Threat lookup.
Search by IP, CIDR, ASN, or domain (partial OK). Free, no account. Or skim the live data below and click into any value to drill in.
query syntax
field:value pairs combined with AND, OR, NOT and parentheses. Case-insensitive keywords.
port:445 · country:NL · asn:14061 · cidr:80.82.77.0/24 · proto:rdp · cve:CVE-2017-0144 · ja4:… · ja4h:… · ja3:… · hassh:… · domain:example.com · path:/wp-login.php · ua:zgrab · tag:scanner · header:x-forwarded-for · banner:SSH-2.0 · has:cert
Anonymous visitors can run single-field pivots; boolean and text queries need a free account. The examples above are pre-authorized for everyone.
Or explore candidate campaign clusters, fingerprints carried by many IPs across only a handful of networks.
Most active right now
top 10, last 7 days · click for full reportCVEs being scanned right now
24h · top 8 of 17 · 8 actively exploited · KEV = on CISA actively-exploited listGitea Container Registry - Unauthorized Private Image Access
Apache 2.4.49/2.4.50 - Path Traversal and Remote Code Execution
Gravity SMTP WordPress Plugin - Sensitive Information Exposure
cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
Most-seen fingerprints
copy any to your detection rulesSSH HASSH
24h · click to find peersTLS JA4
24h · click to find peersLive leaderboards
aggregated 24hTop countries
24hTop ASNs
24hTop ports
24hcurl honeylabs.net/lookup/<ip>