It Started With an ESP32 Honeypot

This whole thing started when I asked about StingBox, a paid honeypot service designed to detect activity on a network and send alerts.

I liked the idea, but my first thought was: I bet I could build better.

At that point, “better” didn’t mean that I knew more than the people who built it. I didn’t. It meant something I could build myself, control, change, and learn from instead of paying for a box and a subscription.

So I started with an ESP32.

The first version presented itself as an IP camera. It had web bait and a monitoring panel that let me see when something interacted with it. It wasn’t part of some grand cybersecurity plan. It was a small experiment that I built because I wanted to know whether I could make it work—and what would happen if I did.

Then it started getting attention.

Once I saw traffic reaching it, the project stopped being only about building the device. I wanted to know where the traffic came from, what it was looking for, and what would happen if I watched more closely.

Every answer led to another question.

That little ESP32 ended up being the beginning of something much larger, but that’s a story for the next post.

Leave a comment