Attack paths
Leading origin-to-target flows
Loading observed attack geography…
Flows use Cloudflare-observed origin and target country pairs. Loading the latest aggregate snapshot…
Unified security intelligence
Live intelligence on threat actors, ransomware, vulnerabilities, weaknesses, and honeypot activity.
CISA exploitation signals
Loading recent CISA assessments…
Active exploitation and public proof-of-concept signals are not, by themselves, confirmation that a vulnerability was exploited as a zero-day.
Near-live network telemetry
Attack paths
Loading observed attack geography…
Flows use Cloudflare-observed origin and target country pairs. Loading the latest aggregate snapshot…
Ranked paths
Loading attack paths…
Origin snapshot · DShield
Loading country totals…
Service targeting
Loading port totals…
Source telemetry provided by SANS Technology Institute, Internet Storm Center ↗. Target and flow views use aggregated Cloudflare Radar ↗ layer 7 mitigated-request data; target geography reflects the attacked zone’s billing country.
Loading dashboard snapshots…
Public threat-actor intelligence
Explore country-attributed and suspected state-linked actors, their aliases, targets, and primary research references.
Attributed profiles
—Country or sponsor metadataCountries represented
—Structured country codesSuspected sponsors
—Explicit sponsor claimsLast refreshed
—Cached for 24 hoursOpen source · MISP Galaxy
Loading threat-actor profiles…
Actor data provided by MISP Galaxy ↗. Follow each profile’s references before making attribution or response decisions.
Threat-actor intelligence · Visual analysis
Explore attribution concentration, reported target sectors, catalog coverage, and the naming and research depth behind public actor profiles.
Loading actor chart data…
Actor data provided by MISP Galaxy ↗. Country and sponsor fields are attribution claims and may be disputed.
Live weakness intelligence
The software weakness patterns most connected to active exploitation, ransomware, and near-term exploit probability.
Catalog version
Loading…Fetching current releaseTotal weaknesses
—Defined software weaknessesCategories
—Organized CWE groupingsViews
—Catalog perspectivesTop ten · CISA KEV + EPSS
Loading live CWE records…
CWE record lookup
Enter the numeric part of a CWE ID. Try or .
Weakness intelligence · Visual analysis
Compare the signals driving the current top-ten weakness ranking.
Loading CWE chart data…
Active vulnerability intelligence
Recently exploited vulnerabilities ranked by real-world activity, ransomware use, exploit probability, recency, and technical severity.
Tracking window
—Recent KEV additionsActive candidates
—CVEs evaluatedRansomware linked
—Within the top tenCatalog release
—CISA KEV snapshotTop ten · KEV + EPSS + NVD
Loading live CVE records…
CVE record lookup
Enter a complete CVE identifier, with or without the CVE prefix.
Vulnerability intelligence · Visual analysis
See why each actively exploited vulnerability is rising to the top.
Loading CVE chart data…
Near-live CISA assessments
Recent CVEs with active-exploitation, public proof-of-concept, or high-risk automatable/total-impact signals from CISA ADP Vulnrichment.
Active exploitation
—Recent CISA assessmentsPublic PoC
—Proof-of-concept availableHigh-risk candidates
—Automatable + total impactLast source update
—Official CVE List releaseCISA ADP · 14-day window
Loading CISA exploitation assessments…
CISA enrichment is consumed from the official CVE List V5 ↗. The source updates approximately hourly; Threat Watch caches the filtered feed for one hour.
CISA exploitation signals · Visual analysis
Explore when priority assessments appear, how readily vulnerabilities can be exploited, and which vendors are most represented.
Loading exploitation charts…
CISA enrichment is consumed from the official CVE List V5 ↗. Active exploitation does not by itself prove zero-day use.
Community honeypot telemetry
Current attacker, port, SSH, and web-scanning signals collected by the global DShield sensor community.
Honeypot indicators
—SSH and web scanner IPsSSH attackers
—DShield Cowrie indicatorsWeb scanners
—Web honeypot indicatorsLast refreshed
—Cached for one hourPublic telemetry · SANS ISC
Loading DShield telemetry…
DShield reputation lookup
Returns DShield report volume, observed targets, dates, network, and ASN metadata.
Data provided by SANS Technology Institute, Internet Storm Center ↗. DShield data may not be resold.
Community honeypot telemetry · Visual analysis
Compare the sources, services, and credentials appearing across the current DShield community snapshot.
Loading DShield chart data…
Data provided by SANS Technology Institute, Internet Storm Center ↗. DShield data may not be resold.
Public leak-site intelligence
Groups ranked by unique victim claims publicly observed by RansomLook during the rolling 30-day window.
Observed claims
—Unique claims in 30 daysActive groups
—Groups with observed claimsLeading share
—Share held by the top groupLast refreshed
—Cached for one hourTop ten · 30-day public claims
Loading ransomware activity…
Activity data provided by RansomLook ↗. Victim claims are observational intelligence and may be incomplete, duplicated at the source, or incorrectly attributed.
Ransomware leak-site intelligence · Visual analysis
Compare 30-day claim volume, current seven-day activity, group share, and the daily discovery timeline.
Loading ransomware chart data…
Activity data provided by RansomLook ↗. Counts represent publicly observed victim claims, not independently confirmed attacks.