Security Operations
vm3.lab-it.net · Honeypot threat intelligence
total events
blocked IPs
Overview
Total Events (24h)
vs prev period
Unique Attackers
vs prev period
SSH Brute (Cowrie)
vs prev period
Web Scans (HTTP)
vs prev period
Critical Alerts (24h)
severity-1 detections
IDS Alerts (24h)
All-time Total
cumulative
Events Over Time
Recent Alerts
No active alerts
High-severity events will appear here
Incident Cases
CRITICAL
HIGH
MEDIUM
LOW
ACTIVE (Open + In Progress)
Create New Case
No cases
자동 차단된 위협은 자동으로 case가 생성됩니다
| ID | Severity | Title | Source IP | Status | Created | |
|---|---|---|---|---|---|---|
IDS Alerts
Suricata + ET Open ruleset · 66K signaturesSEV-1 CRITICAL
SEV-2 HIGH
SEV-3 INFO
TOTAL 24H
Top Signatures
No alerts yet
Categories
No data
Recent Alerts
No IDS alerts in last 24h
| Time | Source IP | Country | Signature | Proto |
|---|---|---|---|---|
SSH Bot Fingerprints (HASSH)
같은 hash = 같은 봇/봇넷Top HASSH Fingerprints (Last 7d)
No SSH client kex events yet
| # | HASSH | SSH Client | Unique IPs | Sessions | Sample IP | First Seen |
|---|---|---|---|---|---|---|
Threat Intelligence Matches
매칭된 IP (24h)
관련 이벤트
Known-bad IPs in our traffic
No TI matches (or loading)
| # | IP | Country | Events 24h | TI Source | CIDR |
|---|---|---|---|---|---|
Geographic Distribution
countries · 30-day heatmapWorld Map
Activity Heatmap
Loading...
Low
High
Top Threats
click IP to drill downTop Attacker IPs
| # | IP Address | Country | Organization | Events | Risk | Scanner |
|---|---|---|---|---|---|---|
| No data | ||||||
|
|
||||||
Live Attack Feed
PAUSED
Waiting for events…
Real-time attacks will stream here
| Time | Source IP | Honeypot | Payload | |
|---|---|---|---|---|
Attack Patterns
most common indicatorsTop Scan Paths
No data
Top Credentials
No data
- /
Top Commands
No data
Correlation Analysis
shared IOCs across multiple attackersShared Credentials
No correlations found
/
Shared Commands
No correlations found
Advanced Analytics
subnet detection · network graph · alert rulesAlert Rules
| Name | Field | Op | Value | Action | |
|---|---|---|---|---|---|
No rules configured
Malicious Sources
URLs captured from attacker commandsMalicious URLs
Loading...
No URLs captured yet
wget/curl commands will be logged here
| Time | Source IP | Country | URL |
|---|---|---|---|