deepforkcyber.com
AI Honeypot · Threat Intelligence
Loading…
events observed
campaigns tracked
countries
networks

🎣 Credential-trap funnel

We plant fake cloud credentials. Attackers harvest them — and use them in the wild. This is the bait working, end to end.

planted
harvested
used out-of-band
distinct validators
harvest→use rate

Key uses over time

What attackers do with stolen keys

No out-of-band API actions recorded in this window.

🤖 AI-crawler legitimacy

Traffic claiming to be a real AI crawler (GPTBot, ClaudeBot, PerplexityBot, and similar) — split against the share hitting credential/secret-harvest paths a genuine crawler never would. That split is a spoofed UA riding on conventional attacker tooling.

AI-crawler claims
on secret-harvest paths
spoof rate

Tracked campaigns

CampaignClassEventsCountriesFirst seen

Attacker population by persona

Which fictional company (persona) draws which kind of attacker — a WordPress site and an exposed NVR/DVR admin panel should not see the same population.

New tool discovery

Distinct TLS fingerprint tools first catalogued per week — total to date.

Coordinated swarms

5+ distinct source IPs sharing a TLS fingerprint within the same hour — evidence of coordinated botnet infrastructure. total to date.

Attack mix

Events per day

Top source countries

Top source networks

Credential-spray corpus

spray attempts
distinct sources

Usernames sprayed against the trap — only generic, well-known logins are published.

Password shapes

Structure of the sprayed passwords — never the values. “Target-domain derived” means mutated from the victim’s own domain.