Honeypot

A few endpoints on this site are decoys: login pages and files only a scanner looks for. What touches them — and the rule that would catch it in a SIEM — is logged below.

Live panel unavailable — the honeypot Worker did not respond. The rest of the page is static and still works.

Hostile-traffic map

The same attempts, aggregated by country — arcs from the origins to this site.

No map data until the Worker is published.

📐 Why this lives in a Worker and not the static site — and the privacy policy, including the IP list — is written up in the project decisions. See the Honeypot project →

🔒 The Cloudflare panel never stores an IP. This honeypot's own events store and publish the source IP, in a separate list — the why and the limits are in the project.

Over the week

Attack heatmap (day × hour, UTC)

lessmore

Most-triggered ATT&CK techniques

Most targeted paths

Log

Recent honeypot events. Searchable and paginated — no IP, by construction.

No attack data accumulated yet — the honeypot fills this in over time.

Known IPs

Every public IP that touched a decoy, with the first and last detection. Entries with no new detection in 30 days fall off the list on their own.

No IPs recorded yet.

Recognise yourself on this list? You can request removal. Contact →