GingerPot is a security monitoring project built around an internet-facing T-Pot honeypot.
It collects real-world security telemetry, analyzes suspicious activity, and transforms raw security events into practical observations about observed security behavior, detection engineering, and security operations.
GingerPot separates data collection from public visualization. Sensitive Elasticsearch data remains private while summarized telemetry is published through a lightweight reporting pipeline.
Internet Activity
|
v
T-Pot Honeypot
|
v
Elasticsearch / ELK
|
+--> Investigation
|
+--> Detection Engineering
|
v
Telemetry Export Pipeline
|
v
Public Dashboard
The name GingerPot comes from a simple personal connection: honey and ginger are ingredients I enjoy together. The honeypot provides the raw ingredients of security telemetry — scans, probes, and suspicious activity — while investigation and analysis transform them into meaningful insights.
The project's visual identity is inspired by traditional blue gingerpot artwork. The blue color also carries a subtle connection to the Blue Team mindset: observing, investigating, and improving security through visibility.