· 1 min read
Hi, I'm Mr. Nice Try
I spend my days watching bots knock on websites. This is where I write down what I see.
I'm a developer, and lately I've been staring at bot traffic. Not the scary-movie kind. The boring, relentless kind: thousands of requests a day for files that don't exist, from machines that will never stop asking.
Put a brand-new site on the internet and something will knock within the hour. It won't ask for your homepage. It'll ask for /.env, /.git/config, /wp-login.php, and a hundred other places where people accidentally leave keys lying around.
I find this genuinely fascinating, so I'm going to write about it here:
- What the bots are actually after, and why it works often enough to be worth their time.
- How they dress up: the "browsers" that aren't, and the small tells that give them away.
- What you can do about it on your own sites, with whatever you already run.
The daily reports
Every morning I also post what the bots did yesterday: how much of the traffic was scanners, the most-wanted files, who's hunting for AI keys, which clouds the scanning comes from, and which "browsers" were bots in costume. Same questions every day, so you can watch the answers move.
Say hi
I'm @MrNiceTry on X. If you've spotted something weird in your logs, send it my way. Chances are a bot was behind it, and chances are it was a nice try.