01 Public threat research / OCI Mumbai
The internet knocks.
Greyfield listens.
An internet-facing SSH and Telnet deception system preserving evidence of discovery, credential pressure, command execution, and payload retrieval against an exposed Linux decoy.
02 Temporal signal
Attack pulse
Five-minute event-time detail across the latest 24 hours, with an hourly seven-day view for longer context. The snapshot itself refreshes hourly.
03 Network evidence
Where the traffic came from
Public source addresses are shown as observed. Location and network ownership are approximate enrichment, not identity attribution.
| Source | Network context | First / last seen | Sessions | Auth | Commands | Artifacts |
|---|
04 Intrusion evidence
Observed intrusion behavior
Greyfield reconstructs credential pressure and post-access activity from commands issued inside the decoy. Records are sanitized for publication, rendered as inert evidence, and mapped to ATT&CK only where the telemetry supports the technique.
MITRE ATT&CK Enterprise
Evidence-mapped techniques
05 Payload transfer
Payload retrieval evidence
This record identifies transfer infrastructure requested through the decoy, with query material removed and SHA-256 retained for correlation. Retrieval is evidence of transfer activity—not proof of execution, family attribution, or operator identity.
| Observed URL | SHA-256 | ATT&CK | Provider correlation | Count | Last observed |
|---|
06 Evidence boundary
Real observations.
Clear limits.
Telemetry is loading.
Greyfield records what reached a controlled deception service; it does not identify the person behind an address. Source geography, network ownership, ATT&CK mappings, and third-party family labels remain qualified analytical context rather than attribution.
- Published events
- —
- Public sources observed
- —
- Accepted logins
- —
- Commands observed
- —
- Artifacts observed
- —
- Sensitive patterns redacted
- —
- Operator events removed
- —
- Non-public addresses removed
- —
- Countries observed
- —
- Networks observed
- —
- Provider-detected artifacts
- —
- Artifact publication coverage
- —