DStrakDEFENCE AND STRATEGIC KNOWLEDGE
Real observed threat intelligence

Live Cyber
Threat Map.

Explore recently observed cyberattack sources based on firewall and honeypot reports collected by the SANS Internet Storm Center/DShield sensor network.

SANS ISC / DShield observations

Live Cyber Threat Map

Each animated line connects two country locations. Its colour and animation are calculated from observed DShield source report volumes; the second country is visual context, not a disclosed victim destination.

Real DShield source-country activity
Observed sourceHigh volumeHighest volume
Understanding the display

How to read the threat map

The visualization maps verified feed fields without implying that DShield publishes exact attacker-to-victim routes.

01

Observed source

Each source IP, country and network shown in the activity feed comes from a current DShield source summary.

02

Report volume

Reports represent packets submitted by participating sensors. More reports produce brighter country-to-country lines.

03

Country connection

Both endpoints are country locations from the observed feed, making every path country to country.

04

Visual destination

The second endpoint provides geographic context only. It is not presented as a disclosed victim location.

Data methodology

Real observations,
honest limitations.

DStrak retrieves a sample of leading source IPs reported to the public DShield API, enriches them with country and network information from the same service, and caches the response for approximately one hour.

The map is an awareness and educational interface—not an incident-response console, attribution system or blocklist. A reported source may be compromised infrastructure, a cloud host, a scanner or a false positive. Location refers to network registration context and should not be interpreted as proof of an attacker’s physical location or nationality.

Read the official DShield API documentation ↗
Threat map questions

Frequently asked questions

Is the DStrak Live Cyber Threat Map showing real data?+

Yes. Source IPs, source countries, networks, report volumes and target counts come from observed SANS Internet Storm Center/DShield data. The animation visualizes aggregated observations rather than individual packets.

Do the animated lines show attack destinations?+

No. DShield does not publish exact victim locations. Each line connects two observed source-country locations for country-to-country context; it does not claim a real victim destination.

How often is the cyber threat data refreshed?+

DStrak refreshes and caches the public DShield sample approximately once per hour to provide recent observations without placing excessive demand on the upstream service.

Can these source IPs be used as a blocklist?+

No. DShield states that source summaries are unfiltered observations and may contain false positives. Investigate relevant context before making a security decision.