API unreachable — retrying…
Honeypot SOC· Threat Console
Connecting…
syncing…
Attacks Today
Total Events
all time
Unique Sources
all time
Countries Today
Top Source Today
investigate →
Payloads Today

Attack Origins

all-time
legend
honeypot sensors · AWS us-east-1
attacker · size = volume
login success
payload drop
command / probe
failed login
LIVEwaiting for events…

Top Sources

today
SourceEvents

Attack Volume

Top Attacker Countries

all time

Attack Timing

day × hour · last 7d · Europe/London

Top Networks

from risk-scored sources · 7d

Sensor Fleet

Live Activity

Streaming
TimeSourceLocationTargetEventDetailRep

Attack Surface by Service

sessions per exposed port · all time

Exposed Ports

multi-sensor telemetry
ServicePortSessionsSourcesFailed LoginsLoginsLast SeenSensor

Detections

TimeSeverityDetectionSourceEvidence

Captured Payloads

VirusTotal verdicts
Last SeenSourceURL / FileHosted OnSHA-256VerdictCount

Tactic Distribution

mapped to MITRE ATT&CK · all time

Top Commands

CommandTacticHitsSources

Credential Attempts

brute force · T1110

Usernames

Passwords

Risk-Scored Sources

last 7d
RiskSourceProviderEventsCmdsPayloadsLoginsAbuse
STIX Indicators
IPs + hashes, STIX 2.1
High-Risk IPs
risk score ≥ 45 · 7d window
Malware Hashes
VirusTotal-confirmed SHA-256
Malware URLs
harvested from commands

Published Feeds

FeedFormatEndpoint
Indicator bundleSTIX 2.1
/feeds/stix
Open ↗
Blocklist — IPsplaintext
/feeds/ips.txt
Open ↗
Blocklist — hashesplaintext
/feeds/hashes.txt
Open ↗
Malware URLsplaintext
/feeds/urls.txt
Open ↗
Feed metadataJSON
/feeds/metadata
Open ↗
# consume from a firewall / SIEM curl -s https://api.shucayb.com/feeds/ips.txt # block at the edge curl -s https://api.shucayb.com/feeds/hashes.txt # EDR hash blocklist curl -s https://api.shucayb.com/feeds/urls.txt # malware hosting URLs — proxy/DNS blocklist curl -s https://api.shucayb.com/feeds/stix # STIX 2.1 — import into MISP / OpenCTI / Microsoft Sentinel (TAXII-less pull)