What is Sebek?
Sebek is a tool designed for data capture, it attempts to capture most of the attackers activity on the honeypot, without the attacker knowing it (hopefully), then sends the recoverd data to a central logging systemi (Refer to Figure A. It can potentially recover such things as keystrokes, uploaded files, passwords, and IRC chats, even if all communications are encrypted (SSH, IPSec, SSL).