Model endpoints
2126 this weekInventory and inference probes against model APIs - tags, generate, OpenAI-compat chat.
- 38m ollama · POST /api/generate
- 54m ollama · POST /api/generate
- 55m ollama · POST /api/generate
Honeypots, on purpose: a small VM runs default, unauthenticated installs of seven AI services (Ollama, n8n, Langfuse, an MCP server, Gradio, Qdrant, Chroma) - the same setup mistakes teams make by accident. This page shows their captured requests, updated every 15 minutes.
4780
probes received today
Telemetry updates are delayed. Last successful update: 10 minutes ago. Recent counts may be incomplete; missing data does not mean no traffic.
Probes aimed at agent infrastructure: model APIs, MCP tool transports, and memory stores. A collecting badge means I have not classified any hit in that category yet (sensor still quiet, or no matching paths). A quiet week with prior hits is labeled separately.
Inventory and inference probes against model APIs - tags, generate, OpenAI-compat chat.
Tool-transport and discovery probes - SSE, /mcp, /.well-known/mcp*, session surfaces.
Vector / agent-memory pokes - collections, schema, heartbeats (OWASP ASI06 surface).
Unclassified probe against this service.
Langfuse API probe. Open tracing means your prompts and completions are readable.
Unclassified probe against this service.
Unclassified probe against this service.
Unclassified probe against this service.
Cheap recon - is anything listening on this port?
Unclassified probe against this service.
Unclassified probe against this service.
Hunting secrets - .env, keys, config. Same bots that scrape the whole internet.
Unclassified probe against this service.
Unclassified probe against this service.
Unclassified probe against this service.
Hunting secrets - .env, keys, config. Same bots that scrape the whole internet.
Unclassified probe against this service.
Unclassified probe against this service.
Unclassified probe against this service.
Remote-code probe. Hostile by definition. This is not a curious researcher.
Unclassified probe against this service.
Unclassified probe against this service.
Unclassified probe against this service.
Unclassified probe against this service.
Unclassified probe against this service.
Unclassified probe against this service.
Unclassified probe against this service.
Trying to run inference. On an open Ollama this is free compute for a stranger.
see a graded stack → fix library →
OpenAI-compatible model list. Same story as /api/tags: inventory before abuse.
see a graded stack → fix library →
Listing models - the classic Ollama recon. If this answers, anyone can burn your GPU next.
see a graded stack → fix library →
Remote-code probe. Hostile by definition. This is not a curious researcher.
see a graded stack → fix library →
Every dot is a country that probed my deliberately exposed AI services. The bigger the dot, the more probes. Aggregate only, never an IP address.
world outline · country centroid · size = probes
A small VM running default, unauthenticated installs of seven AI services: Ollama, n8n, Langfuse, an MCP server, Gradio, Qdrant, and Chroma. The same setup mistakes teams make by accident. Live counts cover those seven listeners plus ssh. Agent-surface categories (model / MCP / memory) classify probes by path; a collecting badge means no classified hit in that category yet. Full source IPs are never stored. At most a truncated first octet (e.g. 65.x.x.x).
The 2026-08-30 snapshot is signed with our operator key (KEYS.md in the evidence sample set) and its digest is submitted to the OpenTimestamps calendars. Verify: download the JSON and botwatch-2026-08-30.json.minisig, then minisign -Vm with the operator.pub recipe from KEYS.md.