Skip to content

Honeypot experiment

Run log

Both honeypots were built and operated by a language model. This is everything it did along the way: the deployment and check chats, every command it ran, its journals – and, kept apart, every time a human stepped in.

Data updated: 2026-10-03 10:31:16 UTC+02:00

Report a problem

Agent chats #


Server selection, deployment and all nine checks on both servers – the ninth being the final one. Each session is rendered readably from its Markdown, with the raw JSON available to download.

Primary record, shown exactly as it was produced. Records are in Czech. Where an English translation exists, it is shown on the English version of the page and always labelled as a translation.
Date Server Session Commands Changes Readable version Raw export
2026-08-19 srv3 Server selection 0 0 Read translated · Conversation not available yet
2026-08-19 srv4 Server selection 0 0 Read translated · Conversation not available yet
2026-08-21 srv3 Deployment 0 0 Read not available yet · Conversation not available yet
2026-08-21 srv4 Deployment 0 0 Read translated · Conversation not available yet
2026-08-22 srv3 Check 1 0 0 Read not available yet not available yet
2026-08-22 srv4 Check 1 0 0 Read not available yet not available yet
2026-08-24 srv3 Check 2 0 0 Read not available yet · Conversation not available yet
2026-08-24 srv4 Check 2 0 0 Read not available yet · Conversation not available yet
2026-08-28 srv3 Check 3 0 0 Read not available yet · Conversation not available yet
2026-08-28 srv4 Check 3 0 0 Read not available yet · Conversation not available yet
Raw chat exports whose command output has not been reviewed yet are not available for download – they could contain sensitive data such as passwords, keys or internal addresses.

Command log #


Every command that ran on the servers through the control service: time, who ran it, exit code and duration. Telling agent and operator apart matters – human interventions are highlighted and can be filtered.

Command outputs are not published in this log – they could reveal confidential details about the environment. Each command therefore only shows the time, who ran it, the exit code and the duration.
Time Server Who Command Exit code Duration
to be added srv3 Agent to be added — —
to be added srv4 Agent to be added — —
to be added srv4 Operator to be added — —
Time window
2026-08-20 – 2026-09-16
Source data
run-log-commands not available yet
Script
to be published
Format
field documentation

Journals and runbooks #


Files the agents kept between checks so the next session would know what had happened. They explain the reasoning behind decisions and read better than the chats.

Primary record, shown exactly as it was produced. Records are in Czech. Where an English translation exists, it is shown on the English version of the page and always labelled as a translation.
Server Kind Document Version from Readable version
srv3 Journal JOURNAL.md — Read not available yet
srv3 Runbook RUNBOOK.md — Read not available yet
srv4 Journal JOURNAL.md — Read not available yet
srv4 Runbook RUNBOOK.md — Read not available yet

Operator interventions #


Separately and completely: when a human touched the environment, why, and what exactly they did. Kept apart from what the agents did.

Some records have been translated from Czech into English and are labelled as translations. The Czech originals are authoritative.
  1. 2026-08-19 – 2026-08-20
    Operatorboth servers Server preparation: ordering the VPSs the agents had chosen, installing the hedgehog-runner control service and the WireGuard tunnel, and setting up syslog forwarding and backup downloads over SSH. translated Reason: The environment the agents worked in, as described in their brief. translated Details: to be added
  2. 2026-08-21
    Operatorboth servers Opening ports on the provider's network firewall after deployment, from the list the agent handed over at its end. translated Reason: The firewall is managed by the operator; the agents cannot see it and have no access to it. translated Details: TODO: přesný seznam portů a čas otevření pro každý server
  3. 2026-09-17 – 2026-09-19
    Operatorboth servers planned Closing all ports on the network firewall, downloading the data and cancelling the servers. translated Reason: End of the run. translated