Beec0n ssh honeypot threat intelligence dashboard

CONNECTING ·

Live attack map

LAST 10 HITS

Total events

last 24h

Login attempts

Unique IPs

Malware grabs

downloads seen

Attacker origins

GEOIP

Waiting for data…

Attack volume · hourly (24h)

7-day trend

Top credentials

Waiting…

Top commands

Waiting…

Download targets

Waiting…

Threat intel matches

ABUSE.CH THREATFOX

Waiting for data…

Live session log

MOST RECENT · LIVE

Waiting for events…

Access the intel

Observed indicators from the last 24h. Low-confidence: source IPs are seen scanning a honeypot and may be compromised or spoofed third-party hosts — use as one signal, not an authoritative blocklist.

Blocklist feed

Full attacker IPs, newline-delimited. Refreshed every 10s.

/feed/blocklist.txt

Stats export

Aggregated stats — event counts, top credentials and commands. Geo shown on-page only.

summary.csv

STIX / TAXII

Structured threat-intel export over a TAXII feed.

planned

built by Bi0u · v1.0 · refreshes every 10s

display IPs masked · feed has full IPs

powered by Cowrie · threat intel from abuse.ch ThreatFox · includes GeoLite2 data created by MaxMind, available from maxmind.com