Panagiotis Gkilis

Defensive Observability · Deception Telemetry

BedVibe Security Telemetry

Always-on defensive telemetry for real internet traffic.

BedVibe Security Telemetry combines a controlled honeypot with read-only production Nginx abuse-log analysis. It turns raw scanner noise into calibrated security intelligence: what was probed, what was blocked, what requires action, and what is safe to ignore.

Read-only log analysis Scanner / exploit classification Calibrated severity Controlled honeypot Redacted reporting
READ-ONLY · no routing changes · no raw logs exposed

What this proves

  • Real production traffic analyzed, not synthetic samples.
  • Sensitive probes were blocked or returned 404; 0 successful probes observed in the captured window.
  • Severity is calibrated so routine scanner noise does not create false alarms.

Security Telemetry Cockpit

Total requests

18,545

captured window

404 responses

18,203

98% — scanner noise

Scanner / exploit probes

9,430

classified by category

Observed sources

843

incl. Cloudflare edge + direct

Severity: Medium 0 sensitive paths served · 0 successful probes · no action needed

Assessment: elevated scanner volume, but every sensitive probe was blocked or returned 404.

Portfolio-safe cockpit view generated from redacted summary data. Full logs and raw IPs remain private on the server.

Architecture

Production Nginx logs Read-only analyzer Scanner classification Calibrated severity Private report + redacted public summary Cockpit UI
Port 5004 honeypot Decoy events Collector Report pipeline
Safety by design. No routing changes. No Nginx config changes. No credential collection. No raw log exposure. The honeypot remains isolated, and source IPs are redacted in any shareable output.

End-to-end proof chain

From raw production traffic to a delivered, redacted report — every stage of the system, captured. No raw logs, full IP addresses, or token URLs are shown.

Redacted telemetry cockpit

BedVibe Security cockpit: 18,545 requests, 9,430 scanner probes, 0 sensitive paths served, MEDIUM severity, with source IPs masked to the last octet.

Real production traffic classified into scanner probes, severity, and action status.

View full-size →

Private customer report

The private BedVibe Security report page with the embedded cockpit, shown without a browser address bar or token URL.

The customer-facing report view, rendered without raw logs, full IPs, or token URLs.

View full-size →

Delivery engine dry-run

Terminal output of the delivery pipeline dry-run: validates config, publishes redacted artifacts, renders the email, and confirms no email was sent.

The report pipeline validates, publishes redacted artifacts, renders the email, and confirms no send during dry-run.

View full-size →

Delivered report email

The delivered BedVibe Security report email showing the WATCH report card in an inbox, with reply and forward controls.

The first real BedVibe Security report delivered to an inbox through the transactional sender.

View full-size →

What the system detected

From the captured analysis window (read-only production access logs):

SignalValue
Total requests18,545
404 responses18,203 (98%)
Scanner / exploit probes9,430
Observed sources843
Sensitive paths served (2xx)0

Top probe categories: config probes · .env files · admin panels · backups · PHP RCE · .git exposure · .ssh keys · Spring actuator · AWS credentials.

A path-traversal RCE attempt (/cgi-bin/…/bin/sh) was observed and returned 404. The dominant client was an automated curl agent (the bulk of the requests).

The traffic represents normal internet background scanning — but the system makes it measurable, explainable, and actionable instead of invisible.

When action is needed

Action is escalated only on a genuine signal — not on routine noise:

  • A sensitive probe returns 2xx (something was served).
  • Repeated 5xx occurs on sensitive probe paths.
  • Direct-origin traffic spikes far beyond baseline.
  • A new high-risk pattern appears.
  • Scanner activity changes sharply versus history.

Normal all-404 scanner traffic stays low / medium with no action needed.

From portfolio system to managed service

  • Managed installation on a customer VPS / server.
  • Read-only log analyzer — no routing or config changes.
  • Redacted daily / weekly reports.
  • Optional controlled honeypot.
  • Exposure checks for customer-owned domains only.
  • Alerting only on meaningful anomalies.

Roadmap

  • 7-day and 30-day trend history.
  • Baseline anomaly detection.
  • Email / Telegram alerting for real action conditions.
  • Security-header analyzer.
  • Self-owned domain exposure scanner.
  • Cloudflare-aware source labeling.
  • Multi-server reporting.
  • Install script and config wizard.

Available as a managed defensive telemetry installation for owned infrastructure.

Want this monitoring run for your own server? See BedVibe Security →

View the managed service Request managed setup