Last updated: March 2026

Who we are

TarPit-Lab (tarpit-lab.xyz) is a personal, non-commercial open threat intelligence project. It is operated by a private individual with no commercial activity, no business registration, and no revenue of any kind. The project exists solely for research, education, and the public benefit of the security community.

For any privacy-related enquiry, contact us at: [email protected]

What data we collect

TarPit-Lab operates a honeypot — a deliberately exposed server that attracts unsolicited inbound connections from automated scanners, bots, and exploit tools. The following data is collected automatically from those inbound connections:

  • IP address — the source IP of each inbound probe
  • Geographic data — country and approximate city derived from the IP address via MaxMind GeoLite2
  • Network data — ASN (Autonomous System Number) and organisation name associated with the IP
  • Connection metadata — timestamp, port, protocol, HTTP method, request path, and HTTP headers
  • Attack classification — automated categorisation of the probe type (scan, bruteforce, RCE attempt, etc.)

All data collected is attacker-originated — it is sent unsolicited to our server. No data is collected from visitors to this website beyond what is described below.

Website analytics

This website records basic page view data for operational purposes: a one-way hashed session identifier (derived from IP, user agent, and date — not reversible to your IP), the page visited, referring URL, country of origin, and browser/OS type. No raw IP addresses of website visitors are stored. This data is used solely to understand how the site is used and is never shared with third parties.

Cookies

TarPit-Lab does not use tracking cookies, advertising cookies, or any third-party cookie services. The only cookie used is a functional session cookie required for the private analyst panel. If you are a regular visitor to the public site, no cookies are set on your device.

We do not use Google Analytics, Facebook Pixel, or any external analytics or advertising service.

Legal basis for processing (GDPR)

The processing of IP addresses and connection metadata from honeypot probes is carried out under Article 6(1)(f) GDPR — legitimate interests. Our legitimate interest is the detection, documentation, and public disclosure of automated malicious activity on the internet, for the purpose of improving collective cybersecurity. IP addresses collected in this context belong to entities that initiated unsolicited connections to our server.

Website analytics are processed under the same legal basis — legitimate interest in understanding operational usage of a public service, using anonymised data.

Public disclosure of IP addresses

IP addresses of sources that have probed our honeypot are made publicly available through the Export section of this site (IP blocklist, JSON feed). This is standard practice in the threat intelligence field and consistent with the operation of established services such as AbuseIPDB, Spamhaus, and similar projects.

IP addresses are published because they initiated unsolicited connections to a system with no legitimate reason to do so. Publication serves the legitimate interest of enabling other operators to protect their own infrastructure.

Data retention

Honeypot event data is retained for operational and research purposes. There is no fixed deletion schedule — data accumulates as the project runs. Website analytics data is retained indefinitely in anonymised, aggregated form.

Data sharing

We do not sell, rent, or share any data with third parties for commercial purposes. Data is made publicly available through this site solely for defensive and research purposes, as described above. No data processing agreements exist with any advertising or data broker.

The server infrastructure is hosted on Hetzner Cloud (EU). No data is transferred outside the European Economic Area.

Your rights under GDPR

If you are located in the European Economic Area, you have the following rights regarding your personal data:

  • Right of access — you may request information about whether your IP address appears in our dataset
  • Right to rectification — you may request correction of inaccurate data
  • Right to erasure — you may request deletion of your IP address from our dataset, subject to our legitimate interest assessment
  • Right to object — you may object to processing based on legitimate interests

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with your national data protection authority. In Finland (where the server is located), this is the Office of the Data Protection Ombudsman.

Legal Notice →  ·  About TarPit-Lab →