Skip to content

Honeypot experiment

Downloads

Files are ordered by size and usefulness, not by source: most people only need the aggregates, and whoever wants their own analysis will find the individual events here too. Every file lists its size, record count, time window and checksum.

Data updated: 2026-10-03 10:31:16 UTC+02:00

Report a problem

Files to download #


The aggregated CSVs are kilobytes and anyone can grab them; the raw data is orders of magnitude larger. Files that have not been generated yet are marked.

Aggregates

Exactly the numbers behind the charts and tables in the results, plus the log of commands run on the servers.

honeypot-ports-baseline-20260922.csv not available yet csv
Size
2.3 MB
Records
88,073
Time window
2026-08-22 — 2026-09-16
SHA-256
a33d1620dc7f796efe6f9ddc51b5ad66c8233b123cbfd2ccc1586cc50398ffa7
Size
2.3 KB
Records
52
Time window
2026-08-22 — 2026-09-16
SHA-256
be5a5da0c02d07cbee47b31573e12f5fc3c5ab1eab4601b03e1361029b97d7a5
honeypot-geo-20260922.csv not available yet csv
Size
158.1 KB
Records
3,558
Time window
2026-08-22 — 2026-09-16
SHA-256
da0ca7d7b4cb118b9a972ddd264ba6d7aade9e38dfaf7510aa0d4ccb76f31631
honeypot-credentials-20260922.csv not available yet csv
Size
569.4 KB
Records
25,217
Time window
2026-08-22 — 2026-09-16
SHA-256
21d486fddf1077374851c303341fd9ac70d369120d8e9ffff9404c1d607bb2ed
honeypot-attacker-commands-20260922.csv not available yet csv
Size
97.7 KB
Records
582
Time window
2026-08-22 — 2026-09-16
SHA-256
759506cb81feba406d1ddc664d3da8810e6281fe24691dce15e49e1154e5e570
Size
197.2 KB
Records
1,190
Time window
2026-08-22 — 2026-09-16
SHA-256
6867ca342e1e22eb990cc590697af0e0c144f178534d14e7e80a7f275201e709
Size
28.0 KB
Records
585
Time window
2026-08-22 — 2026-09-16
SHA-256
fdcdf0e698cb3a8bbe0d6b89aa2c7ab5cd72a2dc770eb57aa612e1c4e36752d5
Size
2.6 MB
Records
21,962
Time window
2026-08-22 — 2026-09-16
SHA-256
7e7d6f33045a307c97dc8295358a2fcd1854f85e0fba7e465302690bc178d1b5

Individual events

Every sensor event as an individual record, in compressed JSONL – for your own analysis.

Size
320.2 MB
Records
16,450,701
Time window
2026-08-22 — 2026-09-16
SHA-256
865a152b232d9e8de4034303db43f7305c69a44dc56773bf37c5b7a71a042940
Size
107.6 MB
Records
5,477,199
Time window
2026-08-22 — 2026-09-16
SHA-256
63647140988d90963ac061654f7d080aa0b53de3aaf4049d0b259d86889d4d36

Session recordings

Recordings of interactive sessions. They are small and among the most interesting artefacts of the whole run.

Size
2.0 MB
Records
0
Time window
2026-08-22 — 2026-09-16
SHA-256
4fb7b211a0f3b49c41d95697c5cf07418704efeb59fea86b25927781e6a84f3a

Malware samples

Malware captured by the honeypots, in a password-protected archive.

honeypot-samples-20260922.7z not available yet 7z
Size
303.6 MB
Records
0
Time window
2026-08-22 — 2026-09-16
SHA-256
af2c6d19cbc4ab7412db38e321ca94f7ace154d3949e50bb85f78b0f3c09738a
Warning: The archive contains real malware. Open it only in an isolated environment, never on an everyday computer, and expect antivirus software to flag it.
Archiv obsahuje ziveho malwaru zachyceneho honeypotem. Heslo: infected. Nerozbaluj na stroji, na kterem ti zalezi.
After downloading, verify the SHA-256 checksum, for example with sha256sum.

Build your own chart #


Pick one of the published CSV files, a column for the X axis and a value for the Y axis, and narrow the rows with WHERE conditions if you like. The chart is computed on the server straight from these files – no other file or column than the ones listed here can be read.

WHERE conditions – all must hold

SUM(events) by date

0200k400k600k800k08-222026-08-22 SUM(events): 82,3032026-08-23 SUM(events): 79,2762026-08-24 SUM(events): 48,92808-252026-08-25 SUM(events): 69,9022026-08-26 SUM(events): 68,7922026-08-27 SUM(events): 204,30608-282026-08-28 SUM(events): 201,8232026-08-29 SUM(events): 206,2752026-08-30 SUM(events): 185,68908-312026-08-31 SUM(events): 539,9192026-09-01 SUM(events): 720,2002026-09-02 SUM(events): 275,75809-032026-09-03 SUM(events): 274,6752026-09-04 SUM(events): 219,4222026-09-05 SUM(events): 154,02309-062026-09-06 SUM(events): 131,8072026-09-07 SUM(events): 184,4032026-09-08 SUM(events): 169,74709-092026-09-09 SUM(events): 177,5722026-09-10 SUM(events): 193,3942026-09-11 SUM(events): 210,41809-122026-09-12 SUM(events): 254,8272026-09-13 SUM(events): 236,9112026-09-14 SUM(events): 213,64009-152026-09-15 SUM(events): 272,0742026-09-16 SUM(events): 101,115

52 of 52 rows match the conditions; the X axis has 26 distinct values.

The first and last day of the window are half days – the window opens and closes at 12:00 UTC.

Show values as a table
date SUM(events) Rows
2026-08-22 82,303 2
2026-08-23 79,276 2
2026-08-24 48,928 2
2026-08-25 69,902 2
2026-08-26 68,792 2
2026-08-27 204,306 2
2026-08-28 201,823 2
2026-08-29 206,275 2
2026-08-30 185,689 2
2026-08-31 539,919 2
2026-09-01 720,200 2
2026-09-02 275,758 2
2026-09-03 274,675 2
2026-09-04 219,422 2
2026-09-05 154,023 2
2026-09-06 131,807 2
2026-09-07 184,403 2
2026-09-08 169,747 2
2026-09-09 177,572 2
2026-09-10 193,394 2
2026-09-11 210,418 2
2026-09-12 254,827 2
2026-09-13 236,911 2
2026-09-14 213,640 2
2026-09-15 272,074 2
2026-09-16 101,115 2
Source data
honeypot-timeline-20260922.csv
Time window
2026-08-22 12:00:00 UTC – 2026-09-16 12:00:00 UTC
Script
hp_aggregate.py · d60ff11
Format
field documentation
Equivalent SQL
SELECT date, SUM(events) FROM timeline.csv GROUP BY date ORDER BY date

Format documentation #


For every published file: field name, type, meaning and an example. The examples illustrate the format; they are not values from the data.

ports.csv

One row per combination of port, protocol and server.

Field Type Meaning Example
port integer Destination port. For srv4, the real port the attacker aimed at (from hptcp), not the port after redirection. 22
protocol string Transport protocol. tcp
service string The service that usually runs on the port. A label, not detection of the actual traffic. SSH
server srv3 | srv4 | both srv3, srv4, or both for a row covering both servers together. srv4
attempts integer Number of connection attempts to the port over the whole time window. 12345
unique_ips integer Number of distinct source IP addresses. 678
share_pct decimal Share of attempts on this port, in percent. 9.1

timeline.csv

One row per day and server.

Field Type Meaning Example
date date (YYYY-MM-DD) Calendar day. 2026-08-22
server srv3 | srv4 srv3 or srv4. srv4
events integer Number of events that day. 12345
unique_ips integer Number of distinct source IP addresses that day. 678
campaign_events integer Events attributed to campaigns. 10000
baseline_events integer Baseline noise events. events = campaign_events + baseline_events. 2345

geo.csv

One row per combination of country and autonomous system.

Field Type Meaning Example
country ISO 3166-1 alpha-2 Country code from source IP geolocation. NL
asn string Autonomous system number. AS64500
asn_name string Autonomous system name. Example Networks
events integer Number of events. 12345
unique_ips integer Number of distinct source IP addresses. 678
share_pct decimal Share of all events, in percent. 9.1

credentials.csv

One row per username and password combination.

Field Type Meaning Example
username string Username tried, unmodified. root
password string Password tried, unmodified. 123456
attempts integer Number of attempts with this combination. 12345
unique_ips integer Number of distinct IP addresses that tried the combination. 678

attacker_commands.csv

One row per unique command.

Field Type Meaning Example
command string The command exactly as the attacker typed it. uname -a
count integer How many times the command was entered. 12345
unique_sessions integer In how many distinct sessions it appeared. 678

samples.csv

One row per unique sample by SHA-256.

Field Type Meaning Example
sha256 hex (64) SHA-256 hash of the file. e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
file_type string File type. ELF
architecture string Target architecture for executables. x86-64
size_bytes integer Size in bytes. 12345
first_seen datetime (ISO 8601) When the sample was first captured. 2026-08-22T14:03:11Z
times_seen integer How many times it was captured. 12

commands.csv

Log of the commands agents and the operator ran on the servers. One row per command; command outputs are not included.

Field Type Meaning Example
timestamp datetime (ISO 8601) When the command was run. 2026-08-21T09:15:02Z
server srv3 | srv4 srv3 or srv4. srv3
source agent | operator agent (the language model) or operator (a human). agent
command string The command that was run. uptime
exit_code integer Exit code. 0
duration_ms integer Run time in milliseconds. 42

Agent chats and journals

Each session comes in two forms: Markdown (the agent’s readable text, reasoning summaries, commands and outputs) and a raw JSON export for machine processing. Both are in the original language. If an English translation of a session exists, it is a separate file and always labelled as a translation on the site.

Individual events

The raw event format differs by sensor and by server. Field documentation will be added when the data is published.

All CSVs are UTF-8, comma-separated, with a header row. Quotes inside values are doubled (RFC 4180); backslashes are ordinary characters. Timestamps use ISO 8601. Note: values contain attacker input unmodified, including strings starting with =, +, - or @. Spreadsheet software may evaluate them as formulas (CSV injection) – open the files as text, or import them with text-typed columns.

Licence #


The data and the scripts each have their own licence. You may use them at work or in research – just credit the source.

Data
CC BY-NC 4.0
Scripts
to be added
Script repository
to be published

How to cite #


If you use the data, please credit the source. One line is enough:

Barták, Tomáš (2026). Honeypot dataset: 25 days of traffic from two honeypots, 22 Aug – 16 Sep 2026 [Data set]. https://batacek.eu/honeypot/

BibTeX

@misc{bartak2026honeypot,
  author = {Barták, Tomáš},
  title  = {Honeypot dataset: 25 days of traffic from two honeypots, 22 Aug – 16 Sep 2026},
  year   = {2026},
  url    = {https://batacek.eu/honeypot/},
  note   = {Data set}
}