slatterysec.com/blog/2026/05/greetings-programs/
sensors 8 up last session 4m ago 24h captures 312 unique src 87

slattery@sec:~/blog$ cat greetings-programs.md

[2026-05-02]  ·  meta · site · honeypot

Greetings, Programs

Welcome to the updated slatterysec.com. If you've been here before, things look a little different. If you haven't — glad you found it.

This is my corner of the internet for documenting security research, honeypot data, and notes from coursework and personal projects. No ads, no tracking, no JavaScript frameworks — just a monospace terminal aesthetic and actual content.

What's here

The site is organized around three things:

Current focus

I'm a graduate student in Digital Forensics and Incident Response at Champlain College. Most of what I'm actively working on falls into one of two buckets: coursework in KAPE-based triage, EvtxECmd analysis, and integrated IR strategy — and the honeypot operation, which has been running continuously since early 2025 and has gotten progressively more interesting.

April 2026 in particular has been a busy month on the sensors. The mdrfckr SSH key implant campaign has been running every period. The Redtail botnet has been hitting both the SSH and web sensors simultaneously. And the web sensor has seen some novel evasion techniques — percent-encoded paths, HEAD-before-GET credential harvesting, rotating User-Agent strings — worth documenting properly.

All of that is in the honeypot reports section if you want the specifics. The April data is fully published.

What this isn't

This isn't a tutorial site. I'm not writing beginner guides or SEO content. If something I post is useful to you, great. If you're a threat actor reading your own campaign writeup here — hi, I see you, your opsec needs work.

Going forward

Plan is to keep publishing honeypot reports on a regular cadence and fill in the blog with writeups as I have time. If you want to get in touch, the contact section has the relevant details.

Thanks for stopping by.