About
What TarPit-Lab is, how it works, and where it is going.
What is TarPit-Lab?
TarPit-Lab is an open threat intelligence project. Multiple sensors are deliberately exposed to the internet to attract unsolicited traffic — automated scanners, bots, exploit attempts, credential attacks, and industrial protocol probes — and capture that activity in real time.
Each sensor simulates a different set of services, acting as a honeypot. Attackers interact with fake SSH servers, databases, web applications, and industrial control systems, revealing their tools, techniques, and targets in the process.
The captured data is processed and made publicly available, with the goal of contributing to a better understanding of what is actively scanning and probing internet-connected systems.
What does “tarpit” mean?
A tarpit is a defensive technique designed to waste attacker resources — keeping connections open as long as possible, slowing down scanners and bots while they are observed. Like insects trapped in tar, automated tools get stuck.
In practice, TarPit-Lab goes beyond the classical tarpit approach. Rather than just stalling connections, the sensors simulate realistic services that respond with plausible protocol-level data. This encourages attackers to reveal more about what they are looking for and how they operate.
What data is collected?
The sensors capture connection metadata: source IP, geographic and ASN information, the type of activity being attempted, and what the attacker is probing or requesting. For ICS/SCADA facades, this includes industrial protocol function codes and register addresses.
This data is aggregated and presented here. Full payloads and raw request details are retained privately and are not exposed through public routes.
Known limitations
- The sensor network is small — a limited number of nodes covering a limited set of geographic locations. The data represents a narrow slice of internet-wide activity, not a comprehensive view.
- Known legitimate scanners (security researchers, indexing services such as Shodan and Censys) appear in the data. They are identified and flagged where possible, but not filtered.
- Geographic IP attribution is approximate. ASN and organization data is generally more reliable than country or city-level attribution.
- ICS/SCADA data is particularly limited — industrial protocol scanners are far less frequent than generic web traffic, and conclusions should be drawn cautiously.
An evolving project
TarPit-Lab is not a static system. The sensor network, the facades it exposes, and the way data is presented change continuously — shaped by what the data itself reveals. New attack patterns lead to new detection campaigns. New protocols get honeypot coverage as they appear in scan traffic. The weekly Threat Pulse reflects what was actually observed, not a fixed template.
This means the platform will look and behave differently over time. That is intentional.
Data retention and privacy
Aggregated statistics and IP addresses are retained and made publicly available for defensive and research purposes. No personally identifiable information beyond IP addresses is collected or stored.
How to use this data
The IP blocklist, ASN blocklist, ICS/SCADA event feed, and JSON feed available on the Export page are suitable for use in firewalls, threat intelligence pipelines, and security dashboards.
All data is provided as-is under CC BY 4.0. Do not rely solely on this data for blocking decisions — treat it as one signal among many.
Have something to share? Contact us →