Field reports and open-source tooling.
Original research from the specialists who run our client engagements: the monthly Mirage honeypot field reports and the open-source tools we build and use in the field.
RSS feedField reports & tooling
A password is a fingerprint: what the internet's brute force is really typing
The honeypot genre has a favourite story: point a fake SSH server at the internet, watch the world guess root/123456, publish the list. It is a true story about one door. Our fleet speaks thirteen credential protocols, and over 44 days it drew 81,065 distinct source addresses and 12.2 million login attempts – enough to see that "brute force" is not one thing. It is a dozen separate campaigns, each carrying a purpose-built dictionary, and the password an attacker types is a fingerprint of the device it expects to find. The loudest campaign is not against SSH servers at all.
A connection is not an exploit: what 27 days of honeypot traffic actually contained
Honeypot reports trade in enormous, frightening numbers. Across 27 days our sensor fleet logged 5.4 million events carrying a CVE label – and 99.9% of them were doorknob-rattling: brute-force logins and port scans against deliberately vulnerable-looking services, not exploitation. Strip the noise and the real signal is small and sharp: 3,572 actual exploit payloads, a hand-picked set of web vulnerabilities from 2017 to 2024, and exactly one human being – a botnet operator typing an eight-year-old SSH key by hand.
threat-finder – open-source runtime CVE scanner
threat-finder is an open-source, Rust command-line scanner from OffSeq that finds CVEs in the software actually running on a host — not what a manifest claims — and ranks them by how network-reachable each affected service is, so operators fix what an attacker can actually touch first.
Have similar exposure in your environment?
[email protected]+371 2256 5353