Live · distributed sensor network

What the internet's attackers are doing, right now.

Venus operates a global network of honeypot sensors and turns the raw flood of probes, scans and exploit attempts into structured, research-grade threat intelligence. This public view is fully aggregated and redacted — the detailed corpus is available to vetted researchers.

aggregated origins · last 7 days
Redacted public view. No source IP addresses, request payloads, or captured credentials are shown here — only aggregates and trends.
Intelligence Brief · last 30 days

20943 actors engaged over the last 30 days; 2% escalated beyond initial reconnaissance. 11 of 11 tracked ATT&CK techniques actively observed this period — Cloud / OS Default Users sustained the highest source diversity over the period.

This week at a glance

Observed activity, last 7 days

Counts only. Every figure is an aggregate across the sensor network and carries no attribution to any individual host.

1.1m
Events observed
▲ 34.1%
5.9k
Distinct sources
▼ 17.2%
8,476
Critical attempts
▲ 6.5%
1,246
Distinct networks
▼ 14.8%
Platform Effectiveness · last 30 days
20,943
Actors engaged · 30d
2%
Escalation rate
35%
Return rate
35971h 5m
Total engagement

Where attacks originate

country-level · sized by volume
Top source countries

Where it's coming from

🇩🇪 Germany
388.6k
🇳🇱 The Netherlands
147.3k
🇺🇸 United States
58.9k
🇮🇳 India
46.6k
🇻🇳 Vietnam
44.0k
🇹🇳 Tunisia
43.1k
🇵🇰 Pakistan
38.8k
🇺🇦 Ukraine
37.8k
🇮🇷 Iran
26.3k
🇧🇬 Bulgaria
25.2k
🇫🇮 Finland
22.2k
🇧🇪 Belgium
19.9k
🇯🇵 Japan
19.9k
🇧🇩 Bangladesh
18.1k
🇫🇷 France
17.9k

Geographic origin reflects the network egress point, not necessarily the operator. Hosting and datacenter networks dominate.

Top originating networks · 30 days
Network / ASNTypeActorsEvents
Datacamp Limited Unknown 62 623.0k
CLOUDFOREST CO., LTD. Unknown 8 367.9k
Nayatel (Pvt) Ltd Unknown 41 294.1k
Google LLC Hosting/DC 637 280.8k
Triple T Broadband Public Company Limited ISP/Residential 47 201.6k
OVH SAS Hosting/DC 147 182.4k
Agence Tunisienne Internet ISP/Residential 2 177.7k
Hetzner Online GmbH Hosting/DC 48 169.1k
MEVSPACE sp. z o.o. Unknown 22 143.8k
Philippine Long Distance Telephone Company Unknown 74 106.7k
3S INF Unknown 14 102.7k
COTAS LTDA. Unknown 9 93.2k
IDDQD-AS Unknown 393 92.0k
Iran Telecommunication Company PJS ISP/Residential 159 91.1k
Tencent Building, Kejizhongyi Avenue Unknown 153 81.9k
Intelligence overview

30-day campaign & attempted-technique picture

Campaign event volume over the last 30 days. Each line represents one threat actor family targeting the sensor network.

MITRE ATT&CK · attempted techniques

These are the techniques operators have tried against the sensor network.

T1595.001
Scanning IP Blocks
T1595.002
Vulnerability Scanning
T1190
Exploit Public-Facing App
T1059.004
Unix Shell
T1505.003
Web Shell
T1078
Valid Accounts
T1110
Brute Force
T1552.001
Credentials In Files
T1046
Network Service Discovery
T1083
File/Directory Discovery
T1021.004
Remote Services: SSH

Gold = attempted during this period.

Redacted signal sample

Recent observations

A live sample with source addresses masked to /16 and exact payloads withheld — category only.

11:01203.76.x.x🇧🇩 BDRecon / scan
11:01109.123.x.x🇫🇷 FRRecon / scan
11:01109.123.x.x🇫🇷 FRRecon / scan
11:01109.123.x.x🇫🇷 FRRecon / scan
11:01147.90.x.x🇩🇪 DERecon / scan
11:01203.76.x.x🇧🇩 BDRecon / scan
11:01109.123.x.x🇫🇷 FRRecon / scan
11:01109.123.x.x🇫🇷 FRRecon / scan
11:01109.123.x.x🇫🇷 FRRecon / scan
This week's read
RCE attempt ▲ 117.8%
257 attempts observed this week, up from 118 last week.
Path traversal ▲ 46.3%
1,612 attempts observed this week, up from 1,102 last week.
Webshell upload ▲ 7.5%
7,737 attempts observed this week, up from 7,195 last week.

Full intelligence, for researchers.

The gated Venus console exposes per-actor profiles, session replays, pattern corpora and downloadable evidence bundles. Access is vetted and every action is logged.

Request access →
Method & ethics

How this stays safe to publish

Aggregate only
Public figures are network-wide counts. No single sensor, host or victim is identifiable.
Addresses masked
Where a sample is shown, source IPs are truncated to /16 and never published in full.
No live payloads
Exploit strings and captured credentials are classified to a category and withheld verbatim.
VENUS · ELYTRA SECURITY · GLOBAL HONEYPOT INTELLIGENCE Figures last updated 2026-10-07 11:50 UTC Aggregated & redacted public view · © 2026 Elytra Security