Methodology
How the honeypot is set up, how data flows to the live feed, and how research articles are produced.
# Honeypot setup
The honeypot runs Cowrie, an open-source medium-interaction SSH and Telnet honeypot. Cowrie emulates a Debian Linux shell - it accepts connections, logs credential attempts, and records commands, but provides no real system access. Any files attackers attempt to download are captured.
The server is a VPS exposed on standard ports with no legitimate users or services. It exists only to attract and log automated scanners and targeted attacks.
Cowrie logs events to JSON at a known path. Each event includes a timestamp, session ID, source IP, event type, and any relevant payload (credentials, command text, download URLs).
# Data pipeline
A Flask API reads the Cowrie JSON logs on the VPS and serves structured data over HTTPS. The live feed page polls this API every 15 seconds and renders the results client-side.
The Flask API has rate limiting applied (60 req/min general, 10 req/min for expensive endpoints). The Next.js layer acts as a proxy - the VPS address is not exposed to the browser.
# Geolocation
IP geolocation uses MaxMind GeoLite2. Country-level accuracy is generally good; city-level and ISP data is less reliable. IPs that cannot be resolved are recorded as ?? and excluded from country rankings.
The geo cache is refreshed on API restart. Results are not re-looked-up once cached unless the cache is cleared. Geolocation data is approximate and should not be used for attribution without corroboration.
# MITRE ATT&CK classification
Commands observed in sessions are classified against MITRE ATT&CK categories using a regex ruleset in the feed API. Categories include:
This classification is automated and not manually reviewed. A command matching multiple rules is assigned the first matching category. Commands with no match are tagged as Other. Hover over commands in the Commands tab for plain-English explanations.
# VirusTotal integration
When an attacker attempts to download a file via wget or curl, Cowrie captures the file. The feed API submits the SHA-256 hash to VirusTotal and stores the result. The Downloads tab shows detection counts and links to the VT report.
VT results marked "pending" have not yet been submitted or have not returned a result. A clean result (0 detections) on a shell script or text file is not necessarily a guarantee of safety - many novel or custom scripts are not in VT's database.
# Research articles
Articles in the research archive are written from primary sources where possible - court documents, technical post-mortems, incident reports, academic papers, and contemporaneous journalism. Sources are cited inline or in article footnotes.
The honeypot research article was written from raw Cowrie log analysis across 31 days of data (1.25M+ events). IP addresses of honeypot infrastructure are not published.
If you spot an error or have a correction, use the contact info on the about page or the security.txt.
# What this site is not
This is a research and documentation project. The live feed shows real attacker behavior captured on a honeypot. It is not a threat intelligence product, a production security tool, or a commercial service.
Data shown on the live page reflects the traffic this specific honeypot attracts and should not be extrapolated as representative of global threat trends.