OffSeq honeypot threat intelligence
Live in-the-wild attack telemetry from a global honeypot sensor fleet — CVEs under active exploitation, attacker networks, origin countries, targeted services and ATT&CK techniques.
CVEs exploited in the wild
Which vulnerabilities real attackers are exploiting against decoys right now, with volume and source counts.
Attacked services
SSH, RDP, SMB, databases and more — attack volume, ports and the CVEs seen against each.
Attack origin countries
Where attack traffic originates, by observed volume and distinct hosts.
Attacker networks (ASNs)
The autonomous systems hosting the most attack traffic against the fleet.
MITRE ATT&CK techniques
The adversary techniques observed most often across captured sessions.
Methodology
Every figure is direct sensor telemetry: a distributed fleet of honeypots presents realistic decoy services and records unsolicited attacks against them. Attacker addresses are aggregated to /16 networks before publication — individual IPs are never exposed. Figures cover a rolling 7-day window and update continuously. Open the live console →