Autonomous Threat Disruption Engine
Defensive honeypot · asymmetric deception · local-first containment
for infrastructure you own
Catch attackers (start here) · pkg.go.dev · Release 2.0 · Deploy · Operate · Architecture · Configure · Acquisition · Get the rights · Valuation · SKUs · IP · Changelog · Legal
Product name: ATDE | Historical repo dirname:
blind-botnet(do not lead marketing with this name)
Brand assets:docs/BRANDING.md· Wordmark:docs/assets/logo-wordmark.svg
Docs: pkg.go.dev/github.com/theworker02/ATDE/v2
go get github.com/theworker02/ATDE/v2@latestModule path: github.com/theworker02/ATDE/v2 (matches the GitHub repo theworker02/ATDE).
Deploy ATDE 2.0 on a public VPS → ten decoys disrupt scanners with graduated policy → every attack is recorded, clustered, and exportable under data/caught/ (console :9091/console).
You do not need Cloudflare, AWS, or AbuseIPDB keys to catch and contain attackers locally. Those are optional escalations.
One-page playbook: docs/CATCH.md · Release: RELEASE.md
cp .env.example .env
docker compose -f deployments/catch-node.yml up -d --build
# bait: 8080,2222,6379,2323,3306,2121,2525,9200,27017,8443 — lock 9091
bash scripts/verify-catch.sh
# review: http://YOUR_IP:9091/console · campaigns: /v1/campaignsATDE is an event-driven defensive security appliance you run on hosts and edges under your control. It baits scanners on decoy surfaces, scores and dossiers every hit, then contains locally first (Linux ipset / iptables / nft, Windows netsh). Cloudflare, AWS WAFv2, AbuseIPDB, and related APIs are optional best-effort escalations — missing credentials or cloud failures never abort the catch pipeline.
┌──────────────┐ ┌─────────────────────┐ ┌──────────────────┐
│ 1. BAIT │────▶│ 2. DOSSIER ENGINE │────▶│ 3A. LOCAL FW │
│ 7 surfaces │ │ events.jsonl │ │ ipset · netsh │
│ HTTP··FTP·· │ │ dossier_<IP>.json │ │ (mandatory path) │
└──────────────┘ └─────────────────────┘ └──────────────────┘
│
┌─────────────┼─────────────▶┌──────────────────┐
▼ ▼ │ 3C. EXPORT │
┌──────────────┐ ┌──────────┐ │ abuse · STIX │
│ 3B. NOTIFY │ │ OpenAPI │ │ OpenAPI catch API│
│ PGP · webhook│ │ :9091 │ └──────────────────┘
└──────────────┘ └──────────┘
│
└────────────▶┌──────────────────┐
│ 3D. CLOUD/ABUSE │
│ CF · AWS · TIP │
│ (best-effort) │
└──────────────────┘
Seven bait surfaces: Atlas HTTP · SSH · Redis · Telnet · MySQL · FTP · deception L7.
Backed by NATS JetStream (THREAT_PIPELINE) with typed subjects under threat.v1.*.
| Item | Path | Description |
|---|---|---|
| All-in-one binary | cmd/atde |
Modes: all, catch-node, honeypot, caught, doctor, dossier, export, abuse, stix, seed-demo, watch, status, … |
| CT / dispatcher entrypoints | cmd/ct-streamer, cmd/dispatcher | Split-process blueprint |
| Docker image | Dockerfile | Distroless-friendly Go build + iptables/ipset |
| Compose stack | deployments/docker-compose.yml | NATS JetStream + ATDE catcher |
| Live config | configs/config.yaml | Production defaults (live: true) |
| Lab config | configs/config.example.yaml | Dry-run template |
| Env template | .env.example | Secrets checklist |
| Event schemas | schemas/*.json | JSON Schema drafts for the bus |
| Makefile | Makefile | build, test, up, caught, release |
| Version stamp | VERSION | Semver 2.0.2 (atde -version) |
| Package | Responsibility |
|---|---|
internal/natsbus |
JetStream connect, publish, durable consumers, DLQ |
internal/ingest/ct |
CertStream + brand RuleEngine |
internal/ingest/honeypot |
Atlas Control Plane HTTP portal + SSH/Redis/Telnet/MySQL/FTP baits |
| internal/ingest/rules | Phishing / brand heuristics |
| internal/extract | Artifact + IoC isolation |
| internal/enrich | Infra map → takedown / sinkhole / publish events |
| internal/catch | Audit ledger + rolling dossiers |
| internal/disrupt/active | Phase-4 controller |
| internal/disrupt/edge | Local-first EnforceContainment + ipset/netsh |
| internal/disrupt/tarpit | Slow-byte protocol starvation |
| internal/disrupt/poison | Evidence-only exfil simulation |
| internal/disrupt/dispatcher | Abuse Markdown + provider posts |
| internal/immunize | Cloudflare + AWS WAFv2 adapters |
| internal/deception | Asymmetric L7 honey-interface |
| internal/sinkhole | Owned DNS rewrite orchestration |
| internal/publish | STIX 2.1 + community intel channels |
| internal/harden | Optional anti-analysis / seccomp |
| internal/config | YAML + live cascade + secret hydration |
| Document | Audience |
|---|---|
| RELEASE.md | 2.0.0 threat disruption release notes |
| acquisition.md | Buyers / diligence |
| docs/IP.md | Intellectual property schedule |
| docs/data-room/INDEX.md | Virtual data room |
| docs/CATCH.md | Deploy bait → record attacks |
| docs/DEPLOY.md | First install & verify |
| docs/OPERATOR.md | Day-2 operations |
| docs/ARCHITECTURE.md | Engineers |
| docs/CONFIGURATION.md | Full config map |
| docs/HONEYPOT.md | Atlas portal / SSH burn / demo |
| docs/VALUATION.md | Pre-revenue rebuild thesis |
| docs/BRANDING.md | Logo & trademarks |
| docs/LEGAL.md | Acceptable use |
| SECURITY.md | Vulnerability disclosure |
| CHANGELOG.md | Releases (Keep a Changelog) |
| CONTRIBUTING.md | DCO / contribution rules |
| CODE_OF_CONDUCT.md | Community norms |
| LICENSE / NOTICE / THIRD_PARTY_NOTICES.md | Apache-2.0 + attribution |
| AUTHORS / COPYRIGHT | Copyright holders |
| CITATION.cff | Academic citation |
.github/workflows/ci.yml |
Test + build badges |
.github/ISSUE_TEMPLATE/* |
Bug / feature forms |
.github/FUNDING.yml |
Sponsors + thanks.dev |
| Artifact | Location |
|---|---|
| Append-only audit log | data/caught/events.jsonl |
| Per-IP rolling dossier | data/caught/dossier_<IP>.json |
| Daily shards | data/caught/caught-YYYY-MM-DD.jsonl |
| Abuse packages | data/evidence/*-abuse-report.md |
- Local-first containment — OS block is the guaranteed path; cloud is async and fail-soft
- High-scale Linux bans —
ipsethash set (atde_honeypot_bans, 24h TTL) + one iptables match-set rule - Safe exec — firewall binaries via argv
exec.CommandContext(no shell) - Private IP refusal — loopback / RFC1918 / TEST-NET never OS-blocked
- Seven-surface decoy mesh — Atlas (
:8080), SSH (:2222), Redis (:6379), Telnet (:2323), MySQL (:3306), FTP (:2121), deception (:8443) - CT monitoring — brand-aware certificate transparency streaming
- Intel packaging — STIX 2.1 + abuse Markdown (CLI + catch API); AbuseIPDB / MISP / Mastodon / Gist when keyed
- Owned-edge immunize — Cloudflare Access Rules + AWS WAFv2 IPSet
- Operator CLI —
caught/dossier/export/abuse/stix/seed-demo/watch/doctor/status - Operator console — read-only UI at
:9091/console+ catch REST API + OpenAPI at:9091/v1/openapi.json - Catch webhooks — optional
ATDE_WEBHOOK_URLon every ledger write - Encrypted owner email — SMTP + OpenPGP alerts when attackers are recorded
.\scripts\quickstart.ps1
# then:
.\bin\atde.exe -config configs\config.yaml -mode all
# console: http://127.0.0.1:9091/consolebash scripts/quickstart.sh
./bin/atde -config configs/config.yaml -mode allgit clone https://github.com/theworker02/ATDE.git
cd ATDE
cp .env.example .env
docker compose -f deployments/docker-compose.yml up -d --build
# Probe decoys locally
curl -sS http://127.0.0.1:8080/wp-login.php
curl -sS "http://127.0.0.1:8443/api/v1/debug?cmd=id"
# Review ledger (from host with ./data mounted)
go run ./cmd/atde -mode caughtExpose TCP 8080, 2222, 6379, 2323, 3306, 2121, and 8443 on a public IP (or port-forward) to collect internet scanners. The :8080 portal looks like a real ops gateway — see docs/HONEYPOT.md.
docker compose -f deployments/docker-compose.yml up -d nats
cp .env.example .env
go mod tidy
go test ./...
make build
# PowerShell
$env:NATS_URL = "nats://127.0.0.1:4222"
$env:ATDE_LIVE = "1"
.\bin\atde.exe -config configs\config.yaml -mode all# bash
export NATS_URL=nats://127.0.0.1:4222 ATDE_LIVE=1
./bin/atde -config configs/config.yaml -mode all| Check | Command |
|---|---|
| Version | atde -version → 2.0.0 |
| Doctor | atde -mode doctor |
| Console | http://HOST:9091/console |
| OpenAPI | http://HOST:9091/v1/openapi.json |
| Honeypot | curl http://HOST:8080/ · .\scripts\demo-honeypot.ps1 |
| Metrics | curl http://HOST:9091/metrics |
| Deception | curl "http://HOST:8443/.env" |
| Ledger | atde -mode caught · atde -mode abuse -ip <IP> · atde -mode stix -ip <IP> |
| Seed demo | atde -mode seed-demo |
| NATS | http://127.0.0.1:8222/healthz |
Full install guide: docs/DEPLOY.md.
| Profile | How | When |
|---|---|---|
| Live catcher | configs/config.yaml + ATDE_LIVE=1 |
Internet-facing decoy node |
| Lab / CI | ATDE_DRY_RUN=1 or config.example.yaml |
No OS blocks / no live API posts |
| Local FW only | Live + no cloud env vars | Contain without Cloudflare/AWS |
| Cloud escalated | Live + CF/AWS/Abuse keys | Owned accounts only |
Disable OS blocks anytime: ATDE_LOCAL_FIREWALL=0.
| Mode | Starts | Use |
|---|---|---|
all |
Full mesh (default container entrypoint) | Production catcher |
honeypot / tarpit |
Decoys + extract + active | Lightweight bait node |
deception |
L7 honey-interface + active | App-edge deception |
ct |
Certificate Transparency only | Passive monitor |
extract / enrich / dispatch |
Pipeline stages | Horizontal scale |
active |
Containment consumer | Edge worker |
sinkhole / publish |
DNS rewrite / intel | Optional stages |
caught |
Ledger printer | Ops review |
version |
Semver | Releases / CI |
- Decoy records telemetry →
data/caught/events.jsonl+ upsertsdossier_<IP>.json - Event published on
threat.v1.raw.honeypot(confidence 0.9+) - Active defense emits
threat.v1.action.disrupt EnforceContainmentapplies local block, then best-effort cloud bans- Enrich may queue abuse packages / AbuseIPDB when keys exist
| Variable | Effect |
|---|---|
CLOUDFLARE_API_TOKEN + CLOUDFLARE_ZONE_ID |
Zone Access Rule blocks |
AWS_WAF_IPSET_ID + AWS_WAF_IPSET_NAME |
WAFv2 IPSet updates |
ABUSEIPDB_API_KEY |
Live IP reports |
SIEM_WEBHOOK_URL |
Attack event fan-out |
COREDNS_REWRITE_API / CF_GATEWAY_REWRITE_URL |
Owned DNS sinkhole |
Complete map: docs/CONFIGURATION.md.
See docs/OPERATOR.md for rotation, incident packages, and tuning.
Event bus subjects and trust boundaries: docs/ARCHITECTURE.md.
| Subject | Purpose |
|---|---|
threat.v1.raw.ct |
Suspicious CT domains |
threat.v1.raw.honeypot |
Honeypot / deception captures |
threat.v1.artifact.extracted |
Isolated IoCs |
threat.v1.artifact.attack |
Deception attack events |
threat.v1.action.takedown |
Abuse packages |
threat.v1.action.disrupt |
Containment |
threat.v1.action.sinkhole |
Owned DNS rewrites |
threat.v1.action.publish |
STIX / community intel |
threat.v1.action.dlq |
Dead-letter |
| Not implemented | Why |
|---|---|
| Live Telegram / Discord floods with stolen tokens | Unauthorized access; evidence simulation only |
| Live Mirai/Hajime (etc.) DHT peer injection | Third-party network interference |
| OS blocks of private / loopback / TEST-NET | Operator safety |
Catching attackers does not depend on those features. See docs/LEGAL.md.
go test ./...
make build
make caughtCI: .github/workflows/ci.yml (vet, test, build artifact).
Contributing: CONTRIBUTING.md.
Diligence packet: acquisition.md · Release: RELEASE.md · Take the rights: GETTING-THE-RIGHTS.md · IP: docs/IP.md · Data room: docs/data-room/INDEX.md.
- GitHub Sponsors:
theworker02 - thanks.dev:
u/gh/theworker02 - Security reports: SECURITY.md
Copyright 2026 theworker02. Licensed under the Apache License 2.0.
| Badge | Meaning |
|---|---|
| docs live | Public documentation / Pages surface for ATDE |
| release v1.0.0 | Stable tagged release with narrative notes |
| license | See repository LICENSE for terms |
| status maintained | Actively kept in the @theworker02 portfolio |
| version 1.0.0 | Documentation and brand completeness milestone |
| pages enabled | Site intended at https://theworker02.github.io/ATDE/ |
Detailed narrative for the stable line lives in CHANGELOG.md and the v1.0.0 GitHub Release.
See ACQUISITION.md for the diligence-oriented product brief, asset map, and commercial posture notes.