MITRE ATT&CK techniques, ranked by observed volume
Live leaderboard of techniques ranked by attacks observed by the OffSeq global honeypot fleet in the last 7 days.
Ranked by attacks observed by the OffSeq honeypot fleet · last 7 days
| # | Technique | Attacks | Source IPs |
|---|---|---|---|
| 1 | T1110 Brute Force | 3,969,492 | 7,820 |
| 2 | T1105 Ingress Tool Transfer | 927,632 | 179 |
| 3 | T1021.005 VNC | 411,784 | 1,109 |
| 4 | T1657 Financial Theft | 340,586 | 87 |
| 5 | T1190 Exploit Public-Facing Application | 142,273 | 6,209 |
| 6 | T1595 Active Scanning | 70,281 | 5,236 |
| 7 | T1059 Command and Scripting Interpreter | 38,305 | 784 |
| 8 | T1210 Exploitation of Remote Services | 21,998 | 1,041 |
| 9 | T1595.002 Vulnerability Scanning | 16,741 | 1,420 |
| 10 | T1046 Network Service Discovery | 15,802 | 3,705 |
| 11 | T1552 Unsecured Credentials | 14,202 | 364 |
| 12 | T1187 Forced Authentication | 1,888 | 213 |
| 13 | T0846 T0846 | 1,818 | 308 |
| 14 | T1592 Gather Victim Host Information | 1,690 | 175 |
| 15 | T1498.002 Reflection Amplification | 1,581 | 562 |
| 16 | T1552.001 Credentials In Files | 1,044 | 132 |
| 17 | T1071.003 Mail Protocols | 904 | 87 |
| 18 | T1090 Proxy | 229 | 19 |
| 19 | T1078 Valid Accounts | 222 | 124 |
| 20 | T1040 Network Sniffing | 215 | 147 |
| 21 | T1505.003 Web Shell | 151 | 84 |
Every row links to a live-updating profile of what OffSeq honeypot sensors captured worldwide. See all planes on the threat-intelligence index.