The first 24 days. Before comprehensive reporting, it was clear that the MIRE had teeth.
Dec 8–31, 2025. From the earliest surviving line to the last hour of the year — reconstructed straight from the logs, one connection line paired with one impact line per request, exactly as the maze wrote it down at the time.
Without a deception layer, commodity scanners keep iterating through mistakes, forgotten routes, and noisy framework errors until they find something useful.
The three-part design was already there and already working on day one: deceive, delay, detect.
2,164 distinct decoy paths hit in 24 days. Fake PHP, admin panels, CI/CD configs, .env files, cloud metadata — all authentically rendered.
IP-based progressive slowdown, live from the start. The slowest single response of the month held an attacker for 9.06 seconds — every one of those seconds billed to them, not to a real service.
Canary tokens baked into fake archives, credentials, and config files — already loaded 3,960 times this month. Fires on exfiltration. Real attribution on who took what.
base + ip_extra = total, the per-IP surcharge that makes repeat offenders wait longer. From a dev IP, then never logged again.Chinese VOD piracy scrapers found the maze inside the first month — hunting media platforms that don't exist here, in paths full of non-ASCII characters.
No user-agent logging yet, so there are no fingerprints to lean on. Every host below is known purely by behaviour: request volume, the paths it chose, its timing.
Every number on this page is real — but this chapter has genuine holes worth naming up front. For these 24 days, the maze bit hard and logged the impact, yet three things it does record now, it simply wasn't recording yet.
No [host] field in the logs yet. Every request in this chapter is anonymous as to which of the cluster's domains received it.
User agents weren't logged yet. The heaviest hitters are known only by IP and behaviour — no fingerprints to lean on.
Whatever attackers submitted to the decoy login forms went unrecorded. The knocks are counted; the payloads are not.
Requests by hour (server local time) — attacks never sleep, even in week one.
The delay engine doesn't treat every path the same — it groups them into categories, each with its own timing. By the end of week one, of all categorized delay hits were wp_login alone.
Twenty-four days, 31,159 trapped requests, 2.57 GB of treacle, and 28 hours of attacker time burned — all before the instrumentation that describes it existed. The bite was there from the first line. Everything that came after was learning to write it down.
"Turn your noise into their cost."
Production honeypot. Real data. Live since December 2025.
← Back to the mazeLee Mössner