We ranked fifteen cloud and hosting providers by the share of their announced IPv4 space that probed our honeypots over thirty days. DigitalOcean's rate is 242 times that of Amazon Web Services (AWS). Per 100,000 announced addresses: UCloud 486, DigitalOcean 224, Akamai Technologies 28, Contabo 28, Google Cloud 22, Alibaba Cloud 21, Scaleway 11, Tencent Cloud 8.1, Microsoft Azure 5.0, Oracle Cloud 3.3, OVHcloud 3.2, Vultr 2.3, Huawei Cloud 1.8, AWS 0.9, Hetzner 0.9. Google Cloud alone sent 64 percent of the probes, most of them full port sweeps, with the Vite dev-server port and a cloud-metadata SSRF path in the mix. 82 percent of DigitalOcean's probing addresses were gone within a day; 72 percent of UCloud's stayed for a week or more. The full table, what each provider's probes go after, and how long their addresses stay visible, in the article. The live board for every network on the internet, including yours: honeylabs.net/asn-index
HoneyLabs
Computer and Network Security
Honeypot telemetry built for engineers. Try it at https://honeylabs.net
About us
HoneyLabs runs its own internet-facing honeypot sensors and publishes what they capture: the request, the payload, the TLS and HTTP fingerprints, the CVE it was probing for, and who else is doing the same. Every indicator links to its evidence. Lookups and IOC feeds are free. A free account watches your own prefixes and networks, alerts you when they show up on a sensor, and turns any query into a feed your firewall, MISP or SIEM can poll. Integrations: Splunk, Microsoft Sentinel, MISP, OpenCTI, TAXII 2.1, REST, and MCP for AI agents. Open-source sensors (Spip, Loom) and an open HTTP request fingerprint (Akin). Based in the Netherlands, servers in the EU.
- Website
-
https://honeylabs.net
External link for HoneyLabs
- Industry
- Computer and Network Security
- Company size
- 2-10 employees
- Headquarters
- Amsterdam
- Type
- Privately Held
- Founded
- 2026
- Specialties
- Threat Intelligence (CTI), Honeypots, and Cybersecurity
Locations
-
Primary
Get directions
Amsterdam, NL
Employees at HoneyLabs
Updates
-
What HoneyLabs is, four months after launch. We run our own internet-facing honeypot sensors and publish what they capture. For every received probe you get the request, the payload, the TLS and HTTP fingerprints, the CVE it was probing for, and peers. New this month: Akin, an open HTTP request fingerprint. Two tokens differ by exactly as many bits as the headers the two clients differ by, so one scanner with three request shapes shows up as one family instead of three strangers. Spec and code are Apache-2.0: https://lnkd.in/ehNmVfev Also new: the Splunk app 1.2.0 matches scanner fingerprints against your own perimeter from a local lookup, adds the CVEs an address probed to every enrichment, and ships three alerts. Microsoft Sentinel, MISP, OpenCTI and TAXII 2.1 are unchanged and keep working. Lookups and IOC feeds are free. A free account watches your own prefixes and networks and tells you when they show up on a sensor. https://honeylabs.net
-
Someone is running an SSH reconnaissance tool from other people's mail servers. On 3 and 4 September, 583 hosts connected once to our sensors. When we checked what those hosts are, nine in ten run a mail service, three quarters run Postfix, and two thirds of the ones we could date are on CentOS 7 or older, with no security updates for years. https://lnkd.in/ePxTGffu #threatintel #honeypots #CTI
-
-
Keeping track of the noisiest networks on the internet. Now our Autonomous Systems Emissions Index is armed with charts! 😎 https://lnkd.in/gxS-EBFQ
-
-
Anthropic publishes one user-agent for its Claude-User crawler. Between 2 August and 6 September our sensors logged 6,648 different versions of it, all carrying a single HTTP client fingerprint from 26 addresses. Those same 26 addresses run three more modules, aiming at the Amazon Web Services (AWS) instance metadata service and at GraphQL endpoints.
-
-
"Who is abusing CVE-2017-9841?" is now something you can ask our MCP server. 57,244 probes, 775 IPs, last 90 days. Top sources Alibaba, Contabo, UCloud. A 2017 PHPUnit RCE on CISA KEV, still being mass-scanned. New: cve_lookup, top_attackers by=cve, and ioc_lookup now returns a verdict plus benign-scanner flagging. https://honeylabs.net/mcp
-
On April 11, one of our honeypots logged 16 requests for the cPanel WHM login path on port 2087, from a single address that has never asked us for anything else, before or since. Seventeen days later cPanel published the advisory for CVE-2026-41940, a 9.8 authentication bypass in exactly that login flow. Censys and Rapid7 had write-ups within days, and by then hundreds of IPs were hitting the path. This one was weeks early. We wanted to know how often that really happens without fooling ourselves, so we ran it against 30M+ honeypot probes. The hard part is deciding what counts as "before": NVD publication lags real disclosure, so we anchor each verdict on the earlier of the NVD entry and the first public exploit template, mined from the commit history of ProjectDiscovery's nuclei-templates. Add a coverage-edge guard and a mass-scanner filter, and 1,697 tracked CVE signatures collapse to three actors we are confident about. The full method, the formulas, and the live table are in the write-up: https://lnkd.in/eA-2yCkf Indicators are obfuscated per draft-grimminck-safe-ioc-sharing, the IOC-sharing spec I authored. #ThreatIntelligence #ThreatHunting #VulnerabilityManagement #Honeypots #CyberSecurity
-
-
Between 16 February and 18 July 2026, our internet-facing sensors received valid Modbus, DNP3, S7comm, or IEC-104 requests from 2,661 unique hosts. Modbus and DNP3 scanners generally attempted to identify the device they reached, while most S7comm and IEC-104 traffic stopped after the initial connection. This post examines the requests and the scanner behaviour behind them. The whole analysis can be found at https://lnkd.in/ewrrBeyK
-
-
📊 Which company sends us the most probes? Here the top this week: ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Expanse, acquired by Palo Alto Networks • Events: 77,110 • Unique IPs: 1,943 • ASNs Active: 1 • Primary Agent: Cortex-Xpanse ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Censys • Events: 72,602 • Unique IPs: 383 • ASNs Active: 4 • Primary Agent: CensysInspect ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ VisionHeight • Events: 15,068 • Unique IPs: 20 • ASNs Active: 1 • Primary Agent: visionheight.com/scan ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Modat • Events: 12,600 • Unique IPs: 128 • ASNs Active: 2 • Primary Agent: ModatScanner ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Nokia • Events: 6,782 • Unique IPs: 224 • ASNs Active: 1 • Primary Agent: GenomeCrawlerd ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━