Is this IP / domain known to be probing? Returns our verdict, whether it is a recognised benign scanner, the CVEs it probed, plus ports / paths / fingerprints.
Ranked leaderboard of source IPs, ASNs, countries, ports, user-agents, or CVEs (`by='cve'`) over a time window.
Raw honeypot events matching filters (IP, ASN, country, dest_port, protocol, http_method, ja4/ja3/akin, community_id, has_client_cert).
Hourly / daily attack volume over a window, with protocol / country / port filters.
Full profile for an ASN: total events, unique IPs, top ports, source countries, user-agents, org name.
Search by TLS JA4 / JA3, HTTP Akin or SSH HASSH fingerprint to find shared infrastructure.
Request shapes within a few headers of an Akin HTTP fingerprint, what those clients ask for, and the family the token belongs to.
Who is probing a named CVE: severity, KEV status, top probing IPs with ASN and scanner tag, fingerprints, sample paths, daily timeline.
Full-text URL-path + user-agent search across attack traffic.