← All work

Cybersecurity · 2025

AI-Agent Honeypot

A decoy website that writes itself while the attacker is still looking.

Status
Research · HSG bachelor thesis
Stack
Python / FastAPIClaude Agent SDKPostgreSQLNext.js dashboardDocker Composeskipfish
Links

My bachelor thesis at the University of St.Gallen: an HTTP honeypot where an AI agent generates a complete, consistent fake website on demand for every path an attacker probes, with every request logged for analysis. Benchmarked against Galah, an established open-source LLM honeypot, it produced much richer and more realistic content, at the cost of slower first responses.

What it does

  • The agent writes real files for each attacker session, not just generated text
  • Each visitor gets their own coherent file tree that reuses the site's CSS and JS
  • Full forensic logging of every request and response, grouped into sessions
  • Containment: firewall-isolated agent container, write access to one folder only, resource limits

The consulting angle

Deception research tested against a baseline with an automated scanner and 55 OWASP Top 10 attacks.

ATTACKER

GET /admin/.env

FASTAPI :8000

parse path · check cache

POSTGRESQL

every request + response

CACHE HIT

return session file instantly

CACHE MISS → AGENT

Claude Code · firewall-isolated · writes ONE file

PER-SESSION FILE TREE

generated/
└─ <session>/
   ├─ style.css   ├─ login.php
   ├─ script.js   └─ admin/.env  ← new
Architecture v3.1 · simplified from the thesis

Next project

The Notification App

→

07 · Contact

Have an idea? Let's ship it.

Tell me what you're building, or what's still on paper. I usually reply within a day, in English, French or German.