Actually Read What You Caught
The most common honeypot mistake happens after deployment: nobody opens the logs. A live sensor fills fast, and most of it is scanner noise. This is how to read a Beelzebub log with nothing but jq, drop the ~70% that ran zero commands, and get to the one session worth catching.
- Events observed
- 98K
- Unique sources
- 39K
- Countries
- 158
- Active sensors
- 3
Data as of Jul 4, 2026, 09:40 UTC
Recent field reports
All research- Plant Something Worth StealingGroundwork · Jul 10, 2026 · 6 min
- Give Your Honeypot a Reason to ExistGroundwork · Jul 3, 2026 · 7 min
- All Roads Lead to Bedrock: An LLMjacking Watched From Inside the BaitThreat Research · Jun 15, 2026 · 10 min
- The MCP Kill Chain Wasn't IsolatedField Notes · Jun 3, 2026 · 4 min
Adversary behavior, studied against decoys built to be found.
How operators move
The shape of a real intrusion once a decoy answers, from reconnaissance through persistence, studied step by step.
LLMjacking & MCP abuse
How automated agents go after AI infrastructure: model abuse, MCP tool-calling, prompt injection.
Reconnaissance in the wild
The probing patterns that precede compromise against exposed web services and APIs.
A pipeline, not a dashboard.
Capture
A small distributed sensor network across multiple regions and protocols, logging every connection with passive fingerprints and microsecond timing.
Classify
Mapped against MITRE ATT&CK. Scored for automation and novelty. Agents detected separately.
Enrich
Cross-referenced with AbuseIPDB, GreyNoise, VirusTotal, Shodan. Malicious IPs reported back.
Research integrity,
earned line by line.
- Evidence over speculation.
- Every finding rests on direct session-level evidence. Conclusions stay inside the data.
- Confidence-graded.
- Every judgment is rated high, medium, or low, and the rating is stated.
- Passive collection only.
- No active scanning, no exploit delivery, no rDNS from sensors.
- No false attribution.
- Geography is reported, never blamed. Origin is not attribution.
- Safety first.
- Credentials, working exploits, and infrastructure are all redacted before publication.
The attacks worth reading about are the ones nobody's watching for.
Passive observation only · No exploit payloads