What happens when you leave a server on the internet
A T-Pot honeypot sits on my home network and pretends to be a vulnerable server. Bots and attackers find it within minutes, try default passwords, drop malware, and probe for web exploits. This page visualizes that traffic as it happens.
Cowrie
Emulates SSH and Telnet services. Captures every username, password, and shell command attackers try.
Dionaea
Mimics services like SMB, FTP, and HTTP to lure in malware droppers. Saves every binary that lands.
Tanner / Snare
A fake web application that classifies incoming requests — SQL injection, XSS, path traversal, and more.
Total attacks
10,000
No change since last update
Unique source IPs
285
Distinct attacker addresses seen in the current window.
Top targeted service
SMB (54%)
Port 445 via DIONAEA
Malware captures
0
Malware binaries caught by Dionaea in the current window.
Credential attempts
5,306
Login attempts caught across SSH, Telnet, FTP, and other exposed services.
Web attack events
212
Hostile web requests classified by Tanner in the current window.
Attack timeline
Hourly event counts over the past week.
LAST_168_HOURS
Sensor status
Latest snapshot2026-07-29 22:54
Window size24h
Source labeltpot-proxmox
Observed countries20
Attacker origins
Where the attacks are coming from, based on source IP geolocation.
GEO_DENSITY
Top source countries
#
Country
Attacks
IPs
1
The Netherlands
5,386
10
2
United States
4,817
75
3
Bulgaria
4,708
3
4
Philippines
3,500
2
5
Bangladesh
3,159
5
6
China
2,380
51
7
Romania
1,731
9
8
Singapore
1,531
13
9
South Korea
1,196
7
10
Brazil
1,061
5
Protocol and service breakdown
Which services attackers are going after the most.
SERVICE_MIX
Protocol and service breakdown: Horizontal bar chart showing the most targeted services and ports in the current honeypot snapshot.
events
SMB :445
6,813SSH :22
5,658HTTP :80
212
Web attack categories
Types of web exploits attempted against the fake application.
WEB_SIGS
Web attack categories: Horizontal bar chart showing the most common classified web attack categories in the current snapshot.
requests
Unclassified
212
Credential attempts
The most common username and password combinations attackers try across all exposed services.
AUTH_PRESSURE
#
Username
Password
Attempts
1
345gs5662d34
345gs5662d34
90
2
node
node
54
3
sol
1234
52
4
sol
sol
52
5
solana
solana
52
6
solv
solv
52
7
sol
123
51
8
support
support
51
9
ubuntu
ubuntu
51
10
validator
validator
51
11
ubuntu
1234qwer
50
12
ubuntu
qwer1234
50
13
validator
solana
50
14
root
3245gs5662d34
43
15
root
123456
11
16
root
12345678
10
17
admin
admin
6
18
admin
password
6
19
admin
1234
5
20
validator
ethereum
1
Malware captures
Binaries that attackers dropped onto the honeypot. Each hash links to VirusTotal for analysis.
PAYLOAD_INDEX
SHA-256
Type
Captures
First seen
No malware samples captured yet.
What's happening
AI-generated summary of the latest 24-hour window of honeypot activity.
AI_SUMMARY
No summary available yet — this generates once enough data has been collected.