What if you could send someone a “secret” link — and instantly know when it’s opened?
In this video, we’re looking at NullVault, a self-hosted honeypot link tracker designed for scam baiting research, OSINT workflows, and monitoring unauthorized access to sensitive material.
NullVault creates a deceptive, professional-looking share page (banking portal, crypto wallet, or generic secure vault). When someone opens the link, it logs:
IP address
Approximate geolocation
ISP
Browser & OS
Referrer
Timestamp
Device breakdown
And more
Each link includes a private control panel with activity charts, maps, IP summaries, and optional webhook alerts (Discord or custom endpoints).
In this video we’ll cover:
What NullVault is (and what it is NOT)
How to deploy it with Docker
Creating honeypot links securely
Exploring the control dashboard
Webhook alert configuration
Security considerations and responsible usage
This project is fully self-hosted, makes zero external runtime requests, enforces a strict CSP, and uses an offline GeoIP database — making it a clean, controlled research tool.
⚠️ This video focuses on educational and defensive use cases only.
Chapters:
0:00 - Welcome to SYNACK Time
2:08 - Product demo
10:34 - Time to install!
17:37 - Configuring our subdomain
18:25 - Nginx Proxy Manager Config
22:15 - Wrapping up and a question for you!
Resources:
nullVault github - https://github.com/rehatiel/nullvault
SYNACK Time - https://synacktime.com
SYNACK Time github - https://github.com/SynAckTime/
Self hosting on a budget - • How to Build a Cheap VPS for Self-Hosting ...
Selfhost Newsletter - https://selfh.st
#CyberSecurity #OSINT #Honeypot #BlueTeam #Docker #InfoSec #ThreatIntel #ScamAwareness #SecurityResearch #SelfHosted #OpenSource #SOC #SYNACKTime