[2026-05-02] · meta · site · honeypot
Greetings, Programs
Welcome to the updated slatterysec.com. If you've been here before, things look a little different. If you haven't — glad you found it.
This is my corner of the internet for documenting security research, honeypot data, and notes from coursework and personal projects. No ads, no tracking, no JavaScript frameworks — just a monospace terminal aesthetic and actual content.
What's here
The site is organized around three things:
- Honeypot reports — I run Cowrie SSH and web honeypots on a RackNerd VPS. Every five days or so I publish a report covering what hit the sensors: attacker IPs, credential pairs, post-auth commands, payload drops, web probes, and cross-sensor correlations. The reports are written manually — no automated tooling.
- Blog posts — Longer-form writeups on things I'm working through: memory forensics labs, IR methodology, malware behavior I've observed in honeypot sessions, CTF notes.
Current focus
I'm a graduate student in Digital Forensics and Incident Response at Champlain College. Most of what I'm actively working on falls into one of two buckets: coursework in KAPE-based triage, EvtxECmd analysis, and integrated IR strategy — and the honeypot operation, which has been running continuously since early 2025 and has gotten progressively more interesting.
April 2026 in particular has been a busy month on the sensors. The mdrfckr SSH key implant campaign has been running every period. The Redtail botnet has been hitting both the SSH and web sensors simultaneously. And the web sensor has seen some novel evasion techniques — percent-encoded paths, HEAD-before-GET credential harvesting, rotating User-Agent strings — worth documenting properly.
All of that is in the honeypot reports section if you want the specifics. The April data is fully published.
What this isn't
This isn't a tutorial site. I'm not writing beginner guides or SEO content. If something I post is useful to you, great. If you're a threat actor reading your own campaign writeup here — hi, I see you, your opsec needs work.
Going forward
Plan is to keep publishing honeypot reports on a regular cadence and fill in the blog with writeups as I have time. If you want to get in touch, the contact section has the relevant details.
Thanks for stopping by.