Stop Looking Like a Honeypot
A stock honeypot has a handful of tells that get it fingerprinted and skipped in seconds: a bare SSH banner, a shell that answers every unknown command the same way, config strings lifted straight from the examples everyone else runs. This is how to find your own tells by probing the box the way the person checking it does, and close the loud ones.
- Events observed
- 98K
- Unique sources
- 39K
- Countries
- 158
- Active sensors
- 3
Data as of Jul 4, 2026, 09:40 UTC
Recent field reports
All research- Actually Read What You CaughtGroundwork · Jul 17, 2026 · 6 min
- Plant Something Worth StealingGroundwork · Jul 10, 2026 · 6 min
- Give Your Honeypot a Reason to ExistGroundwork · Jul 3, 2026 · 7 min
- All Roads Lead to Bedrock: An LLMjacking Watched From Inside the BaitThreat Research · Jun 15, 2026 · 10 min
Adversary behavior, studied against decoys built to be found.
How operators move
The shape of a real intrusion once a decoy answers, from reconnaissance through persistence, studied step by step.
LLMjacking & MCP abuse
How automated agents go after AI infrastructure: model abuse, MCP tool-calling, prompt injection.
Reconnaissance in the wild
The probing patterns that precede compromise against exposed web services and APIs.
A pipeline, not a dashboard.
Capture
A small distributed sensor network across multiple regions and protocols, logging every connection with passive fingerprints and microsecond timing.
Classify
Mapped against MITRE ATT&CK. Scored for automation and novelty. Agents detected separately.
Enrich
Cross-referenced with AbuseIPDB, GreyNoise, VirusTotal, Shodan. Malicious IPs reported back.
Research integrity,
earned line by line.
- Evidence over speculation.
- Every finding rests on direct session-level evidence. Conclusions stay inside the data.
- Confidence-graded.
- Every judgment is rated high, medium, or low, and the rating is stated.
- Passive collection only.
- No active scanning, no exploit delivery, no rDNS from sensors.
- No false attribution.
- Geography is reported, never blamed. Origin is not attribution.
- Safety first.
- Credentials, working exploits, and infrastructure are all redacted before publication.
The attacks worth reading about are the ones nobody's watching for.
Passive observation only · No exploit payloads