The first-party position: what our own sensors observe, versus what we
redistribute from public feeds. Every figure carries its denominator — a number without one
is not evidence. This page reads live from our own indexes; nothing here is hardcoded.
01The honest composition of the feed
Most threat-intel companies never publish this ratio. Ours is small on the
first-party side, and that is exactly why it matters — it is the only part nobody else has.
—
Redistributed from public feeds
urlhaus · threatfox · spamhaus-drop · openphish · malwarebazaar · tor-exit · sslbl-ja3. Free and universally consumed — anyone pulling the same lists has identical coverage.
—
First-party observation
edge-honeypot · exploit-harvester · github-hunt · cf-shape-autoblock. Generated by our own sensors; cannot be obtained by subscribing to anything.
—
First-party share of live corpus
The claim we defend is distribution value plus original observation — never that a redistributed public list is our detection.
02The sensor
Our edge honeypot records every probe with ASN, organisation, arrival PoP, TLS
version, HTTP protocol, user-agent, method and path — no external enrichment required.
—
Probe events recorded
—
Distinct source IPs
—
Distinct ASNs
A honeypot is supposed to get hit. Its value is the
metadata per event, not the size of a blocklist. We never measure this sensor by how much of it
we block, and we do not publish the addresses — an observation is not a target list.
03Two internets
Probe traffic against us does not track the CVE cycle. This is the most
consequential thing our sensor says, and it is only visible with first-party data.
loading probe distribution…
Commodity mass-scanning is a permanent credential-and-WordPress firehose.
Enterprise-appliance CVEs — the ones that dominate the headlines — are exploited in targeted
operations that broad scan telemetry never sees. Those are two different threat models, and the
under-resourced defender is being hit by the first one.
04Weaponization latency
Three timelines joined: CISA's KEV listing date, the first public proof-of-concept
our GitHub watch saw, and the first probe against our own sensor. The third column is what makes
it ours.
—
Median KEV → public PoC
—
Armed before CISA listed it
The window was already shut on listing day.
—
PoC exists, never probed us
Targeted-exploitation candidates.
CVE
Days before KEV listing
05What we will not claim
Discipline is the product. A CVE with no PoC record
reports UNKNOWN, never "slow to weaponize". A missing probe reports "not observed by our sensor",
never "not exploited". Redistributing a public list is distribution value, never detection.
Holding the /24 is block-coverage, not indicator-detection. These rules are compiled into the
detectors, not just written in a style guide.