By Forewarned in Releases on July 26, 2026
Chapel Hill, NC. July 26th 2026 – Forewarned Inc. announces an updated version of the successful STINGAR platform.
The STINGAR v2.4 release builds on the v2.3 platform and further strengthens how higher education and research networks turn honeypot sessions into actionable defense. This update extends IDS/IPS rules generation to Zeek and modern TLS client fingerprints, hardens honeypot sensors against fingerprinting, and broadens where STINGAR can be installed—incorporating feedback from our 80+ partners and continuing to improve capture, analysis, and maintenance of threat intelligence data.
The STINGAR Version 2.4 platform contains the following updates:
IDS/IPS Rules — Zeek and JA4/JA4H – Security teams can now generate Zeek notice-policy scripts alongside Suricata and Snort rules from honeypot session data. A new Zeek tab and export produce a self-contained `stingar-honeypot.zeek` script, with the same background job and feed workflow used for Suricata and Snort (`GET /api/v2/ids-rules/feed?format=zeek`). Rule generation adds JA4 and JA4H and other Foxio fingerprint support next to existing HASSH and JA3 coverage, so defenders can cluster scanner activity across TLS and HTTP clients. HTTP honeypot deployments default to publishing HTTPS on port 443 to improve TLS fingerprint capture. Updated user, API, and OpenAPI documentation covers the new formats.
Honeypot de-fingerprinting and TLS capture – The v2.4 honeypot images make sensors harder for ICS and SSH scanners to identify as honeypots. Conpot presents per-sensor identities, more realistic S7 and industrial protocol responses, and a new HTTPS listener with TLS client fingerprint capture (JA3/JA4) and JA4H. SSH honeypots remove default honeypot tells with per-sensor hostname, OS profile, filesystem, and credential databases. Identities are generated on container start so a fleet shows a believable spread of devices rather than one shared default.
Docker and Podman deployment – Honeypot deployment automatically selects Docker on Debian/Ubuntu sensor hosts and Podman on RedHat-family hosts (including RHEL, Rocky, AlmaLinux, and Oracle Linux), with no manual UI change required. The STINGAR server can be installed on RedHat-family Linux using Podman and native `podman compose`, with an OS-aware quickstart installer and updated installation documentation. Existing Docker-based admin and sensor installs continue to work as before.
LDAP / Active Directory login – Institutions can enable directory-backed login over LDAPS. When LDAP is enabled, the login page offers an LDAP Login option alongside local Login. LDAP settings are configurable in the environment and under Settings, including Active Directory via `sAMAccountName`.
Honeypot deployment management – Operators can delete honeypot deployments from the Manage Honeypots UI (with confirmation), in addition to existing start and stop controls.
Reliability and platform hardening – Further stability fixes addressed for ICS protocol honeypots and scanner-driven traceback storms that could take sensors offline. Honeypot deploy and teardown now work reliably with current Ansible Docker Compose v2 modules. New HP App Store honeypot templates also available, with both TCP & UDP services publish with the correct Compose port syntax.
The update is free to all existing licensees of the STINGARv2 platform and is backward compatible with v2.3.x. Upgrading requires updating docker-compose (or the quickstart compose wrapper) to v2.4 image tags—a simple process that typically takes only a few minutes. Organizations using Zeek should install the required JA4, JA3, and HASSH packages and configure the Zeek feed URL after upgrade. RHEL-family admin installs should follow the Podman quickstart path; in-app auto-update remains disabled when running under Podman, so upgrades use a manual pull and recreate.
The platform will continue to receive new features and fixes. Forewarned is also advancing a cloud-native STINGAR offering for organizations that want elastic, managed deployment options.
Please contact Forewarned, Inc for licensing and existing users please visit <https://stingarv2.readthedocs.io/en/stable/upgrade.html> for upgrade information.
Release notes: <https://github.com/4warned/STINGARv2_Release_Notes/blob/main/RELEASE_NOTES_2.4.md>
About Forewarned
Forewarned Inc. is a C-corporation headquartered in Chapel Hill, NC with the founding team from Duke University’s Office of Information Technology and a deep technical background of networking and enterprise security expertise and a shared vision for creating a safer online environment using STINGAR to improve the safety of all users. For more information about Forewarned and the STINGAR platform please visit <https://forewarned.io> or email: <info@forewarned.io>