MIRAGE
Threat Intelligence › Methodology

How Mirage collects this data

Every figure on this site is direct sensor telemetry — real, unsolicited attacks recorded against decoys, not a scan of a vulnerability database or a reputation feed.

The sensor fleet

Mirage runs a distributed fleet of honeypots — decoy systems that present realistic services (SSH, RDP, SMB, databases, web applications, IoT and OT protocols, and vendor edge appliances) with no legitimate users. Because nothing should ever connect to them, every connection is unsolicited and treated as hostile. Sensors span multiple countries and hosting providers, so the data reflects broad, internet-wide attacker behaviour rather than a single vantage point.

What we measure

For each attack we record the target service, the request or payload, the source's country and network (ASN), the CVE being exploited where identifiable, and the MITRE ATT&CK technique. Counts on every page — attacks, distinct attacker networks, exploited CVEs — are computed directly from these events over a rolling 7-day window and refresh continuously.

Privacy & redaction

Attacker source addresses are aggregated to /16 networks before publication — an individual attacker IP is never exposed on this site. The identity and precise location of our own honeypot sensors are also withheld: sensor identifiers, scenario names and datacenter coordinates are stripped from all public output, and attack-origin maps snap to country centroids rather than a real sensor location. Captured request text is scrubbed of embedded IPs and our own decoy hostnames.

Data-quality gate

To avoid thin or manipulable pages, an entity earns a page only once it clears a floor of at least 50 observed attacks from at least 3 distinct attacker networks in the window. This mirrors the distinct-source rule we use for active-exploitation claims, so no single actor can mint a page by hammering one decoy.

Freshness

This is live intelligence: figures reflect the most recent 7-day window and update as attacks arrive. "Last seen" times on each page are real observation times. Where a vulnerability is on CISA's Known Exploited Vulnerabilities catalog, it is labelled as such.

Questions about the data or interested in the full feed? Contact OffSeq Cybersecurity or open the live console.