Tripwire
Public Honeypot & AI Attack-Triage Pipeline
A honeypot live on the open internet that catches real attackers, then has Claude explain what each one was trying to do.
- Cowrie SSH/Telnet honeypot on an isolated, disposable cloud VPS, hardened so a compromise can't pivot anywhere — the real admin service is moved off the exposed port and egress is locked down.
- Custom Wazuh detection rules turn raw honeypot events into scored, MITRE ATT&CK-tagged alerts, shipped from the public host back to a private SIEM over a Tailscale tunnel.
- Cowrie
- Wazuh
- Docker
- Python
- FastAPI
- Claude API
- Supabase
- Next.js
- Tailscale
- MITRE ATT&CK