🐝

HoneyBee Bash ::: Linux Autonomous System maintenance

         '\     /`
      ___  \___/  ___      HONEYBEE HIVEHUB
     /   \ (0 0) /   \     _________________________________
    |  M  |  X  |  M  |    AUTONOMOUS MAINTENANCE
    |_____/ @@@ \_____|    QUAD-TIERED RISK MITIGATION
            @@@@@          SIGNATURE + HEURISTIC + LLM
             @@@           _________________________________
              V            SCIKIT PANDA SECURITY RESEARCH
            

11 Distro's / 410 Rulesets / 272 Contributors

The hub for sharing HoneyBee configurations and rulesets.

DEBIAN
ARCH
REDHAT
SUSE
ALPINE
SLACKWARE
GENTOO
HiveHub

Welcome to HiveHub.

Here you will find the best datasets for Bee, built and optimized through community contributions. Datasets are organized by distribution and job type. Browse the various versions and import the dataset that fits your needs.

Select your distribution above to see the available job datasets, or continue with the default Debian jobs below.

Jobs for DEBIAN distro

default

1 version / 33 downloads

disk-health

1 version / 3 downloads

service-pulse

1 version / 5 downloads

system-info

1 version / 8 downloads

system-report

1 version / 1 download

zombie-hunt

1 version / 30 downloads
βœ… Your vote has been stored!

Latest entries

  • Redhat: zombie-hunt:default
  • Redhat: system-report:default
  • Suse: system-report:default
  • Redhat: system-info:default
  • Redhat: service-pulse:default

Ruleset catelog

  • Debian: report-status:default
  • Slackware: default:default
  • Debian: zombie-hunt:default
  • Redhat: system-info:default
  • Debian: docker-monitor:default
--register

🐝 Hive Hub contributing


To submit/share your rulesets registration is required to obtain a Hivehub key used to submit your export. This helps us to avoid uploaders impersonating trusted users or abusing the service.


Enter your email address below to register your email adress and obtain the api key for exporting.

Username:
EMail:


--privacy --security

🐝 HiveHub submission process


Rulesets contain true bash commands for detection. These rulesets cannot be executed by themself but Bee will apply them as rules. I find the process and contents of files a risk for my network and Bee users. Therefor i apply automated pre-filters and warning scanners as well as a final manual review by an operator to assure these files contain no configurations intended for harm, damage or unaccepted data handling.


Scanning and filtering

After initial risk scanning of submitted material our automated filter is applied to remove (most) user specific data (ip's, hostname's, key's, usernames) from the files though i leave general LAN IPs or system account names.
During manual review i strip out what the filter missed to assure a proper ruleset. This ruleset is then published on HiveHub becoming available to users for review and download.


Whitelisting for submissions

Sadly i cannot rely on good will to use Hive Hub within acceptable bounderies. For that reason i also rely on whitelisting of users.
Downloads (Bee --import's) require no registration. Do review before downloading. It is smart to know what you allow your Bee to execute.
Uploading a ruleset (bee --export) requires registration to allow placing the data on our servers.

bee --debug

[SYSTEM] Initializing HoneyBee Agent...

[HIVE] Status: Online (12 Bees Active)

[MODE] PERMISSIVE - Threat Score Threshold < 10%

βœ” Signature Check Passed

βœ” Heuristic Score: 10/10

[CMD] Executing: apt-get update && apt-get upgrade -y