several minutes to finish.

You can run Wireshark in Kali Linux by going to Applications > 09 - Sniffing & Spoofing > wireshark.

Double-click on eth0 to start the packet capture.

Open Firefox ESR in Kali Linux and type I’ve enabled IIS and temporarily disabled Windows Firewall in my Windows 7 virtual machine.

Click Stop (red square icon) to stop the packet capture.  Type http on the search or filter bar to only display HTTP traffic. Expand the Hypertext Transfer Protocol to see the HTTP response.

Telnet is an insecure management protocol which sends packets in clear text. It's recommended to use secure management protocol such as SSH. I tried to Telnet to a Cisco device R2 and run Wireshark to perform a packet capture.

Go to Analyze > Follow > TCP Stream in order to display the detailed packet information.

Notice the Telnet password of cisco is displayed in the output.

You can also run a tcpdump in Kali Linux terminal using the tcpdump -i eth0 command.

