Feed Explorer
Click any chart or row to drill in · everything cross-filters
Indicators
42,326
all collections
Unique IPs
13,484
distinct origins
Credentials
16,222
SSH pairs
TTPs mapped
62
MITRE ATT&CK
Top technique
T1059
62% · Cmd & Scripting
Avg confidence
70
honeypot-derived

Attack origins click a country to filter ▸

Aggregate geography of attack traffic (24h)

MITRE ATT&CK click to filter ▸

Technique frequency (24h)

TTP intelligence
MITRE technique mapping is available on Starter and above.

Collections click to filter ▸

Your entitled indicator sets

Indicator types click to filter ▸

STIX object mix

Indicator feed

Search, sort, and click any row for full enrichment

Observed Collection Type Pattern / value MITRE Conf
92
SEVERE
FLEET THREAT INDEX

Composite of attack volume vs a 200K/24h reference, weighted by high-severity techniques and hands-on activity.

7
Protocols
3
Continents
24+
Decoy profiles
Events (24h)
188K
fleet-wide
Unique IPs
13,484
24h
Sessions
890K
18-day
Events / day
187,862
rolling
All-time
35.1M
captured

Attack volume — 24h

Events per hour

Protocol mix

Where attackers knock

Credential spray analysis flip & filter ▸

The username/password pairs hammered against the fleet

UsernamePasswordApplianceHits

Aggregate threat telemetry only. Sensor locations, node identifiers, and operational detail are never exposed to tenants.

SAMPLE FLEET PERSONAS

The decoys we run — the flip side of the Bestiary. Each persona emulates a real system class down to its protocols and banners, so attackers reveal themselves against something that looks like production. OT personas are the Pro-OT differentiator.

Persona classes and engagement stats only — never individual node addresses or locations.

ATTACKER ARCHETYPES

12 archetypes, rated by how often you'll meet them. Click any row for the full field-guide entry — stat block, signature move, and real-world examples.

Volume by archetype

Unique IPs observed (18-day)

RarityArchetypeEncounter rateUnique IPs
CROSS-SENSOR FAN-OUT

How broadly a single address probes the fleet. An address that touches one decoy may be targeting you. An address that touches a dozen different system classes is sweeping the internet. Breadth separates the two, and it is the main input to the confidence score. Counts are banded by design — exact decoy totals are not published.

Fan-out → persona families

Band thickness = addresses in that flow · teal = narrow, targeted · amber = wide sweep

Persona families reached

Which decoy system classes multi-decoy addresses actually touched · our own decoy locations are never shown

Widest fan-out

Click a row to open the indicator

AddressBreadthClassification ConfidenceCollection

CREDENTIAL CANARIES

Planted, believable secrets seeded across the fleet and into your own estate. They do nothing — until someone uses one. The instant a canary token is touched anywhere on the internet, it detonates and tells you exactly where your data walked out the door.

Bait tokens served
tokens issued to grabbers
Bait grabber IPs
distinct IPs that took bait
Detonations (all-time)
tokens later used in the wild
Cross-IP reuse
verified journeys · excludes 13 CDN-masked

Harvest networks vs detonation networks

Whose infrastructure pulls the bait, and whose is used when a token fires. Two separate populations — a line is drawn only where the same network appears on both sides.

Bait deployed vs detonated

By bait type — thousands planted, a handful ever used

Recent detonations FLEET-WIDE

Live canary hits — where the credential surfaced

WhenFlavorSurfaced atOriginTTD

Top bait harvesters FLEET-WIDE

Who pulls the most bait. Mostly bulk scanners, not thieves — harvesting a credential and using one are different claims.

SourceWhat they tookBait pulled
Loading…

Blind sweeps

What scanners ask for when hunting secrets — requests for paths we never issued

Path requestedHits
Loading…

Cross-IP reuse

Bait grabbed at one address, then used from another — the theft-to-reuse signal

Picked upUsed fromOriginNetworkBaitDwell
Loading…

Detonation origins FLEET-WIDE

Where tokens surfaced, and on whose network

Plant a canary

Drop a token anywhere — a config file, an S3 bucket, a password manager note

Self-host & configure your own canaries ENTERPRISE

Generate, download, and deploy canary tokens into your own estate — no data leaves your perimeter

TOKEN BUILDER
aws-keyazure-credgcp-sahttp-urldnsdb-stringssh-key
Pick a flavor, add a memo, choose an alert channel (webhook · SIEM · email), and download a ready-to-drop token + a self-hosted catcher bundle.
# download a self-hosted canary bundle
dc canary build --flavor aws-key --memo "prod-backups" \
  --alert webhook --out ./canary/
# → docker-compose.yml + token + catcher
docker compose -f ./canary/docker-compose.yml up -d
Self-hosted canaries
Build, download, and self-host your own tokens on the Enterprise tier.

Exploitation timeline click a point ▸

CVSS vs. date added to CISA KEV · color = status

CVE watchlist

Click a CVE for the full entry

CVEVendorProductAddedCVSSStatusClassDC catch

MALWARE INTELLIGENCE ENTERPRISE

Binaries the fleet coaxed attackers into dropping — captured, hashed, and detonated in an isolated sandbox. Families, C2, and downloadable samples for your own analysis.

Samples (24h)
128
captured & detonated
Unique families
6
this cycle
Never-seen
3
0 VT detections at capture
Avg sandbox verdict
61/72
malicious

Families (24h)

What's being dropped

Delivery method

How it lands

Recent samples

Click-to-download is gated behind sandbox + legal controls

SHA-256FamilyFirst seenSandboxC2Sample
DETECTION LOGIC ENTERPRISE

The rules that turn raw decoy sessions into alerts — every one MITRE-mapped and fidelity-scored, and exportable as Sigma, YARA, Splunk, or Elastic for your own stack.

Active rules
48
fleet-wide
MITRE techniques
37
covered
Avg fidelity
93%
true-positive rate
Export formats
Sigma·YARA
Splunk·Elastic
one click

Coverage by ATT&CK tactic

Rules per tactic

Rule types

Format mix

Rule library

MITRE-mapped, fidelity-scored detections

RuleNameTechniqueTypeFidelityFires (24h)
ATTACK REPLAYS ENTERPRISE

Walk your team through real, MITRE-mapped adversary sessions the fleet captured — end to end, the way they actually happened. Pick a threat actor and watch it move.

MITRE ATT&CK kill chain

Techniques in the order they fired

Replays are reconstructed from real captured sessions. Values are defanged (hxxp, redacted IPs) for safe sharing.

SELF-DEPLOY HONEYPOTS ENTERPRISE

Run our decoy personas inside your own environment. Generate a hardened bundle, deploy with one command, and report where you choose — syslog/SIEM on-prem, or opt in to the Deception Check cloud. The decoys never require a callback and can't pivot.

LIVE