SSH Honeypot
Research.
A two-phase experiment exposing a server to the open internet to study automated botnet behaviour. Phase 1 captured raw, unfiltered attack traffic. Phase 2 introduced CrowdSec blocklists to filter out known botnet noise, revealing the novel, sophisticated threats that bypass standard defences.
Attack Telemetry
Login attempt data captured directly from the honeypot. The honeypot has been shut down, and these figures are the final snapshot taken before it went offline.
Password Breach Analysis
Captured passwords cross-referenced against known breach databases. Shows what percentage of attempted credentials come from public data dumps versus novel, previously unseen combinations.
What Attackers Do After Getting In
An analysis of post-exploitation commands executed by attackers who successfully breached default credentials. Commands are ranked by frequency across all captured sessions to reveal common attacker methodologies.
Attack Origins
Top attack origins by source IP, resolved locally using MaxMind GeoLite2. This map highlights the novel, sophisticated attacks that successfully bypassed CrowdSec blocklists during Phase 2.
Watch Real Attacks
Full TTY recordings of curated sessions from the honeypot. These are real attackers, not simulations. Sessions are selected for duration, command variety, and interesting behavior.
Threat Actor Profiling.
SSH client version strings identify the tool or botnet behind each session. Sessions from the last 7 days, grouped by client fingerprint and correlated with credentials attempted and commands run.