Fleet Security & Threat Audit Dashboard
2026-09-20 – 2026-09-26 (7 Days, PDT)
Failed SSH Logins (7d)
17,485
HTTP Exploit Probes
22,525
Active CrowdSec Bans
42
CrowdSec Alerts
4,138
System Health & Stale Daemons
Reboot Required
Daily Attack Timelines & Fleet Dynamics
Daily Attack Timeline (Fleet Aggregated)
Daily Attacks by Server Host
Geographic & Threat Pattern Intelligence
Top Attacking Countries
Top Attacking Data Centers & ASNs
Attack Pattern & Threat Vectors
Infrastructure Fleet Posture & Health Status
| Host | Status | CrowdSec | SSH Attacks (7d) | Web Probes (7d) | Stale Daemons | Reboot |
|---|---|---|---|---|---|---|
c1.mwan.dev |
Online | 10 Bans (763 alerts) | 3,527 | 1,627 | 6 services | REBOOT |
c2.mwan.dev |
Online | 11 Bans (448 alerts) | 3,472 | 3,369 | 6 services | REBOOT |
c3.mwan.dev |
Online | 6 Bans (342 alerts) | 3,696 | 1,631 | 6 services | REBOOT |
home.mwan.dev |
Online | 15 Bans (2585 alerts) | 6,790 | 15,898 | 7 services | No |
Targeted Accounts & Credential Spraying Analysis
Breakdown of targeted usernames across SSH authentication attempts grouped by account status. Highlights attempts matching existing local system accounts.
Threat Actors & Sub-Threshold Repeat Scanners
Unbanned and sub-threshold scanning IPs observed across the infrastructure nodes during the audit window.
Alerted Attackers (No Ban)
887
Triggered alerts below ban threshold
Undetected Scanners
1,525
Scanned below alert rate limits
Unbanned Scanning IPs
2,157
No active firewall drop enforced
Observed Threat Actors (0 total)
Scroll to view all actors
| Attacking IP | Target Host | Observed Hits | Country / ASN | CrowdSec Status |
|---|