Files to download #
The aggregated CSVs are kilobytes and anyone can grab them; the raw data is orders of magnitude larger. Files that have not been generated yet are marked.
Aggregates
Exactly the numbers behind the charts and tables in the results, plus the log of commands run on the servers.
Build your own chart #
Pick one of the published CSV files, a column for the X axis and a value for the Y axis, and narrow the rows with WHERE conditions if you like. The chart is computed on the server straight from these files – no other file or column than the ones listed here can be read.
SUM(events) by date
52 of 52 rows match the conditions; the X axis has 26 distinct values.
The first and last day of the window are half days – the window opens and closes at 12:00 UTC.
Show values as a table
date |
SUM(events) |
Rows |
|---|---|---|
| 2026-08-22 | 82,303 | 2 |
| 2026-08-23 | 79,276 | 2 |
| 2026-08-24 | 48,928 | 2 |
| 2026-08-25 | 69,902 | 2 |
| 2026-08-26 | 68,792 | 2 |
| 2026-08-27 | 204,306 | 2 |
| 2026-08-28 | 201,823 | 2 |
| 2026-08-29 | 206,275 | 2 |
| 2026-08-30 | 185,689 | 2 |
| 2026-08-31 | 539,919 | 2 |
| 2026-09-01 | 720,200 | 2 |
| 2026-09-02 | 275,758 | 2 |
| 2026-09-03 | 274,675 | 2 |
| 2026-09-04 | 219,422 | 2 |
| 2026-09-05 | 154,023 | 2 |
| 2026-09-06 | 131,807 | 2 |
| 2026-09-07 | 184,403 | 2 |
| 2026-09-08 | 169,747 | 2 |
| 2026-09-09 | 177,572 | 2 |
| 2026-09-10 | 193,394 | 2 |
| 2026-09-11 | 210,418 | 2 |
| 2026-09-12 | 254,827 | 2 |
| 2026-09-13 | 236,911 | 2 |
| 2026-09-14 | 213,640 | 2 |
| 2026-09-15 | 272,074 | 2 |
| 2026-09-16 | 101,115 | 2 |
- Source data
- honeypot-timeline-20260922.csv
- Time window
- 2026-08-22 12:00:00 UTC – 2026-09-16 12:00:00 UTC
- Script
hp_aggregate.py· d60ff11- Format
- field documentation
- Equivalent SQL
SELECT date, SUM(events) FROM timeline.csv GROUP BY date ORDER BY date
Format documentation #
For every published file: field name, type, meaning and an example. The examples illustrate the format; they are not values from the data.
ports.csv
One row per combination of port, protocol and server.
| Field | Type | Meaning | Example |
|---|---|---|---|
port |
integer | Destination port. For srv4, the real port the attacker aimed at (from hptcp), not the port after redirection. | 22 |
protocol |
string | Transport protocol. | tcp |
service |
string | The service that usually runs on the port. A label, not detection of the actual traffic. | SSH |
server |
srv3 | srv4 | both | srv3, srv4, or both for a row covering both servers together. | srv4 |
attempts |
integer | Number of connection attempts to the port over the whole time window. | 12345 |
unique_ips |
integer | Number of distinct source IP addresses. | 678 |
share_pct |
decimal | Share of attempts on this port, in percent. | 9.1 |
timeline.csv
One row per day and server.
| Field | Type | Meaning | Example |
|---|---|---|---|
date |
date (YYYY-MM-DD) | Calendar day. | 2026-08-22 |
server |
srv3 | srv4 | srv3 or srv4. | srv4 |
events |
integer | Number of events that day. | 12345 |
unique_ips |
integer | Number of distinct source IP addresses that day. | 678 |
campaign_events |
integer | Events attributed to campaigns. | 10000 |
baseline_events |
integer | Baseline noise events. events = campaign_events + baseline_events. | 2345 |
geo.csv
One row per combination of country and autonomous system.
| Field | Type | Meaning | Example |
|---|---|---|---|
country |
ISO 3166-1 alpha-2 | Country code from source IP geolocation. | NL |
asn |
string | Autonomous system number. | AS64500 |
asn_name |
string | Autonomous system name. | Example Networks |
events |
integer | Number of events. | 12345 |
unique_ips |
integer | Number of distinct source IP addresses. | 678 |
share_pct |
decimal | Share of all events, in percent. | 9.1 |
credentials.csv
One row per username and password combination.
| Field | Type | Meaning | Example |
|---|---|---|---|
username |
string | Username tried, unmodified. | root |
password |
string | Password tried, unmodified. | 123456 |
attempts |
integer | Number of attempts with this combination. | 12345 |
unique_ips |
integer | Number of distinct IP addresses that tried the combination. | 678 |
attacker_commands.csv
One row per unique command.
| Field | Type | Meaning | Example |
|---|---|---|---|
command |
string | The command exactly as the attacker typed it. | uname -a |
count |
integer | How many times the command was entered. | 12345 |
unique_sessions |
integer | In how many distinct sessions it appeared. | 678 |
samples.csv
One row per unique sample by SHA-256.
| Field | Type | Meaning | Example |
|---|---|---|---|
sha256 |
hex (64) | SHA-256 hash of the file. | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 |
file_type |
string | File type. | ELF |
architecture |
string | Target architecture for executables. | x86-64 |
size_bytes |
integer | Size in bytes. | 12345 |
first_seen |
datetime (ISO 8601) | When the sample was first captured. | 2026-08-22T14:03:11Z |
times_seen |
integer | How many times it was captured. | 12 |
commands.csv
Log of the commands agents and the operator ran on the servers. One row per command; command outputs are not included.
| Field | Type | Meaning | Example |
|---|---|---|---|
timestamp |
datetime (ISO 8601) | When the command was run. | 2026-08-21T09:15:02Z |
server |
srv3 | srv4 | srv3 or srv4. | srv3 |
source |
agent | operator | agent (the language model) or operator (a human). | agent |
command |
string | The command that was run. | uptime |
exit_code |
integer | Exit code. | 0 |
duration_ms |
integer | Run time in milliseconds. | 42 |
Agent chats and journals
Each session comes in two forms: Markdown (the agent’s readable text, reasoning summaries, commands and outputs) and a raw JSON export for machine processing. Both are in the original language. If an English translation of a session exists, it is a separate file and always labelled as a translation on the site.
Individual events
The raw event format differs by sensor and by server. Field documentation will be added when the data is published.
Licence #
The data and the scripts each have their own licence. You may use them at work or in research – just credit the source.
- Data
- CC BY-NC 4.0
- Scripts
- to be added
- Script repository
- to be published
How to cite #
If you use the data, please credit the source. One line is enough:
Barták, Tomáš (2026). Honeypot dataset: 25 days of traffic from two honeypots, 22 Aug – 16 Sep 2026 [Data set]. https://batacek.eu/honeypot/
BibTeX
@misc{bartak2026honeypot,
author = {Barták, Tomáš},
title = {Honeypot dataset: 25 days of traffic from two honeypots, 22 Aug – 16 Sep 2026},
year = {2026},
url = {https://batacek.eu/honeypot/},
note = {Data set}
}
Found a bug, missing data or a leak of sensitive information? Report a problem