GingerPot is a security research project that collects and analyzes
real-world security activity through honeypot telemetry.
The goal is to explore observed security activity, detection
approaches, and how telemetry can be transformed into practical
defensive insights.
I welcome collaboration with security professionals, researchers,
detection engineers, and anyone interested in defensive security.
-
Threat Research
Analyze observed activity patterns, scanning behavior, and
exploitation attempts.
-
Detection Engineering
Develop detection ideas, SIEM rules, and investigation workflows.
-
Security Operations
Share approaches for alert triage, incident investigation, and
monitoring.
-
Automation and Tooling
Improve workflows around telemetry processing, Elasticsearch, and
security tooling.
-
Research Discussions
Exchange ideas about honeypots, threat intelligence, and defensive
security.
- ✓ Internet-wide scanning trends
- ✓ SMB scanning activity analysis
- ✓ Honeypot telemetry correlation
- ✓ Threat intelligence enrichment
- ✓ Detection engineering & SIEM use cases
- ○ SSH/Telnet brute-force behavior
- ○ Malware delivery techniques (planned)
- ○ Lateral movement simulations (planned)
- ○ ATT&CK technique mapping (planned)
Interested in security monitoring, honeypots, detection engineering,
or threat research? Feel free to connect or follow project updates.