Pre-Auth Connects TCP scanner traffic captured pre-login

Pre-Auth Connects (24h)
Pre-Auth Connects (7d)
Unique Source IPs (7d)
Dominant Protocol (7d)
Auto-refresh every 30s

Hourly Rate — Last 24h

Pre-auth connect volume bucketed by hour. Spikes indicate scanning campaigns or brute-force runs.
24h agoNow

Top Source IPs (7d) top 20

Sources hitting the most pre-auth probes. Click an IP to pivot to dossier.
Source IP Hits First Last Protocols

Targeted Ports (7d)

Destination port distribution. Protocol tag shows the dominant honeypot type associated with each port.
Port Protocol Hits

Pre-Auth Hits Per Decoy (7d)

Which deployed honeypots absorbed the most pre-auth traffic. A zero row here = that decoy is either unknown to external scanners or behind NAT that never exposes it.
Hostname Deployment ID Hits Last Seen