Live Attack Telemetry
Full-screen visualization of attacks crossing the ervik.as sensor network, with a live feed of source, destination, type and severity.
Where does this data come from?
The map is fed by the SANS ISC DShield sensor network — a global collection of honeypots and firewall logs that report the most aggressive attacking IPs on the internet. Source IPs are geolocated in real time, and each line represents an observed attack crossing from a source country to a major data-center hub.
Threat types are inferred from DShield's intel feed tags (e.g., miner, scanner, brute-force). Severity is based on attack volume: critical for the most prolific sources, scaling down to low for emerging scanners.
