Loudest Knock biggest single-IP burst · knock-analyzer, ~6h cadence
Traffic Trend last 30 days
requests by hour of day
0006121823
Live Traffic server.py · classify_ip()
Spoofed Crawler Claims claimed UA vs. reverse+forward DNS · knock-analyzer, ~6h cadence
Caught Twice claims to be a crawler AND matches a named attack signature · knock-analyzer
Attack Signatures Detected named exploit/scanner patterns · all-time · knock-analyzer
Top Scanned Paths last 24h · excludes normal page visits
Top Requested Paths last 24h · all traffic, including normal page visits
Scan Category keyword-bucketed by request path
Real vs. Datacenter org/ASN lookup via ipinfo.io, cached per /24
Top Countries by request count
Top Networks ASN/hosting org · knock-analyzer, as of last analysis run
Every request this server handles gets classified as [REAL] (residential/ISP IP) or [BOT?]
(datacenter/hosting IP) and bucketed into a rough scan category by request path — this is the same internet
background-noise traffic every public IP on earth gets, all day, forever: automated bots probing for WordPress
installs, leaked .env/.git secrets, and known router exploits. None of it is
targeted at this site specifically. This panel is a live view of that traffic, not a defensive tool.