FLEET STATUS — PUBLIC VIEW
BATCH-UPDATED EVERY 6H · LAST {{ lastUpdated }}
What the fleet is seeing
Aggregated observations from our global honeypot fleet. Everything on this page is measured, not modeled — and delayed by design, so it never tips a live capture.
THREAT INDEX (24H)
{{ threatVal }}
{{ threatLabel }}
{{ kpiEvents }}
EVENTS / LAST 24H
{{ kpiIps }}
UNIQUE IPS / 24H
{{ kpiProtoCont }}
PROTOCOLS / CONTINENTS / EMULATED PROFILES
{{ topTechId }}
TOP TECHNIQUE · {{ topTechName }}
RESEARCH FLEET VOLUME — LAST 24 HOURS
EVENTS PER HOUR · UTC
12:0018:0000:0006:0012:00
GLOBAL ORIGINS — LAST 24 HOURS
● ORIGINS (SIZED BY SHARE)
◌ COVERAGE REGION
Marker position is the geographic center of observed source addresses per region. The largest origin in each cluster is labelled; smaller nearby origins show as unlabelled dots. A long tail of smaller sources is summarised as "Other". Coverage regions show where fleet sensors operate — we don't publish node counts or exact locations, for the same reason honeypots work.
TOP ORIGINS (24H)
Origin = source geography of observed connections. Attribution is where the packet came from, not who sent it.
TOP PROTOCOL BREAKDOWN (24H)
SCADA-Modbus probes shown in amber — the traffic most vendors never see because they don't run OT decoys. “Other” bundles lower-volume live captures — a sample: BACnet, DNP3, EtherNet/IP, GE-SRTP, VNC, RDP, LDAP and MSRPC.
MOST-TRIED CREDENTIALS (24H)
#USERNAMEPASSWORDATTEMPTS
{{ c.rank }}
{{ c.user }}
{{ c.pass }}
{{ c.n }}
If any of these open something on your network, fix that today.
TOP MITRE ATT&CK TECHNIQUES (24H)
{{ m.id }}
{{ m.name }}
{{ m.pct }}
Techniques observed and auto-classified across all fleet sessions in the window.
CAPTURE FEED
REPLAY OF RECENT CAPTURES · DELAYED ≥24H · DETAILS REDACTED
{{ feed }}
{{ nuisanceNote }}
CREDENTIAL CANARY — STOLEN-CREDENTIAL REUSE
DETONATIONS DELAYED ≥24H · SOURCES REDACTED
{{ canaryTokens }}
BAIT CREDENTIALS PLANTED
{{ canaryGrabs }}
IPS THAT TOOK THE BAIT
{{ canaryDets }}
DETONATIONS · TOKEN USED
{{ canaryCross }}
CROSS-IP REUSE INCIDENTS
RECENT DETONATIONS
WHEN · UTCGEOASNSOURCESIGNAL
{{ canaryFeed }}
These are stolen credentials caught being reused. When a secret taken from one of our decoys is used anywhere on the internet, it surfaces here — proof of theft-to-reuse, not just a door rattled.
HOW THIS PAGE WORKS
Numbers are aggregated from real fleet captures and refreshed in 6-hour batches — not streamed live. The feed replays genuine sessions at least 24 hours old with identifying details redacted. We'd rather show you slightly-delayed truth than real-time theater.
© 2026 Deception Check, Inc.