Pre-auth connect volume bucketed by hour. Spikes indicate scanning campaigns or brute-force runs.
24h agoNow
Top Source IPs (7d) top 20
Sources hitting the most pre-auth probes. Click an IP to pivot to dossier.
Source IP
Hits
First
Last
Protocols
Targeted Ports (7d)
Destination port distribution. Protocol tag shows the dominant honeypot type associated with each port.
Port
Protocol
Hits
Pre-Auth Hits Per Decoy (7d)
Which deployed honeypots absorbed the most pre-auth traffic. A zero row here = that decoy is either unknown to external scanners or behind NAT that never exposes it.