THREAT LEVEL: ASSESSING |  0 attacks/min |  Last: 
Connecting…

Security Operations

Total Attacks (24h)
Unique Attackers (24h)
Countries (24h)
High Severity (24h)
Total Sessions
Commands Run (24h)
Files Downloaded (24h)
ML Anomalies

Severity Trend (7 days)

Protocol Mix (24h)

Attack Timeline

Attack Types (24h)

Global Attack Origins

Sensor Network

0 online

System Health

WebSocket OFFLINE
API Backend ONLINE
Events Today
ML Detector

Top Attackers (24h)

#IP AddressCountryProtocolHitsSev

Malware Captures (Dionaea)

0 total
MD5 HashSource IPProtoVT ScoreSeen
No malware captured yet — waiting for Dionaea

Top Credentials Tried (24h)

Top Targeted Ports (24h)

Hourly Distribution (24h UTC)

Unique Attackers Per Day (14d)

Login Attempts vs Successes (7d)

Cowrie SSH — Deep Dive

SSH · TELNET
Top SSH Commands
#CommandCount
No command data yet
Session Duration
SSH Login Stats (24h)
Total Attempts
Successes
Success Rate
Avg Attempts/Session
Sessions w/ Commands
Login Success Rate
— sessions
Auth Outcome Mix
Brute Force Intensity
SSH Activity by Hour

Credential Analysis

30-day window
Password Type Distribution
Password Length Distribution
Top Targeted Usernames
Exploit Events by Hour
Target Port Mix
Top Credential Combinations
#UsernamePasswordAttemptsPassword Type
Loading credentials…

Dionaea — Malware & Service Captures

HTTP · SMB · FTP · MySQL · MSSQL · SIP
Total Captures
Unique Files
VT Detected
—% hit rate
Unique Source IPs
Malware Captures — Last 14 Days
VT Detection Severity
Service Captures (24h) 0 total
Malware Families (VT)
File Types
Remote Events by Hour
Remote Severity Mix
Recent Malware Samples
SHA256TypeSizeProtocolSource IPVTFamilyFirst Seen
Waiting for Dionaea captures…
Top Sources (24h)
#IPProtoHits
Waiting for Dionaea

Remote Sensor — Friend Honeypot

remote
Events 24h
Unique IPs
High Severity
Last Seen
Event Types (24h)
Targeted Ports (24h)
Top Remote Sources
IPCountryProtoHitsSev
Waiting for remote sensor events
Credential Attempts
UserPasswordAttempts
No remote credentials yet

ML Anomaly Detection

0%
Top Flagged Sessions
Session IDSource IPAttack TypeLogin AttemptsCommandsAnomaly Score
Running ML analysis…
Anomaly vs Normal

Geographic Intelligence

Top Attacking Countries (24h)
#CountryUnique IPsEventsHigh SevTop Protocol
No geo data yet
Events by Country

Network Intelligence

Top Attacking ISPs / Organisations (7 days)
Persistent Threats — Multi-Day Attackers
IPCountryDaysEventsSeverity
Loading…
ISP Detail Table
#ISP / OrganisationCountryUnique IPsEvents
Awaiting geo enrichment…

Persistent attackers are IPs observed attacking across 2+ different calendar days — indicating systematic, automated threat actors rather than one-off scanners.

ISP data comes from GeoIP enrichment and identifies which hosting providers are most commonly used to launch attacks.

Use this data to identify patterns in attacker infrastructure and correlate with threat intelligence feeds.

Country × Hour Attack Heatmap

Loading…

Live Attack Feed

0 events
TimeSource IPCountry ProtocolAttack TypePort SeveritySensor
 Connecting to live feed…