Events
—
in window
Published campaigns
42
analyst-managed
Tracked IPs
2.4M
distinct source IPs observed
History
454 days
of trend data
Honeypot status
active · event in the last hour quiet · within 24h offline · 24h+What's new
Global source IPs
malicious-heavy high volumeUnique source IPs / day
Trends →Honeypot mix
Top source economies
All →Top source IPs
Full list →| Source IP | Economy | Network | Classification | Events | Last seen |
|---|
Source concentration · source IPs by ASN
tile size ∝ unique IPs / ASNMalware families captured
Notable events — live
Malware · exploits · logins →Distinct payloads
Browse all →Pivot explorer · drill through the notable-event slice, keeping full context
Top economies
| Economy | Events | Unique IPs | |
|---|---|---|---|
| Loading… | |||
Click a row to drill deeper; ↗ opens its dossier. ?
Each row shows activity within the breadcrumb context. Clicking a row turns it into a filter and moves you one level down. Pivots run over the retained notable-event window and are cached, so a broad first pivot can take a couple of seconds.
Credential intelligence
Credentials most-tried against the honeypots. ?
Attacker brute-force guesses, mostly dictionary or default credentials. Admin-only; access is audited.
Loading…
APNIC regional threat distribution
The 56 APNIC economies, by sub-region. ?
APNIC is the Regional Internet Registry serving Asia-Pacific. Share is of the APNIC-region total, and each sub-region shows how many of its economies are active.
Loading…
Portal health
Live status of the portal and its upstreams. ?
Refreshed on each visit and cached server-side for about 30 seconds. Admin-only.
Loading…
Unique source IPs / day
Source IPs by network (ASN)
Source IPs observed
ranked by all-time events · click a row to open its dossier| Source IP | Economy | Network | Events | Last seen |
|---|---|---|---|---|
| Loading… | ||||
← All source IPs
203.101.186.23 Active
🇵🇰 Pakistan
·
AS9541 Cyber Internet Services
First seen
2025-11-14
Last seen
2 min ago
Total events
48,213
Active span
—
Sensors hit
—
Honeypot types
—
Activity
SSH 22 · Telnet 23No per-IP daily series is retained. ?
The curated store keeps per-IP totals plus the intel event slice, not a daily histogram. Use Total events and Active span above, and the Evidence tab below, for this IP's activity.
Notable intel events · most recent ?
A curated slice — malware downloads, exploit attempts, successful logins, credential submissions — not every packet or connection attempt. Honeypots that only log connections/credentials (OpenCanary, Fortinet) rarely produce rows here; that's expected, not missing data.
| Timestamp · UTC | Sensor | Proto | Signature | Raw |
|---|
🛡️ Sensor identities are pseudonymised (honeypot type + economy only) to protect honeypot placement.
Network fingerprint · HASSH
—
SSH/Telnet client fingerprint (HASSH). ?
A shared HASSH means the same client toolkit — useful for tying separate addresses to one actor.
Network metadata
- ASN
- —
- Organisation
- —
- Economy
- —
Sensor coverage
- Honeypot types
- —
- Target ports
- —
Related IPs · shared HASSH
External enrichment
Classification comes from honeynet behaviour — see the Evidence tab. ?
No per-IP external reputation (GreyNoise, OTX, Shodan) is integrated; everything here is what our own sensors observed.
Campaign history
Events / day
Source IPs by economy
Networks (ASN) observed
ranked by source IPs · click to open| ASN | Organisation | Source IPs |
|---|---|---|
| Loading… | ||
← All networks
AS9541 Active
Cyber Internet Services (Pvt) Ltd · 🇵🇰 Pakistan
· RIR APNIC
· 14 prefixes
First seen
2025-08-21
Last seen
2 min ago
Source IPs
1,240
Malicious IPs
890
Events · total
312K
ASN activity — events / day · last 30 days
Source IPs in this network
| Source IP | Economy | Classification | Events | Last seen |
|---|
Top signatures from this ASN
Malware samples fetched by source IPs in this network
top by fetch count · click a hash to open it| SHA-256 | Malware | Fetches |
|---|---|---|
| — | ||
Network
- ASN
- —
- Organisation
- —
- Economy
- —
Abuse posture · from honeynet
- Source IPs
- —
- Malicious IPs
- —
- Malicious ratio
- —
External registration
Metrics are from observed honeynet activity. ?
RDAP, abuse-contact and prefix registration are not integrated, so none of this reflects external reputation.
Honeynet events / day
URLs by payload status
Malware / payload URLs observed
| URL | Host | Status | Served | Last seen |
|---|---|---|---|---|
| Loading… | ||||
← All URLs
— —
First seen
2026-07-19
Last served
2 min ago
Times served
3,214
Host
175.174.52.172
Status
Online
Delivery activity — fetches / day
retained event windowAttacking source IPs that fetched this payload
| Source IP | Economy | Network | Pushes | Last seen |
|---|
Sibling payloads on the same host
| Path | Payload | Served | Status |
|---|
Hosting infrastructure
- Host IP
- —
- ASN
- —
- Open port
- —
- URL first seen
- —
Payload
- SHA-256
- —
- URLhaus status
- —
Family/type resolved on the hash dossier.
Campaigns
Analyst-curated correlation rules. ?
Group activity by an IOC (URL, file hash, IP/CIDR), a URL or command pattern, an SSH fingerprint (HASSH), or any combination. You choose what is published to the public portal and feeds.
| Campaign | Basis | Definition | Member IPs | Status | Actions |
|---|
● Published live on the public portal & feeds
◌ Hidden internal only — excluded from publication
Deleting a campaign removes its definition only; observed events are untouched.
Change history
edits & publication changes · newest first‹ All campaigns
— —
Basis —
·
—
Activity
Member IPs
| Source IP | Economy | Network | Events | Last seen |
|---|
Rule reach in the feed archive
Has this rule been true before? ?
Member IPs above come from the retained event window (about 19 days) — who is attacking us now. This checks the same rule against the historical daily feeds (2021 onwards) to show whether it has been true before, and for how long. Context only: it does not change membership.
Match conditions
Geographic spread · member IPs
Notes
—
Events / day · last 30 days
Top signatures
Protocols / services targeted
by connectionsService mix
share of connectionsTop source IPs on this honeypot
Full list →| Source IP | Economy | Classification | Events |
|---|
Unique source IPs / day
Source IPs by economy
Source economies observed
ranked by source IPs · click to open| Economy | Source IPs |
|---|---|
| Loading… | |
← All economies
Events / day · last 30 days
Networks · ASN
by unique IPs · whole accounted forHoneypots targeted
Top source IPs from this economy
| Source IP | Network | First seen | Last seen | Events |
|---|
Malware samples fetched by source IPs in this economy
top by fetch count · click a hash to open it| SHA-256 | Malware | Fetches |
|---|---|---|
| — | ||
Campaign history · this economy
Source IPs
—
queryable via API
Malware hashes
—
captured payloads
CVEs tracked
—
exploit attempts
Data as of
—
newest ingested event
Feed catalog
The REST API below is the programmatic access. ?
These are the same endpoints this UI uses (/api/ip, /api/search, /api/campaigns, …). Structured export feeds (MISP, STIX/TAXII, CSV) are on the roadmap.
Access tiers
Public Free
Researchers · anyone
- Search UI + entity dossiers (sensitive fields redacted)
- Public feeds — MISP / CSV / JSON
- API 60 req/min
Registered CERTs · operators
Verified national CERTs & honeynet operators
- API keys · 600 req/min · bulk export
- Restricted feeds (HASSH, per-economy, credentials)
- Full fields — raw credentials still gated
Partner Federation
Data-sharing partners
- Real-time STIX 2.1 / TAXII stream
- Unmetered · full notable-event feed
- Contribute your own honeynet data back
REST API — example
Full reference →Look up an IP
GET /api/ip/45.144.29.201 Accept: application/json
Response · IPDossier
{
"ip": "45.144.29.201",
"country": "FR", "asn": 41745,
"as_org": "FORTIS-AS …",
"first_seen": "2025-08-24T…Z",
"last_seen": "2026-07-30T…Z",
"total_events": 126425730,
"distinct_days": 341
}
# evidence: GET /api/ip/{ip}/evidence
# search : GET /api/search?q=…
Rate limits & access by tier
| Tier | Rate limit | Bulk export | Real-time (TAXII) | Sensitive fields |
|---|---|---|---|---|
| Public | 60 / min | — | — | redacted |
| Registered | 600 / min | ✓ CSV / JSON | — | full · no raw creds |
| Partner | unmetered | ✓ | ✓ STIX 2.1 | full |
Search results
—
Try
Sensors that produced attack intel in the retained window — not the whole fleet. ?
The portal only ingests notable events (malware downloads, exploit attempts, logins) from roughly the last three weeks, and has no raw heartbeats. A sensor that saw only scans or connection attempts in that window is healthy but does not appear here, so this count runs materially below the number of sensors actually reporting — Elasticsearch, which keeps every event for 18 months, currently sees about 200 reporting in the last 7 days against the figure shown here.
Active means an intel event in the last hour, so a quiet honeypot can look stale even when it is fine. Counts are per sensor and collector instance: a sensor re-registered onto another collector (as in the agora2 migration) appears once per instance, because re-registration mints a new sensor ID.
Active means an intel event in the last hour, so a quiet honeypot can look stale even when it is fine. Counts are per sensor and collector instance: a sensor re-registered onto another collector (as in the agora2 migration) appears once per instance, because re-registration mints a new sensor ID.
Producing intel
—
sensor × instance, ~3w window
Active · <1h
—
intel event within the hour
Quiet · 1–24h
—
no intel event >1h
Honeypot types
—
—
Collectors
—
—
Sensors by honeypot type
Sensors by collector
Sensors
| Sensor UUID | Collector | Honeypot | Status | First seen | Last event | Intel events |
|---|
— —
Sensor activity — events / day
per-sensor trend — not yet wired
Top source IPs on this sensor
Full list →| Source IP | Economy | Classification | Events |
|---|
Sensor
- UUID
- —
- Honeypot
- —
- Collector
- —
- First seen
- —
- Last event
- —
Image / ports / uptime aren't visible to the portal — it only sees the event stream.
Governance · benign scanner allowlist
Known research & commercial internet scanners are excluded from malicious classification. Their activity is labelled benign · research and kept out of threat metrics and feeds, so legitimate scanning isn't mistaken for an attack. Network owners can request an addition or correction.
Allowlisted scanners
Known scanners are not currently excluded from metrics. ?
The benign-scanner allowlist is not yet materialised as data — the text above describes intended governance. Research and commercial scanners (Censys, Shodan, academic) still count toward metrics; that classification pipeline is planned.
Malware families
Captures by file type
Malware / payloads captured
ranked by times captured · click to open| SHA-256 | Family | Type | Size | Captures | Last seen |
|---|---|---|---|---|---|
| Loading… | |||||
← All malware
4e9f2c7a…b1a7c2 Malware
Mirai · ELF ARM · 78 KB · first submitted 2026-07-19
First seen
2026-07-19
Last seen
2 min ago
Times captured
3,214
File size
78 KB
Family
Mirai
Captures — per day
retained event windowAttacking source IPs that fetched this sample
The intruders that fetched it, not the hosts serving it. ?
These addresses ran the download inside a honeypot session. The machines actually hosting the file are the payload URLs below.
| Source IP | Economy | Network | Fetches |
|---|
Payload URLs this sample was fetched from
The distribution servers hosting the file.
| URL | Host ASN | Status | Fetches |
|---|
File
- SHA-256
- —
- MD5
- —
- Type
- —
- Size
- —
Enrichment
Family and file-type come from MalwareBazaar → mwdb. ?
VirusTotal and Triage are not integrated, so an unclassified sample may still be known elsewhere. Campaign membership is analyst-rule-driven — see the Campaigns tab.
← Malware
—
First seen
—
Last seen
—
Samples
—
Total captures
—
Captures / day all-time
Top delivering source IPs
click to open| Source IP | Economy | Network | Fetches |
|---|---|---|---|
| — | |||
Samples in this family
| SHA-256 | File type | Captures | Last seen |
|---|---|---|---|
| — | |||
Top economies nightly
Top networks (ASN) nightly
Exploit attempts / day
Top CVEs · by attempts
CVEs / exploits observed
ranked by attempts in the selected window · click to open| CVE | Exploit attempts | IP-days |
|---|---|---|
| Loading… | ||
← All CVEs
CVE-2026-46817 Actively exploited
Oracle E-Business Suite · improper privilege management · CWE-269 · CVSS 9.8
First seen · honeynet
2026-07-15
Last seen
2 min ago
Exploit attempts
1,306
CVSS
9.8
CWE
—
KEV added
—
Exploit attempts — per day · last 30 days
Attacking IPs
Exploit attempts
Captured request payloads are not surfaced here yet. ?
Exploit signatures for this CVE appear on the honeypot dossiers (webpot, fortinet).
Vulnerability
- CVE
- —
- Vendor
- —
- Product
- —
- CWE
- —
- CVSS
- —
References
- CISA KEV
- —
- NVD
- —
CVE metadata (vendor/product/CWE/CVSS/KEV) from CISA KEV + NVD enrichment.
Events / day
Top techniques
Attack signatures / techniques
| Signature | Events | IP-days |
|---|---|---|
| Loading… | ||