We’ve been logging the credentials that bots throw at an SSH honeypot (our HoneyPoint Security Server™). Nothing exotic: listeners that accept the handshake, record the username/password pair, and the source IP. After letting this run for a bit, the first thing we noticed was how little the dictionary has changed.

The numbers
Top usernames over the capture window:
| Username | Tries | Sources |
|---|---|---|
root |
45,302 | 350 |
admin |
3,254 | 256 |
user |
1,978 | 132 |
enable |
1,863 | 12 |
test |
1,414 | 101 |
ubuntu |
1,142 | 125 |
user2 |
452 | 26 |
debian |
433 | 39 |
deploy |
387 | 47 |
support |
372 | 104 |
root alone accounts for more attempts than everything else combined, by a factor of about four. That’s not surprising. What’s worth noticing is the sources column: 350 distinct IPs tried root, 256 tried admin. This is the broad, low-effort campaign layer to find the most basic common hanging fruit.








