SV
Active sensor · updated daily
Passive OT/ICS honeypot · aggregated data

What is the internet
looking for right now?

Anonymised statistics from a passive system emulating industrial control systems, network cameras, VPN portals and DevOps services.

Online since: 2025-08-01   ·   Last aggregated: 2026-08-16   ·   Source: passive HTTP sensor
14 240
requests since launch
Unique IP addresses 1 757
Active endpoints 2 500
Login attempts 4
3
This hour
259
Today
0
Logins today
0
Port scan creds
Refreshes in 30s
Polling · every 30 seconds
01

Key metrics

Total requests
14 240
+3 614 last 7 days
Unique IP addresses
1 757
+522 last 7 days
Emulated services
2 500
 active endpoints
Login attempts
4
+0 last 7 days
High-signal events
112
Sophisticated targeted attacks
Sanitised events
249
XSS, SQLi and path traversal attempts
AI agent probes
64
MCP endpoints probed last 7 days

Excl. own IP addresses and known scanning systems.

02

Activity & geographic distribution

Daily activity · last 28 days
Lower
Higher
Hourly activity · last 7 days
0
6
12
18
Lower activity
Higher activity  · Hour (UTC) · last 7 days
Geographic distribution · top 8
US USA
4 602
NL Nederländerna
2 150
DE Tyskland
948
FR Frankrike
431
RO Rumänien
378
BE Belgien
327
BR Brasilien
287
CA Kanada
191
03

Categories & endpoints

Targeted system probes — breakdown by system category
Kommunal dokumentportal
242 1.7%
OT tidsserie-API
28 0.2%
Passersystem
21 0.1%
VPN-portal
10 0.1%
Related CVEs — known vulnerabilities in exposed system types
10.0 CVE-2019-7256 RCE (CVSS 10) — Linear eMerge E3 passersystem
10.0 CVE-2023-20198 Auth bypass (CVSS 10) — Cisco IOS XE webbgränssnitt
9.9 CVE-2023-44373 RCE — Siemens RUGGEDCOM APE1808
9.8 CVE-2024-9003 Auth bypass — Schneider Electric Easergy P5
9.8 CVE-2021-36260 Command injection — Hikvision IP-kameror
9.8 CVE-2023-27350 Auth bypass & RCE — PaperCut (VA-verk)
Protocol scanning — breakdown by system category
Related CVEs — known vulnerabilities in exposed system types
7.5 CVE-2023-27321 DoS — OPC UA Foundation SDK via crafted message
7.4 CVE-2022-44725 Memory corruption — OPC UA SDK (Unified Automation)
Generic mass scanning — breakdown by system category
Generisk webbscanning
13 230 92.9%
Credential-stöld
363 2.5%
DevOps & API-sondning
238 1.7%
ai_agent
97 0.7%
unknown
11 0.1%
Related CVEs — known vulnerabilities in exposed system types
10.0 CVE-2024-3400 RCE (CVSS 10) — Palo Alto PAN-OS GlobalProtect
8.1 CVE-2024-6387 RCE — OpenSSH regreSSHion
Most requested endpoints
root_probe
2 521
favicon_ico
753
sdk_weblanguage
309
raw_file_env
143
login
138
index_php
110
dispatch_asp
80
well_known_security_txt
79
sitemap_xml
76
api_env
75
04

Recent activity

LIVE
Time UTC Country Endpoint Category Method
2 h sedan DE favicon_ico generic_scan GET
2 h sedan DE sdk_weblanguage generic_scan GET
2 h sedan DE root_probe generic_scan GET
2 h sedan US root_probe generic_scan GET
3 h sedan US root_probe generic_scan GET
3 h sedan DE solr_admin_cores generic_scan GET
3 h sedan DE solr_admin_cores generic_scan GET
3 h sedan DE solr_admin_cores generic_scan GET
05

Method · User-agent · Response code

HTTP method
GET
13 741
POST
410
HEAD
61
OPTIONS
22
WNCI
1
HNET
1
TDFR
1
SWGI
1
VHTZ
1
STRV
1
Top User-Agents
browser
8 474
curl
2 100
security_scanner
1 165
no_agent
966
l9explore/1.2.2
433
go_http
265
HTTP response code
200 OK
14 228
404 Not Found
12
06

Credential attempts · login attempts per system and username

Most attempted usernames

No login attempts recorded.

Login attempts per honeypot service
Passersystem
4
07

Attacker patterns · recurring actors and multi-endpoint attempts

1 754
Unique external IPs
20
Recurring actors · >1 visit
20
Targeted actors · 2+ distinct endpoints
# Requests Endpoint groups Service types OT focus
1 673 5 4 OT-targeted
2 672 5 4 OT-targeted
3 656 5 4 OT-targeted
4 494 5 4 OT-targeted
5 196 5 4 OT-targeted
6 76 5 4 OT-targeted
7 270 4 4 OT-targeted
8 205 4 4 OT-targeted
9 136 4 4 OT-targeted
10 130 4 4 OT-targeted
11 128 4 4 OT-targeted
12 67 4 3 OT-targeted
08

Time to first probe · how quickly each service was discovered

Time to first probe · per exposed service since 2026-03-08
Credential-stöld +132 dagar
Passersystem +132 dagar
DevOps / CI-API +132 dagar
ai_agent +134 dagar
VPN-gateway (Ivanti) +138 dagar

Time after ports were opened until the first external request was recorded per service type

Want to know more?
Detailed analysis — attacker profiles, ISP data, credential trends — available on request for security researchers and industry peers.
Contact us ›
09

Geographic timeline · daily activity by origin country · last 7 days

Date US
USA
NL
Nederländerna
DE
Tyskland
BE
Belgien
BR
Brasilien
CA
Kanada
Total
2026-08-17 112 17 53 3 7 26 254
2026-08-16 108 29 27 1 17 25 267
2026-08-15 220 35 22 3 9 2 336
2026-08-14 192 28 27 11 24 · 319
2026-08-13 90 31 17 2 16 2 187
2026-08-12 781 26 18 2 20 16 962
2026-08-11 378 42 16 112 8 7 624
2026-08-10 9 7 · · 2 1 38

External traffic only. Dark cell = high activity from the country. Own IP addresses excluded.

11

Attack types explained

What is actually happening
Credential stuffing
0 unique IPs / 7 d

Automated Telnet connections systematically trying credentials from leaked databases. The goal is to take over routers and IoT devices to expand botnets.

CVE-targeted scanning
0 distinct protocols

Requests matching known CVE signatures — the attacker is looking for a specific vulnerability in industrial control systems, cameras or network equipment.

Disguised traffic
0 requests

OT protocol requests with browser user-agent (Mozilla/Chrome/Safari). The intent is to evade signature-based detection systems that filter out obvious scanner identities.

Counts refer to observations in honeypot data. Figures reflect attacker patterns, not actual breaches.

12

Trends

Requests per day over the last 30 and 90 days
Last 30 days
Last 90 days
13

Quarterly trends

Key KPIs per quarter — escalation over time
Quarter Requests Unique IPs High-signal Credential attempts Residential IPs
2026-Q3 20 402 3 807 0 7
2026-Q2 30 457 +10 055 6 393 +2 586 0 0 68 +61
2026-Q1 23 345 -7 112 3 820 -2 573 112 +112 500 +432

Quarters with zero requests are excluded. Δ = change vs. previous quarter in the table.

14

Attack depth · resource targets, behaviour signatures and origin

What attackers are looking for
13 230
Protocol (TCP/UDP raw)
362
Document files
335
API endpoints
301
Login pages
12
Unknown
Behaviour signatures
11 103
Path enumeration
6 744
Human-like browsing
4 584
Automated scanning
2 769
Vulnerability scanning
2 523
Configuration probe
1 250
Mass scanning
966
No User-Agent
897
API probing
286
Backup probe
172
Confirmed human
152
Payment probe
95
known_scanner
Attacker network operators
2 287
Google LLC
955
Censys, Inc.
Security researcher
861
TECHOFF SRV LIMITED
707
Microsoft Corporation
663
Linode
352
UNMANAGED LTD
347
VPSVAULT.HOST LTD
240
FBW NETWORKS SAS
222
cloud
220
DigitalOcean, LLC

No IP addresses shown. ASN data via passive geo-enrichment.

15

AI agent scanning · MCP protocol probing and known actors

MCP (Model Context Protocol) — AI agent protocol, probed since May 2026
Total (all time)
152
Last 7 days
64
Known protocols
JSON-RPC 2.0
MCP/2024-11-05
Anthropic v1
Known scanners (user-agent)
okänd 152

The honeypot exposes a full MCP interface with OT/ICS themes. Scanning is identified via endpoint_group=mcp_probe and attack_type=mcp_probe.