Kinryū Labs · Honeypot telemetry

Honeypots that log the whole attack.

Down to every prompt sent to the decoy AI services. Around 90 fake services across a few regions: SSH, databases, industrial protocols, and some decoy Ollama and Langflow endpoints. They log whatever arrives. The AI decoys keep the prompt in full. More than 1,000,000 events on an ordinary day, all of it queryable.

See plans Read the reports From $25/month · billed by Polar
Sensors
~90several regions
Events, ordinary day
>200,000
Ports watched
65,535per sensor
Decoy services
SSH · DB · ICS · LLM
Query syntax
SPL / ES|QL pipes
History
full retention

Live

Unusual today

Ports running above their own recent baseline across the sensor fleet. Read straight from the same store the API queries.

Port Service Last 24h Conns Sources Change
8291MikroTik Winbox52108.9× typical
445SMB1,034167.6× typical
5985WinRM174474.7× typical
3306MySQL204572.7× typical
389LDAP87152.0× typical
2000Cisco SCCP34132.0× typical
8080HTTP alt195701.8× typical
7547TR-06957121.8× typical
23Telnet175701.4× typical
31 portsport sweep1,7863370.9–47.0× typical

Sensor last reported 73 hours ago, so the figures below are not current.

02

What the sensors record

The whole exchange, not the request around it. Most of it is background scanning; the baseline exists so the exceptions stand out.

AI / LLM

Decoy language-model services

Ollama, Langflow and an LLM proxy, presented as real. When an exploit carries a prompt, the prompt is kept verbatim and stored next to the request that delivered it.

ICS

Industrial protocols

Modbus, S7, DNP3 and others. Known internet-wide scanners are tagged as scanners, not counted as attacks, so the counts you get are not inflated by census traffic.

Ports

The full 65,535-port range

Every port on every sensor. A port that has never been touched showing up with thirty sources in a day is the kind of thing the baseline is there to catch.

Payloads

Second-stage fetches, by hash

Whatever an exploit tries to pull down is recorded by hash. Failed fetches are logged as well; a distribution host that refuses you is still a finding.

03

Query it

One endpoint, one header, pipe syntax over the full retained history. If you have written Splunk SPL or ES|QL you already know it.

# any plan with an API key
curl -H "X-API-Key: $KEY"   "https://portal.kinryu.sh/api/analyze?q=<query>"
  • event=langflow_rce_attempt earliest=-30d | stats count by ip Who has been trying the Langflow RCE this month, and how hard.
  • event=ai_prompt_captured earliest=-7d | stats count by intent What people are asking the decoy models to do, grouped by classified intent.
  • proto=modbus earliest=-24h scanner=false | stats dc(ip) by sensor Distinct non-scanner sources touching Modbus per sensor, last day.
04

Recent finding

31 July 2026 CVE-2025-3248
Langflow · unauthenticated RCE
11 hashes recovered

A Mirai drop that hid from cloud addresses

The Langflow decoys took an unauthenticated RCE that pulled a shell loader, which in turn fetched ten architecture-specific Mirai binaries. Routine so far.

Automated collection failed three times. The distribution host answered on 22 and 8080 but silently dropped cloud IP ranges on 80 and 443, so every sensor that tried to fetch the payloads from its own address got nothing and no error. Fetching from a non-cloud egress recovered all 11 hashes on the first attempt.

The failed fetches are in the record alongside the successful one. That is the point of logging them.

All write-ups →
05

Plans

Prices in USD. Billed by Polar as merchant of record, which handles local sales tax. Cancel from your Polar receipt at any time.

Public

Read what we publish. No account.

Free

no sign-up

  • Published reports
  • Monthly summary

Lab

For a team that wants the raw data and the history.

$100/ month

5 accounts · 300 req/min

  • Everything in Researcher
  • Full capture history
  • Raw event export
  • Webhook on novel captures
Subscribe

Checkout on Polar. Cancel any time.

Dataset

One packaged, citable collection.

$129one-off

current: IoT botnet infection chain

  • Complete chain, loader to binaries
  • Citable; DOI on request
  • Faulty file fixed and reissued

Before you check out

Use the email you want to sign in with. It becomes your username, and the licence key Polar emails to it is your first password. You can change both once you are in.

Subscriptions are self-serve and carry no SLA. If the feed is down, it stays down until one person fixes it. That is usually quick. Rate limits are per account and are not a soft ceiling.

06

What you are buying, and what you are not

The data

  • Most of it is noise. Mass scanners and census traffic are kept because they are the baseline, not because they are interesting.
  • The rare captures are the point: a working exploit, a prompt nobody has sent before, a payload host that discriminates by address.
  • No named-actor attribution. You get addresses, hashes, timing and content. Who is behind it is your call, not ours.
  • No SLA on self-serve plans. This is a one-person operation and is priced like one.

Collection and data use

  • Sensors run on servers we own. Nothing is collected from anyone else's infrastructure.
  • Only hashes leave the box. No live samples and no working exploit code are distributed through any plan.
  • Source addresses may be personal data in your jurisdiction. You handle them under your own lawful basis; we do not grant one.
  • Datasets are licensed for research and internal use. Redistribution terms are in the licence that ships with each one.
Billing

Polar is the merchant of record for every purchase on this site and any refund is handled under its policy, not ours. If a dataset file is faulty we fix it and reissue it to you. The full terms are at /terms.