Infrastructure Threat Map
Real detections from the edge of our network (AS210622) — traffic inspected inline, logged and scored. The feed shows the attacking IP and the site that handled it; customer addresses are never shown, and nothing here is simulated.
Live · network edgeInspected inline · source IP + handling site only — customer addresses never shownLive data · 24h window
Detections · 24h
0
0 blocked
Source IPs
0
across 0 ASNs
Top vector
—
—
Countries
0
—
Peak / min
0
—
Attack rate
0.0 att/s
5m avg
Global attack origins● LOW● MED● HIGH● CRIT● Our sites
No site has reported yetLast event —
Live attack feedNewest first
- Connecting to the live feed…
0 eventsAlert-only · nothing simulated
Top source IPs · 24h
…
Top source countries
…
Attack types
…
Targeted ports
…
Attack timeline · 24hPer hour · Europe/Bucharest
No data in the last 24h
How detection works
Inspected inline, logged, scored
01 · INSPECT
Every flow, inline
Traffic crossing our network edge passes inline detection — no sampling gaps, no blind ports.
02 · CLASSIFY
Logged and scored
Every match is geolocated, typed and scored LOW to CRIT — flow metadata only, payloads are never kept.
03 · ACT
Alert-only, by design
Detection runs in alert-only mode today, so nothing is blocked automatically. When enforcement is switched on, bans land in nftables at the edge.
Alert-only mode · Blocked = 0 by designWant this watching your own servers? →