Live · distributed sensor network

What the internet's attackers are doing, right now.

Venus operates a global network of honeypot sensors and turns the raw flood of probes, scans and exploit attempts into structured, research-grade threat intelligence. This public view is fully aggregated and redacted — the detailed corpus is available to vetted researchers.

aggregated origins · last 7 days
Redacted public view. No source IP addresses, request payloads, or captured credentials are shown here — only aggregates and trends.
Intelligence Brief · last 30 days

6650 actors engaged over the last 30 days; 5% escalated beyond initial reconnaissance. 7 of 8 tracked ATT&CK techniques actively observed this period — Cloud / OS Default Users sustained the highest source diversity over the period.

This week at a glance

Observed activity, last 7 days

Counts only. Every figure is an aggregate across the sensor network and carries no attribution to any individual host.

228.9k
Events observed
▼ 5.8%
2.3k
Distinct sources
▲ 2.2%
16,572
Critical attempts
▼ 1.5%
465
Distinct networks
▲ 3.8%
Platform Effectiveness · last 30 days
6,650
Actors engaged · 30d
5%
Escalation rate
35%
Return rate
3858h 39m
Total engagement

Where attacks originate

country-level · sized by volume
Top source countries

Where it's coming from

🇺🇸 United States
6.4k
🇨🇳 China
2.5k
🇧🇬 Bulgaria
2.4k
🇸🇪 Sweden
1.9k
🇪🇸 Spain
1.9k
🇩🇪 Germany
1.5k
🇷🇴 Romania
1.2k
🇳🇴 Norway
1.1k
🇹🇼 Taiwan
1.0k
🇳🇱 The Netherlands
1.0k
🇵🇱 Poland
932
🇧🇪 Belgium
829
🇬🇧 United Kingdom
779
🇫🇷 France
672
🇻🇳 Vietnam
621

Geographic origin reflects the network egress point, not necessarily the operator. Hosting and datacenter networks dominate.

Top originating networks · 30 days
Network / ASNTypeActorsEvents
Microsoft Corporation Hosting/DC 371 31.4k
Techoff Srv Limited Hosting/DC 34 26.6k
Unmanaged Ltd Hosting/DC 23 11.1k
Play2go International Limited Unknown 5 8.4k
Hangzhou Alibaba Advertising Co.,Ltd. Unknown 57 8.1k
Google LLC Hosting/DC 229 5.9k
Amazon.com, Inc. Hosting/DC 61 5.5k
DigitalOcean, LLC Hosting/DC 224 5.1k
UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED Unknown 75 4.1k
Tencent Building, Kejizhongyi Avenue Unknown 24 3.7k
OVH SAS Hosting/DC 36 3.7k
DIGI VPS Hosting/DC 2 3.5k
Reliance Communications Ltd.DAKC MUMBAI ISP/Residential 1 3.4k
Feo Prest SRL Unknown 7 3.2k
Limited Network LTD Unknown 18 3.1k
Intelligence overview

30-day campaign & technique picture

Campaign event volume over the last 30 days. Each line represents one threat actor family targeting the sensor network.

MITRE ATT&CK · observed techniques
T1595.002
Vulnerability Scanning
T1046
Network Service Discovery
T1190
Exploit Public-Facing App
T1110.001
Password Spraying
T1110.003
Credential Stuffing
T1133
External Remote Services
T1059
Command/Scripting Interpreter
T1496
Resource Hijacking

Gold = actively observed this period.

Redacted signal sample

Recent observations

A live sample with source addresses masked to /16 and exact payloads withheld — category only.

18:32195.222.x.xScanner / probe
18:32106.92.x.xScanner / probe
18:32183.104.x.xScanner / probe
18:32106.92.x.xScanner / probe
18:32183.104.x.xScanner / probe
18:32183.104.x.xScanner / probe
18:32183.104.x.xScanner / probe
18:32118.139.x.xScanner / probe
18:32106.92.x.xScanner / probe
This week's read
Path traversal ▲ 33.3%
32 attempts observed this week, up from 24 last week.
RCE attempt ▲ 15.8%
44 attempts observed this week, up from 38 last week.
SQL injection → 0.0%
11 attempts observed this week · no prior data.

Full intelligence, for researchers.

The gated Venus console exposes per-actor profiles, session replays, pattern corpora and downloadable evidence bundles. Access is vetted and every action is logged.

Request access →
Method & ethics

How this stays safe to publish

Aggregate only
Public figures are network-wide counts. No single sensor, host or victim is identifiable.
Addresses masked
Where a sample is shown, source IPs are truncated to /16 and never published in full.
No live payloads
Exploit strings and captured credentials are classified to a category and withheld verbatim.
VENUS · ELYTRA SECURITY · GLOBAL HONEYPOT INTELLIGENCE Aggregated & redacted public view · © 2026 Elytra Security