slatterysec.com/blog/2026/07/session-resumed/
sensors 8 up last session 4m ago 24h captures 312 unique src 87

slattery@sec:~/blog$ cat session-resumed.md

STATUS // BLOG // 2026-07-25

Session Resumed

Posted: 2026-07-25  |  Author: Jay  |  Read: ~4 min

Greetings Programs. It's been a minute.

2026-04-30  report published    April 2026 monthly summary
2026-05-02  post published      Greetings, Programs
            ·
            [ 84 days — no entries ]
            ·
2026-07-25  session resumed

The sensors never went down. Roughly 170,000 sessions came through SSH, telnet, and the web honeypot while the site sat still. Collecting and publishing turn out to be two different habits, and I only kept one of them. Coursework ate the other.

What got me writing again wasn't new data. It was going back through the old data properly and finding out a chunk of what I thought I knew was wrong.

Starting with a correction

The first thing going up is a mea culpa. Short version: my SSH sensor wasn't listening where I assumed it was. Everything in that archive arrived on an alternate port, which makes it a sample of one specific kind of scanning rather than a sample of SSH attack traffic. Some of what I published about attacker behavior was built on a filtered view I didn't know was filtered.

Measure the instrument before you trust the measurement. I skipped that step for about a year. Everything in the April reports is accurate as logged — but "as logged" was narrower than I said it was.

That's fixed as of today. The pre-fix archive is preserved as a baseline, which turns the mistake into a controlled before/after instead of just lost time. Same sensors, same host, one variable changed.

In the queue

Three drafted, in the order I expect to publish. All of them came out of the same re-analysis.

QUEUED SSH
The port I never checked
How a missing port mapping quietly shaped a year of collection, what the alt-port-only population actually looks like, and the baseline methodology for measuring what changes now that it's live on 22.
QUEUED SSH
One key, ninety hosts
A single hardcoded ssh-rsa public key across dozens of source IPs in unrelated ASNs — password randomized every session, key never. A hard attribution link between hosts that otherwise look unconnected.
QUEUED ALERT
Not attacking you — auditioning you
Four thousand sessions that log in, type nothing, and probe DNS, SMTP, and STUN. Not compromise attempts. Open-proxy capability testing, and a look at the economy behind it.
Reports resume on the normal cadence once the new collection has a full period behind it. Raw logs and captured binaries available on request, same as always.