MIRE makes it clear when it has no handler for inbound traffic. A request arrives, none of the traps recognise it, and so the MIRE returns a neutral 404, and logs a single line:

Unknown path catch-all path=/…
Between 1 August and 14 September, this neutral response occurred 19’556 times, against 373’078 requests. One request in nineteen arrives at a honeypot built entirely out of specific, tailored answers — and has to be guided into a generic gap.
So for the September release, we did the obvious thing. We looked at the gaps and started working down the list.
Fine-tuning existing traps
Some traps were working but with blind spots that had to be adapted to how the scanners hit the systems.
Every scan opens the same way. Before anything asks for /wp-content/plugins/some-unpatched-thing/readme.txt, it asks for /wp-content/. This is the scanner checking whether the directory exists at all before spending requests on what might be inside it. That bare directory request is the first thing almost every scanner sends and, if it fails, the more complex traps also do not work.
/wp-content/ /wp-includes/ /wp-json/ /.git/ /.well-known/
/api/ /files/ /wp/ /wordpress/ /blog/
Ten paths with 1’253 requests from 533 separate IP addresses — each one receiving a delay and a 404 response rather than inviting them to spend more time in the MIRE; now, their first contact gets a “Welcome” sign!
Eight more additions
Some digging into other paths that could be turned into signal from noise were the following.
| What was falling through | Hits | Why it missed |
|---|---|---|
/wp/v2/*, /wp/wp/v2/* | 1’217 | Unlisted doors into an existing trap |
.php7, .php0, .php.bak | 330 | Strict .endswith('.php') |
| Open-proxy / SSRF probes | 327 | No log signal of their own |
.gitignore, .gitconfig, .svn | 301 | Siblings of a trap we had |
/api/config, session properties | 242 | Outside the API traps |
/blog// | 225 | Werkzeug collapses the pattern |
readme.html | 200 | No .html branch existed |
Two are worth pulling out. readme.html is the oldest WordPress version fingerprint there is — 200 requests from 123 addresses — and the file-serving branch had no case for .html at all. Yes, guilty — we should have considered the reconnaissance hitting .html files as well as all of the other extensions that they go after…!
And /blog//, with its doubled slash, cannot be fixed with a route at all: Werkzeug collapses consecutive slashes inside the pattern, so a rule written for /blog// compiles down to the rule for /blog/ and lands in a blind spot. It had to become a prefix check on the catch-all instead to ensure detection.
There was also a scraper network to deal with — many rotating addresses, each requesting the same harvested Chinese-language slug exactly once, which means the per-IP decoy budget we shipped in August never trips. That one is now keyed on the slug rather than the address: first sighting gets a generated fake post, every repeat gets 410 Gone.
Let’s see in a month if they get the message…
First results are in
The MIRE version was promoted to production on 14 September. In the 42 hours after the change took effect, the following improvements have been observed with the new configuration proving its value.
| Path family | Before | After |
|---|---|---|
/api/session/properties | 25 | 0 |
/wp/v2/* | 35 | 0 |
/.svn/* | 13 | 0 |
/blog//* | 8 | 0 |
/.gitignore | 2 | 0 |
The bots are entering the doors we designed. Normally, this would be the end of the announcement. But, in Apple style:
One More Thing…
In the 42 hours after the deploy, MIRE logged 1’000 catch-all requests across 374 distinct paths — an average of 2.7 requests each. 270 of those paths were seen once or twice and then never again.
The fall-through rate over those three days ran 7.6%, 6.1%, 7.1%. In early August it ran 3 to 5%. It has been climbing all month for reasons that have nothing to do with anything we shipped, and our ten closures are comfortably smaller than the week-to-week noise.
Sometimes, it simply will be the case that gaps exist; reduction will continue but the return on that investment will decrease.
But there are still patterns
The gaps still present a pattern and that makes adapting the MIRE worthwhile.
/signin /sign-in /signup /register /user/login
/users/login /auth /auth/login /account /account/login
/dashboard /panel /portal /backoffice /secure
/forgot-password /reset-password
What looks like 17 different different requests but fall into one taxonomy — scraping for a login interface. 374 requests to these paths will need one trap — a login interface — to again create a valuable return on investment.
A bug, hiding in plain site
While analysing the logs for new functionality, a bug was discovered:
UserWarning: Duplicate name: 'var/www/html/settings.ini'
The decoy archives — the fake backups MIRE hands out to anyone who asks for one — fill themselves with two to four filler files per directory, picked at random from a list of five names. Five names simply was not a deep enough pool of entropy for filenames and collisions were resulting.
Attackers had been collecting weird archives with repeating filenames — which potentially could be real but the deeper pool of filenames will make them feel more interesting.
Now the interesting bit
None of the above is why September was interesting.
Credential capture went from an August average of 269 submitted username and password pairs per day to 899 a day across the first half of September — 22’270 pairs since 1 August. We did not build anything that would cause that. The brute-force traffic simply got heavier.
And in the other direction: AI and crawler interceptions fell from 3’097 a day in August to 591 a day in September. The toll booth is still standing. The traffic it was built for largely stopped turning up — the question is did MIRE cause it?
To summarise
In September, we made 9 improvements closing gaps that were quantifiably worthwhile covering. We also fixed a cosmetic bug that could lead an attacker to think they were being fed useless data (unless the archive was password-protected!)
Next month, we will repeat the search for patterns and taxonomies — and address them in the MIRE.


