Lock in $30 Savings on PRO—Offer Ends Soon! ⏳

Azazel Series

Avatar for Mr.Rabbit Mr.Rabbit
November 30, 2025

Azazel Series

Azazel Series is a family of “Cyber Scapegoat Gateways” for untrusted networks, built around the core loop of Detection / Deception / Delay / Visibility. It detects threats with Suricata, misdirects attackers with OpenCanary decoy services, and deliberately slows or constrains suspicious traffic using tc/nftables under selectable modes (e.g., Portal / Shield / Lockdown), while keeping operations observable via a log pipeline and endpoints such as Mattermost, console, and E-Paper.

The lineup includes Azazel-Pi (portable SOC/NOC on Raspberry Pi 5 for shelters or temporary clinics), Azazel-Zero (pocket-sized gateway on Raspberry Pi Zero 2 W for hotel Wi-Fi and field work), and Azazel-USB (USB-boot edition that turns any laptop into an Azazel gateway). The roadmap extends toward correlation + lightweight AI threat scoring, dynamic decoy switching with attacker profiles, and broader deployment from disaster networks to municipal SOC use.

Azazel Series は、Untrusted Network を前提に「Detection / Deception / Delay / Visibility」を中核に据えた “Cyber Scapegoat Gateway” 群です。Suricata による検知、OpenCanary による欺瞞(擬似 SSH/HTTP/DB 等)、tc/nftables とモード制御(Portal / Shield / Lockdown など)による遅滞・制御を組み合わせ、ログパイプラインと Mattermost/コンソール/E-Paper により運用可視化まで一気通貫で扱います。

モデルは、Raspberry Pi 5 を用いた小規模拠点向けの Azazel-Pi、Raspberry Pi Zero 2 W による個人装備向けの Azazel-Zero、任意のラップトップを USB ブートで一時的に Azazel 化する Azazel-USB で構成されます。今後は、相関+軽量 AI による文脈化・スコアリング、攻撃パターンに応じた動的デコイや攻撃者プロファイル、そして被災地ネットワークから自治体 SOC までの応用展開を視野に入れています。

Avatar for Mr.Rabbit

Mr.Rabbit

November 30, 2025
Tweet

More Decks by Mr.Rabbit

Other Decks in Technology

Transcript

  1. Makoto Sugita (aka Mr. Rabbit) I am … @01ra66it Mr.Rabbit

    Linkedin Presentations 2019 AVTOKYO HIVE🇯🇵 / SECCON YOROZU🇯🇵
 2020 Black Hat Asia Arsenal🇸🇬 / AVTOKYO HIVE🇯🇵 
 2022 SECCON Open Conference🇯🇵 — 🏅 Best Award
 2023 CODE BLUE CyberTAMAGO🇯🇵 / AVTOKYO HIVE🇯🇵
 SECCON Open Conference🇯🇵
 2024 CODE BLUE CyberTAMAGO🇯🇵 / AVTOKYO HIVE🇯🇵
 2025 BSides Tokyo🇯🇵 / BSides Las Vegas🇺🇸 
 Black Hat USA Arsenal🇺🇸 / SecTor a black hat event🇨🇦 
 CODE BLUE Bluebox🇯🇵
 CODE BLUE CyberTAMAGO🇯🇵 ← Now Independent Security Researcher (hobbyist)
 Executive Member, InfoSec Workshop @ Echigo-Yuzawa
 CISSP/SSCP/CompTIA CSAP/OSWP
  2. Agenda • Section I - What is the Azazel System?

    • Section II - Introducing the Azazel Series • Section III - Future of Azazel Azazel System
  3. Agenda • Section I - What is the Azazel System?

    • Section II - Introducing the Azazel Series • Section III - Future of Azazel Azazel System
  4. "[B[FMγϦʔζڞ௨ΞʔΩςΫνϟ Detection / Deception / Delay / Visibility %FUFDUJPO w

    4VSJDBUBʢ֤Ϟσϧڞ௨ͷݕ஌Τϯδϯʣ %FDFQUJPO w 0QFO$BOBSZʢٖࣅ44))551%#౳ʣ %FMBZ$POUSPM w UDOGUBCMFTʢ஗ԆɾγΣʔϐϯάɾϒϩοΫʣ w Ϟʔυ੍ޚʢ1PSUBM4IJFME-PDLEPXOͳͲʣ 7JTJCJMJUZ0QFSBUJPOT w ϩάύΠϓϥΠϯʢ7FDUPSͳͲʣ w .BUUFSNPTUίϯιʔϧ&Ŗ1BQFS w B[DUMεΫϦϓτ܈ Azazel Series Core Architecture Clients Uplink & Services Untrusted → Controlled
  5. Agenda • Section I - What is the Azazel System?

    • Section II - Introducing the Azazel Series • Section III - Future of Azazel Azazel System
  6. AZ-01X Azazel-Pi Portable SOC/NOC on Raspberry Pi 5 3PMF খن໛ωοτϫʔΫ޲͚$ZCFS4DBQFHPBU(BUFXBZ

    )BSEXBSF #BTF3BTQCFSSZ1J (#  /7.F64#44% ୯ମͰ4VSJDBUBɾ0QFO$BOBSZɾ੍ޚϞδϡʔϧΛՔಇ $PSF'VODUJPO %FUFDUJPO4VSJDBUB %FDFQUJPO0QFO$BOBSZ %FMBZUDOGUBCMFTʢϞʔυ੍ޚʣ 7JCJMJUZϩά.BUUFSNPTU௨஌ 6TF$BTFT ආ೉ॴɾԾઃΫϦχοΫɾখن໛ڌ఺ͷҰ࣌40$/0$
  7. AZ-02 Azazel-Zero Personal Cyber Scapegoat Gateway on Raspberry Pi Zero

    2 W 3PMF ݸਓ૷උ޲͚ͷܰྔ$ZCFS4DBQFHPBU(BUFXBZ )BSEXBSF #BTF3BTQCFSSZ1J;FSP8 64#05(ʢ64#&UIFSOFU(BEHFUʣʴ&1BQFS)"5 $PSF'VODUJPOT %FUFDUJPOɿܰྔઃఆͷ4VSJDBUB %FDFQUJPOɿඞཁ࠷খݶͷ0QFO$BOBSZαʔϏε %FMBZɿUDOGUBCMFTʹΑΔ؆қ஗ԆɾߜΓࠐΈ 7JTJCJMJUZɿ&1BQFSίϯιʔϧͰͷεςʔλεදࣔ 6TF$BTFT ग़ுઌɾϗςϧ8J'JɾҰ࣌తͳݱ৔ௐࠪ ݸਓϖϯςετ૷උϑΟʔϧυϦαʔν༻ͷl࣋ͪา͚Δ"[B[FMz
  8. AZ-03 Azazel-USB Any Laptop as an Azazel GatewayʢUSB Boot Editionʣ

    3PMF Ͳͷϥοϓτοϓ΋"[B[FMήʔτ΢ΣΠʹม͑Δ64#ϒʔτ൛ )BSEXBSF #BTF64#઀ଓ44%64#ϝϞϦ       طଘϥοϓτοϓΛ64#ϒʔτͰىಈ       ಺ଂσΟεΫඇґଘɾΠϯετʔϧෆཁ $PSF'VODUJPOT %FUFDUJPOɿ4VSJDBUBʢϗετ$16Λ׆͔ͨ͠ݕ஌ʣ %FDFQUJPOɿ0QFO$BOBSZʢෳ਺αʔϏεɾγφϦΦʹରԠʣ %FMBZɿUDOGUBCMFTʹΑΔৄࡉͳ஗ԆɾγΣʔϐϯάɾःஅ 7JTJCJMJUZɿίϯιʔϧ8FC6*ϩά࿈ܞʹΑΔՄࢹԽ 6TF$BTFT ඃࡂ஍΍܇࿅؀ڥͰͷlҰ࣌40$/0$Խz ϖϯςετݱ৔ɾΦϯαΠτௐࠪͰͷݱ஍Ϛγϯ׆༻ ࣋ͪࠐΈػࡐ੍͕ݶ͞ΕΔ؀ڥͰͷ64#Ұຊల։
  9. ̏Ϟσϧͷൺֱ ؀ڥͱ໨తʹԠͨ͡"[B[FMͷબͼํ ߲໨ AZ-01X Azazel-Pi AZ-02 Azazel-Zero AZ-03 Azazel-USB ໾ׂ

    খن໛40$/0$༻ήʔτ΢ΣΠ ݸਓ޲͚ɾܰྔ$ZCFS4DBQFHPBU(BUFXBZ طଘϥοϓτοϓΛҰ࣌తʹ"[B[FMԽ ༻్Πϝʔδ ආ೉ॴԾઃڌ఺ͷೖΓޱ๷ޚ ݸਓ૷උϑΟʔϧυϫʔΫ ඃࡂ஍ɾ܇࿅ɾϖϯςετݱ৔ͷz64#Ұຊ ల։z ϕʔεϋʔυ 3BTQCFSSZ1J (#  44% 3BTQCFSSZ1J;FSP8 &1BQFS)"5 64#઀ଓ44%64#ϝϞϦ ೚ҙͷϥοϓτ οϓ Մൖੑ খܕ͕ͩʮਾ͑ஔ͖دΓʯ ϙέοταΠζͰߴ͍Մൖੑ 64#ϝσΟΞͷΈܰྔ ੑೳ༨༟ ݕ஌ʴܰྔ"*·Ͱ҆ఆӡ༻Մೳ ݕ஌ɾ؆қ஗଺͕த৺ ʢ"*͸جຊର৅֎ʣ ϗετੑೳ࣍ୈͰॏ͍"*෼ੳ΋౥ࡌՄೳ ίΞػೳ %FUFDUJPO%FDFQUJPO%FMBZ7JTJCJMJUZ ʢϑϧߏ੒ʣ ಉ͕ͩ͡ɺܰྔߏ੒ɾػೳΛ࡟ͬͯলిྗԽ ಉ͡ߏ੒͕ͩϦιʔεʹ༨༟͕͋Ε͹֦ு͠ ΍͍͢ "*είΞϦϯάػೳ ࣮ӡ༻ϨϕϧͷείΞϦϯά͕Մೳ ݪଇͳ͠ɺ΋͘͠͸͘͝؆қͳϧʔϧϕʔε ࠷΋ߴ͍ʢϗετ$16(16Λ׆༻Մೳʣ ిݯɾӡ༻ੑ ৗઃӡ༻޲͖ʢ"$څిલఏʣ ϥοϓτοϓ͔Β௚઀څి ϥοϓτοϓͱಉ͡ӡ༻ʢిݯࣄ৘ʹґଘʣ Ձ֨ײʢ໨҆ʣ தʢ1J 44%ʣ ௿ʢ;FSP8ϕʔεͰ࠷҆ʣ ϝσΟΞࣗମ͸௿͕ͩɺ1$ࠐΈͩͱதʙߴ ޲͍͍ͯΔ৔໘ ආ೉ॴɾΫϦχοΫɾখن໛ڌ఺ ग़ுઌɾϗςϧ8J'Jɾݸਓϖϯςετ ػࡐ੍ݶԼͰͷݱ৔ల։ݱ஍1$ͷҰ࣌ 40$/0$Խ
  10. Agenda • Section I - What is the Azazel System?

    • Section II - Introducing the Azazel Series • Section III - Future of Azazel Azazel System
  11. είΞϦϯάͷਐԽ ૬ؔʴܰྔ"*ʹΑΔڴҖͷจ຺Խ 4VSJDBUB 0QFO$BOBSZΞϥʔτ .PDL--. ʢϧʔϧʴώϡʔϦεςΟοΫʣ ϩʔΧϧ--. ʢܰྔϞσϧʣ 5ISFBU4DPSF ˠϞʔυมߋΞϥʔτ

    ૬ؔΤϯδϯ ʢෳ਺Ξϥʔτͷ࣌ؒతɾۭؒతͳ݁ͼ͖ͭʣ ίϯςΩετ৘ใ ʢ୺຤ͷ໾ׂɺωοτϫʔΫηάϝϯτɺ࣌ؒଳͳͲʣ ӡ༻ΞΫγϣϯ ʢ4BGF1PSUBM2P4τϦΞʔδ΁ͷఏҊʣ Today: On-device threat scoring Next: Correlation & context-aware triage
  12. ٗᛋ૚ͷڧԽ ಈతσίΠͱ߈ܸऀϓϩϑΝΠϧ "UUBDLFS "[B[FM(BUFXBZ %FDPZ4FSWJDFT w 44))551%#ͳͲͷ ෳ਺αʔϏε w ٖࣅΞΧ΢ϯτɺٖࣅσʔλ

    3FBM4FSWJDFT 5PEBZ w ݻఆઃఆͷ0QFO$BOBSZαʔϏε w ࣄલʹܾΊଧͪͨ͠όφʔɾϙʔτɾαʔϏεछผ /FYU w ߈ܸύλʔϯʹԠͨ͡σίΠ੾Γସ͑ w ߈ܸऀϓϩϑΝΠϧʢ*1ৼΔ෣͍ཤྺʣ w γφϦΦผͷِ૷؀ڥʢྫɿ%#෩ɺ؅ཧϙʔλϧ෩ʣ ໨తɿ߈ܸऀͷ࣌ؒͱϦιʔεΛୣ͍ɺຊ෺ͷࢿ࢈͔ΒҙࣝΛҳΒ͢
  13. Ԡ༻ྖҬͷల։ ඃࡂ஍ωοτϫʔΫ͔Β࣏ࣗମ40$΁ w ආ೉ॴ8J'J w Ұ࣌40$/0$ w 4BGF1PSUBM w খن໛ிࣷ

    w ΫϦχοΫ w ϩʔΧϧ؂ࢹ w ࣏ࣗମ40$ w ஍ҬͷةػωοτϫʔΫ w ඪ४Խͱల։ ڞ௨ίϯηϓτɿ҆ՁɾϩʔΧϧ׬݁ɾݱ৔ʹґଘ͠ͳ͍ӡ༻