TFTP Honey Pot Results
A security researcher analyzed traffic captured by a TFTP honey pot, finding that the vast majority of probes originated from automated scans by cybersecurity companies rather than malicious actors. The author details the technical challenges of identifying and categorizing these repetitive, daily network requests.
Why it matters
This provides insight into the noise levels in cybersecurity monitoring and the prevalence of automated scanning by infosec firms.
2026-07-12 (Last Modified: 2026-07-13) My TFTP honey pot has been running for over a month, continuously on my $5 a month VPS, and intermittently on my Dell R530 home server. It's time to see what surprises it has captured.
When the TFTP honey pot runs, both servers see between 20 and 50 TFTP packets per day. Both servers see mostly the same traffic. I was extremely excited when I got daily UDP port 69 traffic, most of it in TFTP format. I was let down when I realized most of the traffic was regularly scheduled scans from seven infosec companies.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in