SOC Overview
Loading dashboard…
Head to the Website Scanner to assess any domain in under a minute. The dashboard below shows live attacker activity from the SANS Internet Storm Center (DShield) feed — refreshed every 3 minutes, every number derived from what was actually observed worldwide in the last 24 hours.
Paste a domain → SSL posture, security headers, technology fingerprint, reputation, and AI-generated risk briefing. Quality scales with the API keys configured in Settings (VirusTotal, URLScan, Shodan, OTX).
| ID | Severity | Title | Source | Detected |
|---|---|---|---|---|
| ALR-198-8153 | critical | Botnet / C2 traffic from attacker IP | DShield · Dimitrovgrad, Bulgaria | |
| ALR-1-7310 | high | Brute-force / credential stuffing burst | DShield · Moscow, Russia | |
| ALR-34-4671 | high | Brute-force / credential stuffing burst | DShield · San Diego, United States | |
| ALR-33-4497 |
| high |
| Brute-force / credential stuffing burst |
| DShield · Amsterdam, The Netherlands |
| ALR-139-4488 | high | Brute-force / credential stuffing burst | DShield · Amsterdam, The Netherlands |
| ALR-3-4466 | high | Brute-force / credential stuffing burst | DShield · Pflugerville, United States |