Skip to content

Honeypot experiment

Downloads

Files are ordered by size and usefulness, not by source: most people only need the aggregates, and whoever wants their own analysis will find the individual events here too. Every file lists its size, record count, time window and checksum.

Data updated: 2026-10-03 10:31:16 UTC+02:00

Report a problem

Files to download #


The aggregated CSVs are kilobytes and anyone can grab them; the raw data is orders of magnitude larger. Files that have not been generated yet are marked.

Session recordings

Recordings of interactive sessions. They are small and among the most interesting artefacts of the whole run.

Size
2.0 MB
Records
0
Time window
2026-08-22 — 2026-09-16
SHA-256
4fb7b211a0f3b49c41d95697c5cf07418704efeb59fea86b25927781e6a84f3a
After downloading, verify the SHA-256 checksum, for example with sha256sum.

Build your own chart #


Pick one of the published CSV files, a column for the X axis and a value for the Y axis, and narrow the rows with WHERE conditions if you like. The chart is computed on the server straight from these files – no other file or column than the ones listed here can be read.

WHERE conditions – all must hold

SUM(events) by date

0200k400k600k800k08-222026-08-22 SUM(events): 82,3032026-08-23 SUM(events): 79,2762026-08-24 SUM(events): 48,92808-252026-08-25 SUM(events): 69,9022026-08-26 SUM(events): 68,7922026-08-27 SUM(events): 204,30608-282026-08-28 SUM(events): 201,8232026-08-29 SUM(events): 206,2752026-08-30 SUM(events): 185,68908-312026-08-31 SUM(events): 539,9192026-09-01 SUM(events): 720,2002026-09-02 SUM(events): 275,75809-032026-09-03 SUM(events): 274,6752026-09-04 SUM(events): 219,4222026-09-05 SUM(events): 154,02309-062026-09-06 SUM(events): 131,8072026-09-07 SUM(events): 184,4032026-09-08 SUM(events): 169,74709-092026-09-09 SUM(events): 177,5722026-09-10 SUM(events): 193,3942026-09-11 SUM(events): 210,41809-122026-09-12 SUM(events): 254,8272026-09-13 SUM(events): 236,9112026-09-14 SUM(events): 213,64009-152026-09-15 SUM(events): 272,0742026-09-16 SUM(events): 101,115

52 of 52 rows match the conditions; the X axis has 26 distinct values.

The first and last day of the window are half days – the window opens and closes at 12:00 UTC.

Show values as a table
date SUM(events) Rows
2026-08-22 82,303 2
2026-08-23 79,276 2
2026-08-24 48,928 2
2026-08-25 69,902 2
2026-08-26 68,792 2
2026-08-27 204,306 2
2026-08-28 201,823 2
2026-08-29 206,275 2
2026-08-30 185,689 2
2026-08-31 539,919 2
2026-09-01 720,200 2
2026-09-02 275,758 2
2026-09-03 274,675 2
2026-09-04 219,422 2
2026-09-05 154,023 2
2026-09-06 131,807 2
2026-09-07 184,403 2
2026-09-08 169,747 2
2026-09-09 177,572 2
2026-09-10 193,394 2
2026-09-11 210,418 2
2026-09-12 254,827 2
2026-09-13 236,911 2
2026-09-14 213,640 2
2026-09-15 272,074 2
2026-09-16 101,115 2
Source data
honeypot-timeline-20260922.csv
Time window
2026-08-22 12:00:00 UTC – 2026-09-16 12:00:00 UTC
Script
hp_aggregate.py · d60ff11
Format
field documentation
Equivalent SQL
SELECT date, SUM(events) FROM timeline.csv GROUP BY date ORDER BY date

Format documentation #


For every published file: field name, type, meaning and an example. The examples illustrate the format; they are not values from the data.

ports.csv

One row per combination of port, protocol and server.

Field Type Meaning Example
port integer Destination port. For srv4, the real port the attacker aimed at (from hptcp), not the port after redirection. 22
protocol string Transport protocol. tcp
service string The service that usually runs on the port. A label, not detection of the actual traffic. SSH
server srv3 | srv4 | both srv3, srv4, or both for a row covering both servers together. srv4
attempts integer Number of connection attempts to the port over the whole time window. 12345
unique_ips integer Number of distinct source IP addresses. 678
share_pct decimal Share of attempts on this port, in percent. 9.1

timeline.csv

One row per day and server.

Field Type Meaning Example
date date (YYYY-MM-DD) Calendar day. 2026-08-22
server srv3 | srv4 srv3 or srv4. srv4
events integer Number of events that day. 12345
unique_ips integer Number of distinct source IP addresses that day. 678
campaign_events integer Events attributed to campaigns. 10000
baseline_events integer Baseline noise events. events = campaign_events + baseline_events. 2345

geo.csv

One row per combination of country and autonomous system.

Field Type Meaning Example
country ISO 3166-1 alpha-2 Country code from source IP geolocation. NL
asn string Autonomous system number. AS64500
asn_name string Autonomous system name. Example Networks
events integer Number of events. 12345
unique_ips integer Number of distinct source IP addresses. 678
share_pct decimal Share of all events, in percent. 9.1

credentials.csv

One row per username and password combination.

Field Type Meaning Example
username string Username tried, unmodified. root
password string Password tried, unmodified. 123456
attempts integer Number of attempts with this combination. 12345
unique_ips integer Number of distinct IP addresses that tried the combination. 678

attacker_commands.csv

One row per unique command.

Field Type Meaning Example
command string The command exactly as the attacker typed it. uname -a
count integer How many times the command was entered. 12345
unique_sessions integer In how many distinct sessions it appeared. 678

samples.csv

One row per unique sample by SHA-256.

Field Type Meaning Example
sha256 hex (64) SHA-256 hash of the file. e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
file_type string File type. ELF
architecture string Target architecture for executables. x86-64
size_bytes integer Size in bytes. 12345
first_seen datetime (ISO 8601) When the sample was first captured. 2026-08-22T14:03:11Z
times_seen integer How many times it was captured. 12

commands.csv

Log of the commands agents and the operator ran on the servers. One row per command; command outputs are not included.

Field Type Meaning Example
timestamp datetime (ISO 8601) When the command was run. 2026-08-21T09:15:02Z
server srv3 | srv4 srv3 or srv4. srv3
source agent | operator agent (the language model) or operator (a human). agent
command string The command that was run. uptime
exit_code integer Exit code. 0
duration_ms integer Run time in milliseconds. 42

Agent chats and journals

Each session comes in two forms: Markdown (the agent’s readable text, reasoning summaries, commands and outputs) and a raw JSON export for machine processing. Both are in the original language. If an English translation of a session exists, it is a separate file and always labelled as a translation on the site.

Individual events

The raw event format differs by sensor and by server. Field documentation will be added when the data is published.

All CSVs are UTF-8, comma-separated, with a header row. Quotes inside values are doubled (RFC 4180); backslashes are ordinary characters. Timestamps use ISO 8601. Note: values contain attacker input unmodified, including strings starting with =, +, - or @. Spreadsheet software may evaluate them as formulas (CSV injection) – open the files as text, or import them with text-typed columns.

Licence #


The data and the scripts each have their own licence. You may use them at work or in research – just credit the source.

Data
CC BY-NC 4.0
Scripts
to be added
Script repository
to be published

How to cite #


If you use the data, please credit the source. One line is enough:

Barták, Tomáš (2026). Honeypot dataset: 25 days of traffic from two honeypots, 22 Aug – 16 Sep 2026 [Data set]. https://batacek.eu/honeypot/

BibTeX

@misc{bartak2026honeypot,
  author = {Barták, Tomáš},
  title  = {Honeypot dataset: 25 days of traffic from two honeypots, 22 Aug – 16 Sep 2026},
  year   = {2026},
  url    = {https://batacek.eu/honeypot/},
  note   = {Data set}
}