The Blog

Notes from the treacle — what the honeypots actually caught.

The Polite Redirect

A scanner hit my sites for seven minutes and almost none hit The MIRE. My URL shortener was being scanned and neutered the inbound traffic itself…

Read more →

Patterns, not doors

MIRE's own catch-all marker said what it was missing, starting with the first request every scanner sends. Ten fixes, eight more, and a fall-through rate that barely moved — because the tail isn't 374 separate gaps, it's a handful of wordlists.

Read more →

What 7’434 user-agents taught us

Last month we built a toll booth. AI crawlers and data-harvesting bots that turned up looking for something to ingest got a slow text notice and an invoice for 0.00001 BTC instead of an expensive decoy. It was cheap to serve, it wasted their time, and it felt good. This month we went back to…

Read more →

ClaudeBot wasn’t alone

A follow-up to “How ClaudeBot fell in love with The MIRE/C³” Last time, I told the story of how ClaudeBot found the one door robots.txt left open on cfd.mire.cc and spent weeks pulling tens of thousands of randomly-named files out of a directory listing that regenerates itself on every request. The IP verification was solid,…

Read more →

What 421’000 dead-ends taught us

MIRE is the deception layer that sits behind our sites. Anything the real stack would answer with a 404 — the scanner noise, the credential fishing, the CVE-of-the-week probes — gets quietly handed to MIRE instead, which replies with a convincing fake: a login panel, a leaking .env, a backup archive with a canary token…

Read more →

How ClaudeBot fell in love The MIRE/C³

The MIRE/C³ is a Multi-layer Intrusion Response Engine — not just a honeypot, though one of its layers does exactly the kind of bait-and-log work people associate with that word. Part of its job is to look like the soft, exposed infrastructure an attacker (or a careless crawler) loves to find — fake admin panels,…

Read more →
Loading more…