FLEET STATUS — PUBLIC VIEW BATCH-UPDATED EVERY 6H · LAST {{ lastUpdated }}

What the fleet is seeing

Aggregated observations from our global honeypot fleet. Everything on this page is measured, not modeled — and delayed by design, so it never tips a live capture.

THREAT INDEX (24H)
{{ threatVal }}
{{ threatLabel }}
{{ kpiEvents }}
EVENTS / LAST 24H
{{ kpiIps }}
UNIQUE IPS / 24H
{{ kpiProtoCont }}
PROTOCOLS / CONTINENTS / EMULATED PROFILES
{{ topTechId }}
TOP TECHNIQUE · {{ topTechName }}
RESEARCH FLEET VOLUME — LAST 24 HOURS EVENTS PER HOUR · UTC
12:0018:0000:0006:0012:00
GLOBAL ORIGINS — LAST 24 HOURS ORIGINS (SIZED BY SHARE) COVERAGE REGION
{{ r.label }}
{{ m.label }}
Marker position is the geographic center of observed source addresses per region. The largest origin in each cluster is labelled; smaller nearby origins show as unlabelled dots. A long tail of smaller sources is summarised as "Other". Coverage regions show where fleet sensors operate — we don't publish node counts or exact locations, for the same reason honeypots work.
TOP ORIGINS (24H)
{{ o.name }}
{{ o.pct }}
Origin = source geography of observed connections. Attribution is where the packet came from, not who sent it.
TOP PROTOCOL BREAKDOWN (24H)
{{ p.name }}
{{ p.pct }}
SCADA-Modbus probes shown in amber — the traffic most vendors never see because they don't run OT decoys. “Other” bundles lower-volume live captures — a sample: BACnet, DNP3, EtherNet/IP, GE-SRTP, VNC, RDP, LDAP and MSRPC.
MOST-TRIED CREDENTIALS (24H)
#USERNAMEPASSWORDATTEMPTS
{{ c.rank }} {{ c.user }} {{ c.pass }} {{ c.n }}
If any of these open something on your network, fix that today.
TOP MITRE ATT&CK TECHNIQUES (24H)
{{ m.id }} {{ m.name }} {{ m.pct }}
Techniques observed and auto-classified across all fleet sessions in the window.
CAPTURE FEED REPLAY OF RECENT CAPTURES · DELAYED ≥24H · DETAILS REDACTED
{{ feed }}
{{ nuisanceNote }}
CREDENTIAL CANARY — STOLEN-CREDENTIAL REUSE DETONATIONS DELAYED ≥24H · SOURCES REDACTED
{{ canaryTokens }}
BAIT CREDENTIALS PLANTED
{{ canaryGrabs }}
IPS THAT TOOK THE BAIT
{{ canaryDets }}
DETONATIONS · TOKEN USED
{{ canaryCross }}
CROSS-IP REUSE INCIDENTS
RECENT DETONATIONS
WHEN · UTCGEOASNSOURCESIGNAL
{{ canaryFeed }}
These are stolen credentials caught being reused. When a secret taken from one of our decoys is used anywhere on the internet, it surfaces here — proof of theft-to-reuse, not just a door rattled.
HOW THIS PAGE WORKS
Numbers are aggregated from real fleet captures and refreshed in 6-hour batches — not streamed live. The feed replays genuine sessions at least 24 hours old with identifying details redacted. We'd rather show you slightly-delayed truth than real-time theater.
Want this view of your own network?
Request early access
Deception Check mark © 2026 Deception Check, Inc.
Home Research Bestiary