Live signal lab

NadSec-Online Portal

A public, simplified Kibana-style view of NadSec honeypots. Per-sensor attack telemetry, monthly AI-written reports, IOC feeds, and downloadable STIX logs—ready to drop into your workflows.

T-Pot CE backboneOTX STIX 2.1Robert AI briefs

Stack status

Honeypots online

Cisco ASA, SSH, ADB, Redis, Elastic - expanding as new traps go live.

Distribution

OTX pulses

Public STIX exports

Reporting brain

Robert AI

Monthly narratives

guest@nadsec:~
_

Signals we surface

Indicator rich

STIX bundles packed with IPs, hashes, and context labels you can drop straight into SIEM, blocklists, or enrichment.

Signals we surface

Exploit telemetry

Payloads, botnet binaries, and brute-force sequences pulled directly from high-interaction traps. No production data, ever.

Signals we surface

New

AI briefs

Robert AI reads the noise, clusters infrastructure reuse, and writes the monthly digest humans actually want to read.

Quick pulse

Latest ADBHoney indicators

Pulled directly from the newest STIX bundle (November 2025).

View full dashboard

Unique IPs

0

Source IPs observed this month.

SHA-256 hashes

0

File samples trapped by the honeypot.

Indicator objects

0

STIX indicator objects published.

Signal score

0

Heuristic strength of the current drop.

Roadmap

Incoming traps and UX

In build

Next

Cisco ASA + SSH

Geo heat, exploit strings, and repeat-offender tracking for VPN auth and SSH spray campaigns.

Next

Malware lab notes

Reverse-engineer blurbs plus YARA snippets for binaries pulled off the traps.

Next

Automation hooks

Webhooks, RSS, and JSON feeds so every new indicator can sink directly into your stack.

Next

Archive UX

Month-by-month browsing with search, filters, and CSV export for the spreadsheet faithful.

How it works

Pipeline from trap to dashboard

No production data
1

Catch

T-Pot CE honeypots sit on noisy ports, vacuuming malicious sessions and payloads on purpose.

2

Normalize

Events are enriched and pushed into AlienVault OTX as rolling pulses with STIX 2.1 exports.

3

Translate

Robert AI ingests the pulses and writes human-friendly monthly reports for each honeypot.

4

Publish

Dashboards like ADBHoney render metrics, reports, and indicator tables for anyone to consume.

Ethos and safety

This is a research playground. Everything shown is derived from honeypot traffic only - no production user data, no private traffic, no exceptions. Telemetry refreshes monthly with each report drop. Share the links, clone the STIX, or ignore it entirely - your call.