Known gaps in the data #
Windows in which something did not collect, or data did not reach every destination. The list is generated from the incident analyses and never maintained by hand – each gap links to the incident that caused it. The files from the archive are the source of truth, not the counts in the live syslog.
| From | To | Length | Servers | Stream | Recoverable | Recovered | Incident |
|---|---|---|---|---|---|---|---|
| 2026-08-22 00:15:21 UTC | 2026-08-22 11:31:30 UTC | 11 h 16 min | srv3 | pcap (eth0) — ještě neběžel | no | not recovered | 2026-08-22-srv3-pcap-ring-buffer-snaplen |
| 2026-08-22 11:31:30 UTC | 2026-08-22 11:35:51 UTC | 4 min | srv3 | pcap (eth0) — přepsáno po rebootu | no | not recovered | 2026-08-22-srv3-pcap-ring-buffer-snaplen |
| 2026-08-22 15:40:00 UTC | 2026-08-24 18:51:21 UTC | 2 d 3 h | srv3 | webtrap-https (443/tcp) | no | not recovered | 2026-08-22-srv3-webtrap-https-tls-accept-hang |
| 2026-08-24 16:18:29 UTC | 2026-08-24 18:48:28 UTC | 2 h 30 min | srv3 | dionaea (všechny emulované protokoly) | no | not recovered | 2026-08-24-srv3-dionaea-mongod-parser-freeze |
| 2026-08-25 09:41:00 UTC | 2026-08-25 10:04:00 UTC | 23 min | srv3 | dionaea (všechny emulované protokoly) | no | not recovered | 2026-08-24-srv3-dionaea-mongod-parser-freeze |
| 2026-08-27 00:33:00 UTC | 2026-08-27 00:54:00 UTC | 21 min | srv3 | dionaea (všechny emulované protokoly) | no | not recovered | 2026-08-24-srv3-dionaea-mongod-parser-freeze |
| 2026-08-27 18:33:00 UTC | 2026-08-27 18:54:00 UTC | 21 min | srv3 | dionaea (všechny emulované protokoly) | no | not recovered | 2026-08-24-srv3-dionaea-mongod-parser-freeze |
| 2026-08-28 08:48:00 UTC | 2026-08-28 09:09:00 UTC | 21 min | srv3 | dionaea (všechny emulované protokoly) | no | not recovered | 2026-08-24-srv3-dionaea-mongod-parser-freeze |
| 2026-08-28 12:08:00 UTC | 2026-08-28 12:31:00 UTC | 23 min | srv3 | dionaea (všechny emulované protokoly) | no | not recovered | 2026-08-24-srv3-dionaea-mongod-parser-freeze |
| 2026-08-28 12:34:00 UTC | 2026-08-28 13:01:00 UTC | 27 min | srv3 | dionaea (všechny emulované protokoly) | no | not recovered | 2026-08-24-srv3-dionaea-mongod-parser-freeze |
| 2026-08-28 18:52:50 UTC | 2026-09-16 00:00:00 UTC | 18 d 5 h | srv3 | dionaea SIP (5060) — emulace vypnuta | no | not recovered | 2026-08-24-srv3-dionaea-mongod-parser-freeze |
| 2026-08-28 20:42:00 UTC | 2026-08-28 20:51:30 UTC | 10 min | srv3 | dionaea (všechny emulované protokoly) | no | not recovered | 2026-08-24-srv3-dionaea-mongod-parser-freeze |
| 2026-08-31 13:13:40 UTC | 2026-08-31 13:26:04 UTC | 12 min | srv3 | dionaea (všechny emulované protokoly) | no | not recovered | 2026-08-24-srv3-dionaea-mongod-parser-freeze |
| 2026-08-31 14:12:42 UTC | 2026-08-31 14:22:03 UTC | 9 min | srv3 | dionaea (všechny emulované protokoly) | no | not recovered | 2026-08-24-srv3-dionaea-mongod-parser-freeze |
| 2026-08-31 16:35:03 UTC | 2026-08-31 16:46:09 UTC | 11 min | srv3 | dionaea (všechny emulované protokoly) | no | not recovered | 2026-08-24-srv3-dionaea-mongod-parser-freeze |
| 2026-09-01 04:10:00 UTC | 2026-09-01 04:20:29 UTC | 10 min | srv3 | dionaea (všechny emulované protokoly) | no | not recovered | 2026-08-24-srv3-dionaea-mongod-parser-freeze |
| 2026-09-01 07:22:00 UTC | 2026-09-01 07:32:36 UTC | 11 min | srv3 | dionaea (všechny emulované protokoly) | no | not recovered | 2026-08-24-srv3-dionaea-mongod-parser-freeze |
| 2026-09-01 07:57:00 UTC | 2026-09-01 08:03:21 UTC | 6 min | srv3 | dionaea (všechny emulované protokoly) | no | not recovered | 2026-08-24-srv3-dionaea-mongod-parser-freeze |
| 2026-09-02 08:16:00 UTC | 2026-09-02 08:26:03 UTC | 10 min | srv3 | dionaea (všechny emulované protokoly) | no | not recovered | 2026-08-24-srv3-dionaea-mongod-parser-freeze |
| 2026-09-07 17:35:36 UTC | 2026-09-07 17:44:17 UTC | 9 min | srv3 | dionaea (všechny emulované protokoly) | no | not recovered | 2026-08-24-srv3-dionaea-mongod-parser-freeze |
| 2026-09-07 18:23:40 UTC | 2026-09-07 18:26:20 UTC | 3 min | srv3 | dionaea (všechny emulované protokoly) | no | not recovered | 2026-08-24-srv3-dionaea-mongod-parser-freeze |
| 2026-09-07 20:06:16 UTC | 2026-09-07 20:07:03 UTC | 1 min | srv3 | dionaea (vsechny emulovane protokoly) | no | not recovered | 2026-09-07-srv3-deliberate-dionaea-freeze-repro |
| 2026-09-13 04:22:00 UTC | 2026-09-13 05:01:50 UTC | 40 min | srv3 srv4 | syslog | yes | from the archive | Control channel outage |
Source: the data_gaps of every incident in Incidents
Own traffic to filter out #
Not everything in the data comes from attackers. These values belong to monitoring and to tests during deployment, and should be excluded before analysis.
| Field | Value | Period | Description |
|---|---|---|---|
src_ip |
169.58.205.217 |
whole run | Watchdog probes from srv3. translated |
path |
/hp-watchdog-probe |
whole run | The path the watchdog probes request. translated |
user_agent |
hp-watchdog |
whole run | User-Agent of the watchdog probes. translated |
src_ip |
127.0.0.1 |
2026-08-21 — 2026-08-22 | Test data from deployment. translated |
src_ip |
10.222.0.0/24 |
2026-08-21 — 2026-08-22 | Test data from deployment. translated |
Analysis pitfalls #
Mistakes that are easy to make with this data – how to spot them and how to avoid them.
- The ::ffff: prefix on IPv4 addresses cowrie writes IPv4 addresses as ::ffff:203.0.113.5. Unless the prefix is stripped, the same attacker is counted twice – once from cowrie and once from the other sensors.
- Redirected ports on srv4 On srv4, cowrie sees ports 42222 and 42223 and hpweb sees 42280 and 42443. These are not the ports the attacker aimed at but the nftables redirect target. Only hptcp knows the real destination port. For cowrie and hpweb on srv4, ignore the port or derive it from the session.
- Own traffic Monitoring probes, test data from deployment and diagnostic commands by agents and the operator. The concrete values to filter out are in the table above.
- Campaigns Single campaigns could produce most of a day’s traffic. Without separating campaigns from baseline noise, a volume chart looks like a trend or a collection outage.
- Event time, not processing time For time-based analysis use the timestamp inside the event. Log copies on the collection server also carry a receive time that can be hours or days later.
- Incomparable servers srv4 exposed a surface orders of magnitude larger than srv3. Absolute counts of the two servers cannot be compared, only their structure and ranking.
- Format changes during the run The agents adjusted configuration during checks, so the format of some records may have changed mid-run. Specific changes will be added after going through the data; their trace is in the run log.
What the data cannot tell you #
The limits of what this data can support are best stated up front.
- Two servers are not statistics The results describe what reached two particular servers. General conclusions about the whole internet cannot be drawn from them.
- One provider, one location Both servers ran at the same provider. Attackers target address ranges differently, and elsewhere the traffic could look different.
- Less than a month The run captured the campaigns that happened to be active – not long-term trends or seasonality.
- An address’s country is not the attacker’s origin Geolocation says where a source address is registered. Attacks routinely go through rented servers, proxies and compromised devices, so the address’s country does not tell you where the attacker comes from.
- Comparing language models Each server was run by a different model, but two runs are not enough to judge which model is better. Differences in the data can have many causes, from the exposed surface to individual technical decisions.
How the data is prepared for publication #
Under the GDPR a source IP address is personal data. It was collected in full for analysis and appears in the results only in aggregate.
How the published raw data is pseudonymised, and what is lost in the process, will be described when the data is published.
Found a bug, missing data or a leak of sensitive information? Report a problem