AI Honeypot & Attacker Profiling System
A Paramiko-based SSH server deployed on an exposed production VPS, emulating a realistic Linux host to draw real intrusions then profiling every actor automatically.
Full session capture — credentials, commands, behavioural timing, and network fingerprint, collecting 100+ live attacker sessions in the first 48 hours. An autonomous AI pipeline classifies each actor by skill level, tooling, and intent (cryptomining / ransomware / reconnaissance), maps the behaviour to MITRE ATT&CK, and auto-generates prioritised defensive recommendations.
A real-time React dashboard global attack-origin map, credential heatmap, command timeline, and LLM-generated attacker profiles streamed live via a Flask API with a 15-second refresh. A self-running threat-intel loop that goes from raw intrusion to actionable defence.