01 Public threat research / OCI Mumbai

The internet knocks.
Greyfield listens.

An internet-facing SSH and Telnet deception system preserving evidence of discovery, credential pressure, command execution, and payload retrieval against an exposed Linux decoy.

Snapshot Observed Sensor
Source constellation · auto-rotates · drag or touch to rotate · Awaiting telemetry
Drag, touch, or select a signal Public source details appear here
Sessionsconnections accepted
Source IPsglobally routable infrastructure
Login attemptscredentials observed
Commandspost-access activity
Artifactsretrieval events
ATT&CKtechniques evidenced

02 Temporal signal

Attack pulse

Five-minute event-time detail across the latest 24 hours, with an hourly seven-day view for longer context. The snapshot itself refreshes hourly.

SessionsAuthCommands

03 Network evidence

Where the traffic came from

Public source addresses are shown as observed. Location and network ownership are approximate enrichment, not identity attribution.

— sources · View all ↗
SourceNetwork contextFirst / last seenSessionsAuthCommandsArtifacts

04 Intrusion evidence

Observed intrusion behavior

Greyfield reconstructs credential pressure and post-access activity from commands issued inside the decoy. Records are sanitized for publication, rendered as inert evidence, and mapped to ATT&CK only where the telemetry supports the technique.

Observed command evidenceView all ↗
countobserved commandclassificationATT&CK

MITRE ATT&CK Enterprise

Evidence-mapped techniques

Download Navigator layer

05 Payload transfer

Payload retrieval evidence

This record identifies transfer infrastructure requested through the decoy, with query material removed and SHA-256 retained for correlation. Retrieval is evidence of transfer activity—not proof of execution, family attribution, or operator identity.

Observed URLSHA-256ATT&CKProvider correlationCountLast observed

06 Evidence boundary

Real observations.
Clear limits.

Telemetry is loading.

Greyfield records what reached a controlled deception service; it does not identify the person behind an address. Source geography, network ownership, ATT&CK mappings, and third-party family labels remain qualified analytical context rather than attribution.

Published events
Public sources observed
Accepted logins
Commands observed
Artifacts observed
Sensitive patterns redacted
Operator events removed
Non-public addresses removed
Countries observed
Networks observed
Provider-detected artifacts
Artifact publication coverage