Cybersecurity · 2025
AI-Agent Honeypot
A decoy website that writes itself while the attacker is still looking.
- Status
- Research · HSG bachelor thesis
- Stack
- Python / FastAPIClaude Agent SDKPostgreSQLNext.js dashboardDocker Composeskipfish
- Links
My bachelor thesis at the University of St.Gallen: an HTTP honeypot where an AI agent generates a complete, consistent fake website on demand for every path an attacker probes, with every request logged for analysis. Benchmarked against Galah, an established open-source LLM honeypot, it produced much richer and more realistic content, at the cost of slower first responses.
What it does
- The agent writes real files for each attacker session, not just generated text
- Each visitor gets their own coherent file tree that reuses the site's CSS and JS
- Full forensic logging of every request and response, grouped into sessions
- Containment: firewall-isolated agent container, write access to one folder only, resource limits
The consulting angle
Deception research tested against a baseline with an automated scanner and 55 OWASP Top 10 attacks.
ATTACKER
GET /admin/.envFASTAPI :8000
parse path · check cachePOSTGRESQL
every request + responseCACHE HIT
return session file instantlyCACHE MISS → AGENT
Claude Code · firewall-isolated · writes ONE filePER-SESSION FILE TREE
generated/ └─ <session>/ ├─ style.css ├─ login.php ├─ script.js └─ admin/.env ← new
Next project
The Notification App
07 · Contact
Have an idea? Let's ship it.
Tell me what you're building, or what's still on paper. I usually reply within a day, in English, French or German.