Venus operates a global network of honeypot sensors and turns the raw flood of probes, scans and exploit attempts into structured, research-grade threat intelligence. This public view is fully aggregated and redacted — the detailed corpus is available to vetted researchers.
20943 actors engaged over the last 30 days; 2% escalated beyond initial reconnaissance. 11 of 11 tracked ATT&CK techniques actively observed this period — Cloud / OS Default Users sustained the highest source diversity over the period.
Counts only. Every figure is an aggregate across the sensor network and carries no attribution to any individual host.
Geographic origin reflects the network egress point, not necessarily the operator. Hosting and datacenter networks dominate.
| Network / ASN | Type | Actors | Events |
|---|---|---|---|
| Datacamp Limited | Unknown | 62 | 623.0k |
| CLOUDFOREST CO., LTD. | Unknown | 8 | 367.9k |
| Nayatel (Pvt) Ltd | Unknown | 41 | 294.1k |
| Google LLC | Hosting/DC | 637 | 280.8k |
| Triple T Broadband Public Company Limited | ISP/Residential | 47 | 201.6k |
| OVH SAS | Hosting/DC | 147 | 182.4k |
| Agence Tunisienne Internet | ISP/Residential | 2 | 177.7k |
| Hetzner Online GmbH | Hosting/DC | 48 | 169.1k |
| MEVSPACE sp. z o.o. | Unknown | 22 | 143.8k |
| Philippine Long Distance Telephone Company | Unknown | 74 | 106.7k |
| 3S INF | Unknown | 14 | 102.7k |
| COTAS LTDA. | Unknown | 9 | 93.2k |
| IDDQD-AS | Unknown | 393 | 92.0k |
| Iran Telecommunication Company PJS | ISP/Residential | 159 | 91.1k |
| Tencent Building, Kejizhongyi Avenue | Unknown | 153 | 81.9k |
Volume by attack category this week against the previous week. Trend lines show the last 14 days.
| Category | 14-day trend | This week | vs last week |
|---|---|---|---|
| RCE attempt | 257 | ▲ 117.8% | |
| Path traversal | 1,612 | ▲ 46.3% | |
| Webshell upload | 7,737 | ▲ 7.5% | |
| SQL injection | 12 | → 0.0% | |
| Credential stuffing | 232,466 | ▼ 6.6% | |
| Scanner / recon | 43,791 | ▼ 7.7% |
Campaign event volume over the last 30 days. Each line represents one threat actor family targeting the sensor network.
These are the techniques operators have tried against the sensor network.
Gold = attempted during this period.
A live sample with source addresses masked to /16 and exact payloads withheld — category only.
The gated Venus console exposes per-actor profiles, session replays, pattern corpora and downloadable evidence bundles. Access is vetted and every action is logged.