Tags
Browse and search all threat intelligence tags
Admin Panel Hunt
Web-attackScanning for administrative interfaces
CGI Script Hunt
Web-attackScanning for vulnerable CGI scripts
Cisco ASA Probe
ReconReconnaissance probe targeting Cisco ASA firewall and VPN infrastructure. Indicates scanning for Cisco ASA devices, typically preceding exploitation attempts.
Cisco UCM Exploit
CveIPs observed attempting to exploit CVE-2026-20045, an unauthenticated remote code execution vulnerability in the web management interface of Cisco Unified Communications Manager.
Cisco UCM Probe
ReconIPs observed probing Cisco Unified Communications infrastructure — administrator consoles, self-service portals, version endpoints and voice services across Cisco Unified Communications Manager (CUCM), Unity Connection, IM & Presence and Unified Contact Center Express.
Citrix ADC / Gateway Probe
ReconHTTP request targeting Citrix ADC or Citrix Gateway (formerly NetScaler ADC/Gateway) specific URL paths, indicating deliberate reconnaissance or scanning for Citrix remote access infrastructure.
CMS Enumeration
Web-attackContent management system discovery and enumeration
Config File Hunt
Web-attackScanning for exposed configuration files
cPanel Auth Bypass (CVE-2026-41940)
CveActive exploitation of the cPanel and WHM pre-authentication bypass vulnerability, targeting the WHM admin interface and cPanel session authentication endpoints.
cPanel Probe
ReconReconnaissance probe targeting cPanel and WHM web hosting control panel infrastructure. Detected via cPanel-specific HTTP paths and connections to native cPanel and WHM management ports.
Database Admin Hunt
Web-attackScanning for database admin interfaces (phpMyAdmin, etc.)
Directory Traversal Attempt
Web-attackPath traversal attack attempting to access restricted files
Enterprise Software Probe
Web-attackProbing for enterprise software (Confluence, Jenkins, etc.)
Exchange Probe
ExploitProbing Microsoft Exchange for ProxyShell/ProxyLogon vulnerabilities
File Upload Attempt
Web-attackAttempting to upload potentially malicious files
FortiOS API Probe
ReconIPs observed probing the Fortinet FortiOS REST management API — the configuration, monitoring and log endpoints that expose administrator accounts, live device state and traffic records.
FortiOS SSL-VPN Probe
ReconIPs observed probing the Fortinet FortiOS SSL-VPN web portal — the remote-access login, credential-check, client-integrity and portal-information endpoints — fingerprinting FortiGate SSL-VPN deployments and identifying reachable versions ahead of exploitation.
GlobalProtect Probe
ReconProbing Palo Alto GlobalProtect VPN login endpoints
IoT Default Credential Attempt
BotnetDefault credential stuffing attempt on telnet
Ivanti Connect Secure Probe
ReconIPs observed probing Ivanti Connect Secure (formerly Pulse Secure) SSL VPN infrastructure — fingerprinting the DANA session-root surface to identify reachable Ivanti remote access deployments ahead of exploitation.
Ivanti EPMM Exploit
CveCVE-2026-1281/CVE-2026-1340 Ivanti Endpoint Manager Mobile pre-auth RCE via Bash arithmetic expansion in /mifs/c/appstore/fob/ and /mifs/c/aftstore/fob/ endpoints
MCP Server Scan
ReconScanning for exposed Model Context Protocol (MCP) and Server-Sent Events (SSE) endpoints
Mirai Credential Spray
BotnetMirai-specific IoT default credentials detected in telnet payload
Mirai Scanner
BotnetMirai-style port 23/2323 dual scanning pattern detected
Outlaw Botnet
BotnetAn IP with this tag has been identified as the Outlaw (a.k.a. Dota) SSH cryptojacking botnet — a self-propagating Monero-mining botnet that spreads across SSH servers
P2PInfect Botnet
BotnetAn IP with this tag has been identified as the P2PInfect Redis/SSH worm botnet — a self-replicating Rust-based peer-to-peer botnet that spreads across exposed Redis servers and enrolls each victim into its payload-serving mesh
PHPUnit RCE Scan
ExploitScanning for exposed PHPUnit eval-stdin.php endpoint allowing arbitrary PHP code execution
Port Scan
ReconScanning 5+ ports on target host
RDP Connection Attempt
ActivityRemote Desktop Protocol (RDP) connection attempt detected on port 3389
Redis Connection Attempt
ActivityConnection established to a Redis service on port 6379
Router Exploit
Web-attackAttempting router firmware exploits (Netgear, D-Link, etc.)
SharePoint Active Exploitation
CveActive exploitation of SharePoint vulnerabilities
SharePoint Webshell Scanning
CveScanning for SharePoint web shells
SIP Register Scanner
ActivitySIP VoIP scanning activity on port 5060
SMTP Auth Attempt
ActivityHost submitted an SMTP AUTH command to a honeypot mail server. Consistent with open-relay scouting or opportunistic credential submission.
SMTP Bruteforcer
Brute-forceHost made repeated SMTP AUTH attempts within a short window, strongly indicative of credential spraying against a mail server.
SolarWinds Probe
Web-attackProbing for SolarWinds Orion endpoints
SonicWall NGFW Probe
ReconIPs observed probing SonicWall Next-Generation Firewall management surfaces, fingerprinting the SonicOS REST API and management GUI to identify reachable SonicWall NGFW deployments ahead of exploitation.
SQL Injection Attempt
Web-attackSQL injection attack detected in request
SSH Bruteforcer
Brute-forceRepeated SSH credential attempts from this IP — username and password submitted multiple times to the SSH honeypot
SSH Connection Attempt
ActivitySSH connection attempt detected on port 22 or 2222
SSH Login Attempt
ActivitySSH credential attempt observed — attacker submitted a username and password to the SSH honeypot
Telnet Bruteforcer
Brute-forceMultiple username/password submissions to Telnet honeypot
Telnet Connection Attempt
ActivityTelnet connection attempt detected on port 23 or 2323
Telnet Login Attempt
ActivityTelnet credential attempt observed — attacker submitted a username and password to a Telnet server
ThinkPHP RCE
ExploitExploiting ThinkPHP framework invokefunction endpoint for remote code execution
TLS/SSL Crawler
ActivityTLS/SSL connection fingerprinting detected via Suricata
VNC Bruteforcer
Brute-forceRepeated VNC authentication attempts from a single IP address
VNC Connection Attempt
ActivityVNC connection established on port 5900/5901
VNC Login Attempt
ActivityVNC authentication attempt on port 5900/5901