Fleet Security & Threat Audit Dashboard
2026-09-11 – 2026-09-17 (7 Days, PDT)
Failed SSH Logins (7d)
17,834
HTTP Exploit Probes
12,362
Active CrowdSec Bans
35
CrowdSec Alerts
7,018
System Health & Stale Daemons
8 Stale Services
Daily Attack Timelines & Fleet Dynamics

Daily Attack Timeline (Fleet Aggregated)

Daily Attacks by Server Host

Geographic & Threat Pattern Intelligence

Top Attacking Countries

Top Attacking Data Centers & ASNs

Attack Pattern & Threat Vectors

Infrastructure Fleet Posture & Health Status
Host Status CrowdSec SSH Attacks (7d) Web Probes (7d) Stale Daemons Reboot
c1.mwan.dev Online 6 Bans (854 alerts) 2,223 3,270 Clean No
c2.mwan.dev Online 16 Bans (407 alerts) 1,805 2,371 1 services No
c3.mwan.dev Online 6 Bans (2542 alerts) 6,060 1,439 Clean No
home.mwan.dev Online 7 Bans (3215 alerts) 7,746 5,282 7 services No
Targeted Accounts & Credential Spraying Analysis

Breakdown of targeted usernames across SSH authentication attempts grouped by account status. Highlights attempts matching existing local system accounts.

Threat Actors & Sub-Threshold Repeat Scanners

Unbanned and sub-threshold scanning IPs observed across the infrastructure nodes during the audit window.

Alerted Attackers (No Ban)
1,466
Triggered alerts below ban threshold
Undetected Scanners
1,172
Scanned below alert rate limits
Unbanned Scanning IPs
2,403
No active firewall drop enforced
Observed Threat Actors (0 total) Scroll to view all actors
Attacking IP Target Host Observed Hits Country / ASN CrowdSec Status