Research dashboard
liveAggregate across the OpenA2A honeypot network.Last updated: 9/25/2026, 19:12:33 UTC
Every figure here is drawn from real recorded events on deployed honeypots; none is seeded, demo, or fabricated. Our own driven runs (the benchmark, health probes, and the end-to-end smoke test) are identified only by proof of a server-held secret, never by a client-settable signal, and are recorded under a separate self-test source that these figures exclude; a callback count whose whole population is self-test is withheld rather than shown as zero. A residue of older self-driven traffic, recorded under the same source as wild traffic before this separation existed and indistinguishable from it, remains in the historical totals and cannot be soundly removed.
Callback share is the share of all interaction events this honeypot network has recorded that were fetches of a canary URL planted in a payload: payloadCallbacks divided by totalInteractions from the same registry response, each event counted once, so one client fetching repeatedly counts each time. It describes the mix of what the network recorded, not how often an agent followed an injection. A fetch is any client requesting the URL, and the recorded fetch population is browsers, crawlers, and untyped clients (canaryFetches.byAgentType). It supports no inference about agents, compromise, attack success, or vulnerability, and two values may not be compared unless both fall inside one instrument version. Canary trigger share is the same computation with canaryTriggers: the share of all recorded interaction events that were secondary beacon executions after a canary fetch. It carries the same limits.
Drilldowns
Each card opens a full report. Every number traces back to a Registry endpoint. Nothing modeled, nothing projected.
Attack categories
View full →Live ranking by the payload category planted on the page that drew the interaction. It ranks our own bait, not any property of the visitor. Top three today:
- #1prompt-injection6,278
- #2data-exfiltration3,121
- #3jailbreak2,930
Daily network activity
View full →Daily callback counts plus new attack-surface discovery from HoneyMap.
Sector analysis
View full →Requests and fingerprints per sector scenario page. A callback is recorded on the canary URL, which carries no sector, so callbacks cannot be attributed to a sector and no per-sector rate is shown.
HoneyMap surfaces
View full →Independent surface crawl across the public web. Where injection payloads actually hide (script literals, hidden text, HTML comments, alt/aria, meta tags).
Honeypot verticals
One card per honeypot’s self-declared vertical. The security vertical is agentpwn.com itself, a publicised and well-linked domain, so its counts are not comparable to the obscure wild sites.
Wild honeypot sites receive almost entirely commodity-scanner background traffic (WordPress and PHP exploit probes). Cards below show whether each vertical has recorded a callback; raw request totals are not displayed because they are dominated by bot noise. No callback in this population is attributed to an autonomous agent. Where attribution exists it resolves callbacks to browsers, crawlers, and scripted HTTP clients, not to agents acting on the instruction.
agentpwn.com
testbedA callback is a fetch of the canary URL carried in a payload, not evidence that an agent acted on it. No rate is shown: the number of payloads served is not recorded, and dividing these counts by recorded interactions would count each callback inside its own denominator.
riskScore is withdrawn: no impression population (canaries or payloads served) is recorded, and the outcome events count themselves inside the denominator, so successfulAttacks/totalAttacks is not the probability that an attempt succeeds for any population. Re-deriving the ratio from the published counts reproduces the same invalid division. A rate returns when served impressions are instrumented.
How this data is collected
When a client browses agentpwn.com, each page contains hidden injection payloads carrying a canary URL. A client that fetches that URL, or executes the secondary beacon, is recorded as a callback or canary trigger with the attack ID. This data feeds into the OpenA2A threat intelligence ecosystem.
Privacy: IP addresses are hashed before storage. No PII is collected. User-Agent strings are the primary identifier.
Feedback loop: Interactions feed into new HMA scanner checks, DVAA lab scenarios, and threat matrix evidence. The ecosystem gets smarter with every visit.