Honeypot Live Stats — 15847 connections today from 41 unique IPs (125503 total, 1534 unique IPs all-time)
Miles Huynh
· Reading time: 2 minutes · Admin

Building my first honeypot on AWS

Building my first honeypot on AWS

I've spent most of my time in IT support handling tickets, MFA resets, and onboarding — not touching cloud infrastructure directly. Today's goal: launch a real AWS server, put something live, and see what actually happens to it.

Launching the instance

Picked the simplest starting point — a t3.micro running Ubuntu, free-tier eligible, connecting straight from the browser through EC2 Instance Connect. No key pair, no prior setup.

Putting something live

Nginx first, to prove I could serve something. Then a hand-written personal page, deployed by pasting into nano over SSH — small, but the first server I've ever owned end to end.

Then I got curious who else was watching. Any public IP gets scanned constantly. Instead of ignoring it, I set up Cowrie — a fake SSH server on port 2222 that logs every command an attacker tries. Opened the port to the world, and within a few hours the first scanner found it: connected, grabbed the banner, disconnected in 34 milliseconds. No login attempt, no commands. Just reconnaissance — the internet doing what it always does.

What I actually learned

Launching a real EC2 instance is a lot less scary than it sounds. A public IP gets attention within hours, not days. Logging is the whole point of a honeypot — the fake shell is just bait, the log file is the actual value.

Next up: a real domain and HTTPS, then writing up whatever the honeypot picks up.