DugganUSA · Live Telemetry wired for sound

What We See That Nobody Else Does

The first-party position: what our own sensors observe, versus what we redistribute from public feeds. Every figure carries its denominator — a number without one is not evidence. This page reads live from our own indexes; nothing here is hardcoded.

01The honest composition of the feed

Most threat-intel companies never publish this ratio. Ours is small on the first-party side, and that is exactly why it matters — it is the only part nobody else has.

Redistributed from public feeds
urlhaus · threatfox · spamhaus-drop · openphish · malwarebazaar · tor-exit · sslbl-ja3. Free and universally consumed — anyone pulling the same lists has identical coverage.
First-party observation
edge-honeypot · exploit-harvester · github-hunt · cf-shape-autoblock. Generated by our own sensors; cannot be obtained by subscribing to anything.
First-party share of live corpus
The claim we defend is distribution value plus original observation — never that a redistributed public list is our detection.

02The sensor

Our edge honeypot records every probe with ASN, organisation, arrival PoP, TLS version, HTTP protocol, user-agent, method and path — no external enrichment required.

Probe events recorded
Distinct source IPs
Distinct ASNs
A honeypot is supposed to get hit. Its value is the metadata per event, not the size of a blocklist. We never measure this sensor by how much of it we block, and we do not publish the addresses — an observation is not a target list.

03Two internets

Probe traffic against us does not track the CVE cycle. This is the most consequential thing our sensor says, and it is only visible with first-party data.

loading probe distribution…

Commodity mass-scanning is a permanent credential-and-WordPress firehose. Enterprise-appliance CVEs — the ones that dominate the headlines — are exploited in targeted operations that broad scan telemetry never sees. Those are two different threat models, and the under-resourced defender is being hit by the first one.

04Weaponization latency

Three timelines joined: CISA's KEV listing date, the first public proof-of-concept our GitHub watch saw, and the first probe against our own sensor. The third column is what makes it ours.

Median KEV → public PoC
Armed before CISA listed it
The window was already shut on listing day.
PoC exists, never probed us
Targeted-exploitation candidates.
CVEDays before KEV listing

05What we will not claim

Discipline is the product. A CVE with no PoC record reports UNKNOWN, never "slow to weaponize". A missing probe reports "not observed by our sensor", never "not exploited". Redistributing a public list is distribution value, never detection. Holding the /24 is block-coverage, not indicator-detection. These rules are compiled into the detectors, not just written in a style guide.