MIRAGE
Threat Intelligence

OffSeq honeypot threat intelligence

Live in-the-wild attack telemetry from a global honeypot sensor fleet — CVEs under active exploitation, attacker networks, origin countries, targeted services and ATT&CK techniques.

CVEs exploited in the wild

Which vulnerabilities real attackers are exploiting against decoys right now, with volume and source counts.

Attacked services

SSH, RDP, SMB, databases and more — attack volume, ports and the CVEs seen against each.

Attack origin countries

Where attack traffic originates, by observed volume and distinct hosts.

Attacker networks (ASNs)

The autonomous systems hosting the most attack traffic against the fleet.

MITRE ATT&CK techniques

The adversary techniques observed most often across captured sessions.

Methodology

Every figure is direct sensor telemetry: a distributed fleet of honeypots presents realistic decoy services and records unsolicited attacks against them. Attacker addresses are aggregated to /16 networks before publication — individual IPs are never exposed. Figures cover a rolling 7-day window and update continuously. Open the live console →