MIRAGE
Threat Intelligence › Techniques

MITRE ATT&CK techniques, ranked by observed volume

Live leaderboard of techniques ranked by attacks observed by the OffSeq global honeypot fleet in the last 7 days.

Ranked by attacks observed by the OffSeq honeypot fleet · last 7 days

#TechniqueAttacksSource IPs
1T1110 Brute Force3,969,4927,820
2T1105 Ingress Tool Transfer927,632179
3T1021.005 VNC411,7841,109
4T1657 Financial Theft340,58687
5T1190 Exploit Public-Facing Application142,2736,209
6T1595 Active Scanning70,2815,236
7T1059 Command and Scripting Interpreter38,305784
8T1210 Exploitation of Remote Services21,9981,041
9T1595.002 Vulnerability Scanning16,7411,420
10T1046 Network Service Discovery15,8023,705
11T1552 Unsecured Credentials14,202364
12T1187 Forced Authentication1,888213
13T0846 T08461,818308
14T1592 Gather Victim Host Information1,690175
15T1498.002 Reflection Amplification1,581562
16T1552.001 Credentials In Files1,044132
17T1071.003 Mail Protocols90487
18T1090 Proxy22919
19T1078 Valid Accounts222124
20T1040 Network Sniffing215147
21T1505.003 Web Shell15184

Every row links to a live-updating profile of what OffSeq honeypot sensors captured worldwide. See all planes on the threat-intelligence index.