Two honeypots feed this page. This site logs scans on paths like /wp-admin and /.env that don't exist here. Never did, this is static HTML. AMvpn runs a real SSH honeypot that's been catching attack traffic since April 2026. Everything below is the combination of the two, and it's all aggregate. No individual IPs, ever.
Loading…
—
Total hits
—
Last 30 days
—
Unique sources
This site, last 30 days.
This site, most-hit paths, all time.
Loading…
—
Last 90 days
—
Last 30 days
—
Unique sources
AMvpn, top attacking countries, all time.
This site: a handful of paths that only ever get hit by automated scanners (common WordPress, PHP, and admin panel probes) are logged like any other request, but return the same 404 status a real typo would. The only difference is they get a slightly different page. A script tallies hits every 15 minutes, and a weekly summary gets sent to me.
AMvpn: a real Cowrie SSH/Telnet honeypot on a separate VM, with GeoIP data added to every event, feeding a live dashboard and Telegram alerts. Once an hour an aggregate summary (never raw IPs or session data) gets pushed here over a restricted SSH connection that can only overwrite that one file. Full write-up on the case study page.
No analytics, ad trackers, or marketing pixels run on this site, and never have.
The honeypot above isn't tracking either. It only logs requests to bait paths like /wp-admin and /.env, which no real visitor would hit while browsing the site.
Real visits still land in a standard server access log, IPs included, same as any web server keeps. That log stays local, isn't shared or sold, and isn't used to profile anyone.