A professional habit of looking closely.
An independent honeypot project for publishing the practical work: what we changed, what the decoys observed, and what the evidence can honestly support.
- events observed
- 98,493
- unique sources
- 39,297
- countries
- 158
- sensors represented
- 4
Export of July 4, 2026
A decoy becomes an instrument.
A honeypot presents a system worth touching: an exposed shell, an API, or a model endpoint. To the visitor it looks useful. To us it records the sequence.
The point is not to make routine internet noise sound dramatic. It is to recognize the rare interaction that teaches us something, preserve it safely, and explain it clearly.
Behavior across shells, services, and agents.
- 01
Shell interaction
Commands, authentication behavior, persistence attempts, and the difference between automated scripts and hands-on activity.
- 02
AI infrastructure
Model enumeration, prompt extraction, exposed inference, and agents invoking tools through deceptive endpoints.
- 03
Web and API behavior
Reconnaissance and exploitation patterns aimed at services that appear useful enough to investigate.
Passive collection
Sensors wait for inbound interaction. They do not scan back, deliver exploits, or pursue operators.
Evidence first
Observed behavior is kept separate from inference. Geography and infrastructure are not treated as attribution.
Safe publication
Secrets, operational identifiers, and material that could harm third parties are removed before release.
Built on Beelzebub, extended for our own observation work.
The sensors run a fork of the open-source Beelzebub framework by Beelzebub.AI. Their work provides the foundation; this site documents what we learn while operating and extending it.