Defensive Observability · Deception Telemetry
BedVibe Security Telemetry
Always-on defensive telemetry for real internet traffic.
BedVibe Security Telemetry combines a controlled honeypot with read-only production Nginx abuse-log analysis. It turns raw scanner noise into calibrated security intelligence: what was probed, what was blocked, what requires action, and what is safe to ignore.
What this proves
- Real production traffic analyzed, not synthetic samples.
- Sensitive probes were blocked or returned 404; 0 successful probes observed in the captured window.
- Severity is calibrated so routine scanner noise does not create false alarms.
Security Telemetry Cockpit
Total requests
18,545
captured window
404 responses
18,203
98% — scanner noise
Scanner / exploit probes
9,430
classified by category
Observed sources
843
incl. Cloudflare edge + direct
Assessment: elevated scanner volume, but every sensitive probe was blocked or returned 404.
Portfolio-safe cockpit view generated from redacted summary data. Full logs and raw IPs remain private on the server.
Architecture
End-to-end proof chain
From raw production traffic to a delivered, redacted report — every stage of the system, captured. No raw logs, full IP addresses, or token URLs are shown.
Redacted telemetry cockpit
Real production traffic classified into scanner probes, severity, and action status.
View full-size →Private customer report
The customer-facing report view, rendered without raw logs, full IPs, or token URLs.
View full-size →Delivery engine dry-run
The report pipeline validates, publishes redacted artifacts, renders the email, and confirms no send during dry-run.
View full-size →Delivered report email
The first real BedVibe Security report delivered to an inbox through the transactional sender.
View full-size →What the system detected
From the captured analysis window (read-only production access logs):
| Signal | Value |
|---|---|
| Total requests | 18,545 |
| 404 responses | 18,203 (98%) |
| Scanner / exploit probes | 9,430 |
| Observed sources | 843 |
| Sensitive paths served (2xx) | 0 |
Top probe categories: config probes · .env files ·
admin panels · backups · PHP RCE · .git exposure · .ssh keys ·
Spring actuator · AWS credentials.
A path-traversal RCE attempt (/cgi-bin/…/bin/sh) was observed and returned 404.
The dominant client was an automated curl agent (the bulk of the requests).
When action is needed
Action is escalated only on a genuine signal — not on routine noise:
- A sensitive probe returns 2xx (something was served).
- Repeated 5xx occurs on sensitive probe paths.
- Direct-origin traffic spikes far beyond baseline.
- A new high-risk pattern appears.
- Scanner activity changes sharply versus history.
Normal all-404 scanner traffic stays low / medium with no action needed.
From portfolio system to managed service
- Managed installation on a customer VPS / server.
- Read-only log analyzer — no routing or config changes.
- Redacted daily / weekly reports.
- Optional controlled honeypot.
- Exposure checks for customer-owned domains only.
- Alerting only on meaningful anomalies.
Roadmap
- 7-day and 30-day trend history.
- Baseline anomaly detection.
- Email / Telegram alerting for real action conditions.
- Security-header analyzer.
- Self-owned domain exposure scanner.
- Cloudflare-aware source labeling.
- Multi-server reporting.
- Install script and config wizard.
Available as a managed defensive telemetry installation for owned infrastructure.
Want this monitoring run for your own server? See BedVibe Security →
View the managed service Request managed setup