Attack origins click a country to filter ▸
Aggregate geography of attack traffic (24h)
MITRE ATT&CK click to filter ▸
Technique frequency (24h)
Collections click to filter ▸
Your entitled indicator sets
Indicator types click to filter ▸
STIX object mix
Indicator feed
Search, sort, and click any row for full enrichment
| Observed ↕ | Collection ↕ | Type ↕ | Pattern / value | MITRE ↕ | Conf ↕ |
|---|
Composite of attack volume vs a 200K/24h reference, weighted by high-severity techniques and hands-on activity.
Attack volume — 24h
Events per hour
Protocol mix
Where attackers knock
Credential spray analysis flip & filter ▸
The username/password pairs hammered against the fleet
| Username | Password | Appliance | Hits |
|---|
Aggregate threat telemetry only. Sensor locations, node identifiers, and operational detail are never exposed to tenants.
The decoys we run — the flip side of the Bestiary. Each persona emulates a real system class down to its protocols and banners, so attackers reveal themselves against something that looks like production. OT personas are the Pro-OT differentiator.
Persona classes and engagement stats only — never individual node addresses or locations.
12 archetypes, rated by how often you'll meet them. Click any row for the full field-guide entry — stat block, signature move, and real-world examples.
Volume by archetype
Unique IPs observed (18-day)
| Rarity | Archetype | Encounter rate | Unique IPs |
|---|
How broadly a single address probes the fleet. An address that touches one decoy may be targeting you. An address that touches a dozen different system classes is sweeping the internet. Breadth separates the two, and it is the main input to the confidence score. Counts are banded by design — exact decoy totals are not published.
Fan-out → persona families
Band thickness = addresses in that flow · teal = narrow, targeted · amber = wide sweep
Persona families reached
Which decoy system classes multi-decoy addresses actually touched · our own decoy locations are never shown
Widest fan-out
Click a row to open the indicator
| Address | Breadth | Classification | Confidence | Collection |
|---|
Planted, believable secrets seeded across the fleet and into your own estate. They do nothing — until someone uses one. The instant a canary token is touched anywhere on the internet, it detonates and tells you exactly where your data walked out the door.
Harvest networks vs detonation networks
Whose infrastructure pulls the bait, and whose is used when a token fires. Two separate populations — a line is drawn only where the same network appears on both sides.
Bait deployed vs detonated
By bait type — thousands planted, a handful ever used
Recent detonations FLEET-WIDE
Live canary hits — where the credential surfaced
| When | Flavor | Surfaced at | Origin | TTD |
|---|
Top bait harvesters FLEET-WIDE
Who pulls the most bait. Mostly bulk scanners, not thieves — harvesting a credential and using one are different claims.
| Source | What they took | Bait pulled |
|---|---|---|
| Loading… | ||
Blind sweeps
What scanners ask for when hunting secrets — requests for paths we never issued
| Path requested | Hits |
|---|---|
| Loading… | |
Cross-IP reuse
Bait grabbed at one address, then used from another — the theft-to-reuse signal
| Picked up | Used from | Origin | Network | Bait | Dwell |
|---|---|---|---|---|---|
| Loading… | |||||
Detonation origins FLEET-WIDE
Where tokens surfaced, and on whose network
Plant a canary
Drop a token anywhere — a config file, an S3 bucket, a password manager note
Self-host & configure your own canaries ENTERPRISE
Generate, download, and deploy canary tokens into your own estate — no data leaves your perimeter
dc canary build --flavor aws-key --memo "prod-backups" \
--alert webhook --out ./canary/
# → docker-compose.yml + token + catcher
docker compose -f ./canary/docker-compose.yml up -d
Exploitation timeline click a point ▸
CVSS vs. date added to CISA KEV · color = status
CVE watchlist
Click a CVE for the full entry
| CVE | Vendor | Product | Added | CVSS | Status | Class | DC catch |
|---|
Binaries the fleet coaxed attackers into dropping — captured, hashed, and detonated in an isolated sandbox. Families, C2, and downloadable samples for your own analysis.
Families (24h)
What's being dropped
Delivery method
How it lands
Recent samples
Click-to-download is gated behind sandbox + legal controls
| SHA-256 | Family | First seen | Sandbox | C2 | Sample |
|---|
The rules that turn raw decoy sessions into alerts — every one MITRE-mapped and fidelity-scored, and exportable as Sigma, YARA, Splunk, or Elastic for your own stack.
Splunk·Elastic
Coverage by ATT&CK tactic
Rules per tactic
Rule types
Format mix
Rule library
MITRE-mapped, fidelity-scored detections
| Rule | Name | Technique | Type | Fidelity | Fires (24h) |
|---|
Walk your team through real, MITRE-mapped adversary sessions the fleet captured — end to end, the way they actually happened. Pick a threat actor and watch it move.
—
MITRE ATT&CK kill chain
Techniques in the order they fired
Replays are reconstructed from real captured sessions. Values are defanged (hxxp, redacted IPs) for safe sharing.
Run our decoy personas inside your own environment. Generate a hardened bundle, deploy with one command, and report where you choose — syslog/SIEM on-prem, or opt in to the Deception Check cloud. The decoys never require a callback and can't pivot.