DEFENSE SYSTEMS ACTIVE

Collective Defense Intelligence

One homelab. 300,000+ protected installations. Every attacker that touches this infrastructure makes the entire internet safer.

Built by LiΘ™neanu Dumitru-Cristian β€” from a 44 mΒ² apartment near IaΘ™i, Romania

Dell Precision 7910 Β· Xeon E5-2699 v4 Β· 88 threads Β· 503 GiB RAM Β· RTX 4060 Ti

0
Honeypot Events
0
Unique Attackers
0
Signals Shared
0
Protected Nodes
0
K8S Pods
0
Log Lines Parsed

The Kill Chain β€” Attack to Global Defense

Every attacker follows this path. They think they found a vulnerable server. What they found is a trap wired to 300,000 security systems worldwide.

🎯

Attacker Discovers "Vulnerable SSH"

Shodan, Censys, or mass scanning finds port 22 open. It looks like a real Linux server with weak credentials.

ATTACKER PERSPECTIVE
🍯

Cowrie Honeypot Engages

The attacker connects to a high-interaction SSH honeypot. They see a realistic Debian shell, working file system, fake services. They think they're in.

TRAP ACTIVE
πŸ“

Everything Gets Logged

Every credential attempt, every command, every keystroke, every malware download β€” captured in real-time. TTY sessions recorded for replay.

331,799 EVENTS CAPTURED
πŸ”

CrowdSec Detects Attack Patterns

In parallel, CrowdSec IDS parses 1.21M+ Traefik access log lines in real-time. CVE exploits, brute force attempts, WordPress scanners, path traversals β€” all classified and scored.

1.21M LOG LINES PARSED
🚫

MikroTik Bouncer Blocks at Router Level

CrowdSec pushes the ban decision via REST API to the MikroTik CCR1009 router. The IP is dropped at the network edge β€” before it even reaches the server. Currently 597 active address-list entries.

BLOCKED IN SECONDS
πŸ“±

Operator Notified via Telegram

Real-time Telegram and Discord notifications fire. The operator sees attacker IP, attack type, ban duration, and GeoIP data β€” from their phone, anywhere in the world.

REAL-TIME ALERTS
🌐

Signal Pushed to CrowdSec CAPI

The attack signal is pushed to the CrowdSec Central API β€” a global threat intelligence network of 300,000+ installations. 33,120+ signals contributed from this infrastructure alone.

33,120+ SIGNALS SHARED
πŸ”₯

Attacker IP Burned Globally

The IP is now flagged across the entire CrowdSec community. Every installation that subscribes to the community blocklist will preemptively block this attacker. One trap, global protection.

GLOBAL BAN PROPAGATED
πŸ“Š

Logs Flow to Loki β†’ Grafana

Cowrie logs stream to Loki via the custom cowrie-to-loki pipeline. Grafana dashboards visualize attack patterns, credential trends, geographic origins, and malware families.

DASHBOARDS Β· ANALYTICS Β· REPORTS
πŸ›‘οΈ

Tiered Ban Escalation Engaged

First offense: 3-hour ban (Tier 0). Return visitor: 1-week ban (Tier 1). Persistent threat: permanent ban (Tier 2). The system has memory. Repeat offenders don't get second chances.

TIER 0 β†’ TIER 1 β†’ TIER 2: 3h β†’ 1 WEEK β†’ PERMANENT

Live Intelligence Statistics Live Β· 7 of 9

Not estimates. Not projections. These are verified counts from production systems β€” running right now, 24/7/365.

🍯 Honeypot Intelligence

0
Total Events Captured
Credential attempts, commands, file downloads, session data
0
Unique Attacker IPs
Distinct sources identified and fingerprinted
0
Caught Today
Attackers trapped in the honeypot in the last 24 hours

🌐 Community Contribution

πŸ“Έ Snapshot
0
Signals Pushed to CAPI
Threat intel shared with the global CrowdSec network (cumulative β€” exact counter only via watcher-key auth, not auto-refreshed)
0
Community Blocklist Pulled
Bidirectional β€” we give intel, we receive community protection
πŸ“Έ Global Β· Apr 2026
0
Protected Installations
CrowdSec community nodes receiving our signals β€” global network metric, not local

βš”οΈ Active Defense

0
MikroTik Address-List Entries
Active bans at the router level β€” dropped before reaching the server
0
Traefik Log Lines Parsed
CrowdSec IDS analyzing every request in real-time
0
Threat Intel Feed IPs
Imported from curated threat intelligence feeds

Attack Taxonomy Live Β· per-scenario

Every probe, scan, and exploit attempt is classified, scored, and catalogued. Here's what's hitting this infrastructure β€” right now.

πŸ” HTTP Probing 178
HIGH

Automated scanners probing for exposed endpoints, version fingerprinting, and service enumeration across all HTTP surfaces.

πŸ“ WordPress Scanning 76
HIGH

wp-login, xmlrpc.php, wp-admin brute force, plugin vulnerability scanning. We don't even run WordPress.

πŸ“‚ Sensitive File Access 43
HIGH

Probing for .env files, .git directories, database dumps, backup archives, API keys left in public directories.

πŸ•·οΈ Non-Static Crawling 40
MEDIUM

Aggressive crawlers hitting dynamic endpoints, API routes, and application paths far beyond normal indexing behavior.

πŸ” Admin Interface Probing 34
HIGH

Scanning for /admin, /manager, /phpmyadmin, /adminer, cPanel, and other administrative interfaces.

πŸšͺ HTTP Backdoor Attempts 24
CRITICAL

Attempting to access known web shells, backdoor paths, and remote code execution endpoints left by previous compromises.

⚠️ Jira CVE-2021-26086 6
CRITICAL Β· CVE

Atlassian Jira Server file read vulnerability exploitation attempt. Path traversal to read arbitrary files from Jira installations.

πŸ”΄ Fortinet CVE-2018-13379 β€”
CRITICAL Β· CVE

FortiOS SSL VPN credential theft attempt. Path traversal to extract plaintext credentials from /dev/cmdb/sslvpn_websession.

πŸ’€ Exchange CVE-2022-41082 β€”
CRITICAL Β· CVE

Microsoft Exchange ProxyNotShell RCE. Attackers scanning for vulnerable Exchange servers to achieve remote code execution.

🌐 Path Traversal + Netgear RCE β€”
CRITICAL

Directory traversal attacks and Netgear router remote code execution attempts. Scanning for vulnerable network equipment.

"

🏒 The Bulletproof Glass Building

Imagine a fully transparent office building in the middle of a busy street. Floor-to-ceiling glass walls. Anyone can look inside. It looks inviting β€” maybe even vulnerable.

But the glass is bulletproof. And the interior? Those are LCD screens projecting a convincing fake office. The real operations happen in a bunker underneath.

That's what attackers see when they probe this infrastructure.

The Cowrie honeypot is the LCD screen β€” a pixel-perfect simulation of a vulnerable server that records every move. CrowdSec is the security camera system capturing everything in HD. The MikroTik firewall with its 4-chain architecture is the bulletproof glass β€” 79 filter rules thick.

And every recording β€” every credential attempt, every exploit, every malware sample β€” gets sent to every security company in the world. Not metaphorically. Literally. 300,000+ installations receive our threat intelligence in real-time through the CrowdSec Central API.

The attackers aren't just failing. They're making every other target on the internet harder to attack.

What Scanners Are Probing β€” Right Now Live Β· 24h window

Every 404 hitting the landing-page nginx is logged with the original request URI and aggregated into /honeypot-stats.json. This is what bots are looking for on this infrastructure in the last 24 hours β€” directly, without filtering.

β€”
Total 404 Probes (24h)
β€”
Distinct Paths Probed
Top 15 β€” populated from Loki, refreshed every 15 min
Loading from /honeypot-stats.json…

Scope: nginx pod in shuffle-on-landing namespace only β€” not the cluster-wide attack surface. Source: Loki query {namespace="shuffle-on-landing", app="landing"} | json | status="404". The request_uri log field was added 2026-04-30 β€” give it 24h to fully accumulate.

What Subdomains Scanners Are Guessing Live Β· 24h window

Wildcard DNS routes *.shuffle-on.com to the cluster. Subdomains without an IngressRoute fall through to a catchall middleware that rewrites the path to a sentinel and serves a 404. The Host header preserves what the scanner *guessed* β€” giving a real-time view of attackers' mental model of this infrastructure's namespace.

β€”
Catchall Hits (24h)
β€”
Distinct Subdomains Guessed
Top 15 β€” populated from Loki, refreshed every 15 min
Loading from /honeypot-stats.json…

This is reconnaissance against the namespace, not against any specific page. Each entry is a Host header that doesn't have a real IngressRoute behind it β€” i.e., a guess. Common guesses (admin, portainer, guacamole, lsn-redis) reveal scanner dictionaries; uncommon ones reveal what's been leaked elsewhere about the operator's stack.

Scanner Backlash β€” When They Came Looking πŸ“Έ Apr 2026 Incident

A real incident. Our pentesting activity triggered a counter-response from the LeakIX sensor network. Our defense stack caught them before they finished their first probe.

πŸ”„ The Counter-Scan Incident

LeakIX Sensor Network vs. Shuffle-On Defense Stack

During authorized outbound security testing, the infrastructure's scanning activity was detected by LeakIX β€” a large-scale internet sensor network that monitors scanning behavior globally.

Within seconds of our first outbound probes, LeakIX nodes began counter-scanning our IP ranges. They came to investigate us β€” to fingerprint our services, identify our stack, and catalogue our infrastructure.

T+0s β€” Outbound
Pentest Scan Initiated
Authorized security assessment begins. Outbound probes launched through controlled channels.
T+8s β€” Inbound
LeakIX Counter-Scan Detected
CrowdSec IDS detects inbound reconnaissance from LeakIX sensor IPs. Multiple scan vectors identified.
T+<2min β€” Blocked
MikroTik Bouncer Engages
CrowdSec→MikroTik REST API pipeline fires. LeakIX IPs added to address-list. Telegram alert dispatched.
"They came to investigate us. Our defense stack caught them before they finished their first probe. The entire counter-scan was detected, classified, blocked, and reported β€” automatically β€” in under two minutes."

Defense Stack β€” Every Layer

From the internet edge to the kernel. Seven layers of defense, two bouncers, bidirectional threat intel, and a honeypot sidecar.

🌐 Internet
β†’
☁️ Cloudflare CDN
β†’
πŸ”§ MikroTik CCR1009
πŸ›‘οΈ CrowdSec IDS
β†’
πŸ”€ Traefik Proxy
+
πŸ” Authelia SSO
β†’
☸️ K8S Pods
πŸ¦… Falco
β†’
πŸ“‘ CrowdSec LAPI
⇄
🌍 CrowdSec CAPI · 300K+ Nodes

🍯 Honeypot Sidecar

Port 22
β†’
Cowrie
β†’
Loki
β†’
Grafana

πŸ“± Alert Pipeline

CrowdSec
β†’
MikroTik Ban
+
Telegram
+
Discord
Bouncer #1
🧱 iptables Firewall Bouncer
Host-level Linux firewall integration
Bouncer #2
πŸ”§ Custom MikroTik REST API Bouncer
Pushes bans to router via RouterOS REST API
Overlay
πŸ§… Tor Relay
Contributing bandwidth to the Tor network

πŸ€– Built with GitHub Copilot CLI

Claude Opus 4.6 Β· Sonnet 4.5

This entire defense infrastructure — from the Cowrie honeypot Dockerfile to the CrowdSec→MikroTik bouncer integration, from the Grafana dashboards to the AI-powered pentesting platform with 41 MCP tools — was architected, implemented, and deployed with GitHub Copilot as the primary engineering partner.

The Copilot agent debugged Kubernetes manifests at 2 AM, wrote the cowrie-to-loki pipeline, designed the tiered ban escalation logic, and built the stealth scanning framework that routes through Tor proxy.

Even this page was built by Copilot. It deserves the spot.

✨ Powered by GitHub Copilot