Observed source
Each source IP, country and network shown in the activity feed comes from a current DShield source summary.
Explore recently observed cyberattack sources based on firewall and honeypot reports collected by the SANS Internet Storm Center/DShield sensor network.
Each animated line connects two country locations. Its colour and animation are calculated from observed DShield source report volumes; the second country is visual context, not a disclosed victim destination.
The visualization maps verified feed fields without implying that DShield publishes exact attacker-to-victim routes.
Each source IP, country and network shown in the activity feed comes from a current DShield source summary.
Reports represent packets submitted by participating sensors. More reports produce brighter country-to-country lines.
Both endpoints are country locations from the observed feed, making every path country to country.
The second endpoint provides geographic context only. It is not presented as a disclosed victim location.
DStrak retrieves a sample of leading source IPs reported to the public DShield API, enriches them with country and network information from the same service, and caches the response for approximately one hour.
The map is an awareness and educational interface—not an incident-response console, attribution system or blocklist. A reported source may be compromised infrastructure, a cloud host, a scanner or a false positive. Location refers to network registration context and should not be interpreted as proof of an attacker’s physical location or nationality.
Read the official DShield API documentation ↗Yes. Source IPs, source countries, networks, report volumes and target counts come from observed SANS Internet Storm Center/DShield data. The animation visualizes aggregated observations rather than individual packets.
No. DShield does not publish exact victim locations. Each line connects two observed source-country locations for country-to-country context; it does not claim a real victim destination.
DStrak refreshes and caches the public DShield sample approximately once per hour to provide recent observations without placing excessive demand on the upstream service.
No. DShield states that source summaries are unfiltered observations and may contain false positives. Investigate relevant context before making a security decision.