I had always liked the idea of running a honeypot. There was something interesting about putting a system online and watching what people tried to do with it.
Then I came across StingBox. I liked the concept, but it was a subscription service. I didn’t want another monthly payment, so I decided to see whether I could build what I needed myself.
The first version wasn’t elaborate. It was an ESP32 connected to my network with only four or five sensors attached. I wasn’t trying to build an enterprise security platform. I wanted to see what people were looking for and what happened once the device was online.
It started getting activity almost immediately.
That was the part that really pulled me in. This little ESP32 was collecting connection attempts and showing me that automated scanning and probing never really stops. Put something online, and eventually somebody—or more likely somebody’s bot—is going to knock on the door.
The first version worked surprisingly well. There weren’t many major problems to solve. From there, I started adding the things I wanted: notifications when something happened, better records of the activity, and a dashboard where I could see what the honeypot was collecting.
Before long, I had built the parts of the paid service that interested me without paying for a subscription. More importantly, I understood how it worked because I had built it myself.
That simple experiment became the starting point for everything that followed: tracking attacks, studying the source addresses, reporting malicious activity, improving the infrastructure, and asking increasingly complicated questions about what was happening on the other side of those connections.
What began as one ESP32 and a simple question became a much larger cybersecurity research project.
In the next post, I’ll get into the original ESP32 build—what it needed, how I set it up, and how I turned those first connection attempts into useful information.
This project was built and tested using equipment and networks I controlled. Anyone building a honeypot should isolate it from important systems and assume that anything exposed to the internet will eventually be attacked.

Leave a comment