Live data · free to read

What the sensor network is seeing right now.

Aggregate statistics from the sensors behind the SciScope Scanner Feed — published in full, with no key and no signup. This page is regenerated from the same bundle the API serves, so what you see here is what subscribers are getting.

Data generated · refreshed hourly

199,239
IP addresses scored in the current window
18,782
on the feed right now
9,743
of the feed flagged by our sensors alone, with no outside corroboration — 52% (7-day average)
8,014
on the high-confidence blocklist
208
legitimate crawler IPs kept off it
01 / right now

Ten addresses on the feed as of this build

Ten entries from the live feed — the same records a subscriber's firewall is pulling right now. The full feed carries 18,782 of them, each with the evidence behind the verdict.

addressscoreccnetworktagslast seen
205.210.31.31100USGOOGLE-CLOUD-PLATFORM - Google LLCAS396982host:GCP2026-09-02
43.228.157.8100DEGHOSTYNETWORKS - Ghosty Networks LLCAS205759asn_drop corroborated2026-09-02
75.127.6.2100USAS-COLOCROSSING - HostPapaAS36352host:HostPapa2026-09-02
77.90.185.20100DELimitedNetwork-AS - Limited Network LTDAS213790asn_drop corroborated2026-09-01
79.124.62.230100SCDM_AUTO - DM AUTO EOODAS207812asn_drop corroborated2026-09-02
92.118.39.71100NLUNMANAGED-DEDICATED-SERVERS - UNMANAGED LTDAS47890asn_drop corroborated2026-09-02
137.184.226.25097USDIGITALOCEAN-ASN - DigitalOcean, LLCAS14061host:DigitalOcean2026-09-02
192.161.49.295USHOSTP-LA - HostPapaAS23273host:HostPapa2026-09-02
64.62.156.17295USHURRICANE - Hurricane Electric LLCAS6939host:Hurricane Electric2026-09-02
40.80.200.21693USMICROSOFT-CORP-MSN-AS-BLOCK - Microsoft CorporationAS8075host:Azure2026-09-02
2026-08-04 · 45%range 42–57%2026-09-02 · 57%

corroborated means an independent public list agrees with us. The rows without it are the point: 52% of the feed carries no outside corroboration at all (7-day average) — our sensors saw it and nobody else's list has it yet.

02 / activity

Events per sensor, per day

What the sensors recorded each day — firewall drops, SSH attempts and web probes.

2026-08-03: 59,347 per sensor2026-08-04: 61,001 per sensor2026-08-05: 69,755 per sensor2026-08-06: 68,623 per sensor2026-08-07: 66,310 per sensor2026-08-08: 61,188 per sensor2026-08-09: 80,511 per sensor2026-08-10: 57,823 per sensor2026-08-11: 58,987 per sensor2026-08-12: 57,043 per sensor2026-08-13: 58,086 per sensor2026-08-14: 63,507 per sensor2026-08-15: 65,223 per sensor2026-08-16: 92,154 per sensor2026-08-17: 70,089 per sensor2026-08-18: 61,381 per sensor2026-08-19: 51,203 per sensor2026-08-20: 53,346 per sensor2026-08-21: 52,384 per sensor2026-08-22: 60,276 per sensor2026-08-23: 86,925 per sensor2026-08-24: 65,806 per sensor2026-08-25: 57,287 per sensor2026-08-26: 62,578 per sensor2026-08-27: 62,974 per sensor2026-08-28: 78,919 per sensor2026-08-29: 66,326 per sensor2026-08-30: 79,168 per sensor2026-08-31: 58,160 per sensor2026-09-01: 57,945 per sensor
92,15446,0770
events per sensor, per day
2026-08-03peak 92,154 per sensor on 2026-08-162026-09-01 · complete days only
03 / targets

Most-targeted destination ports, last 7 days

Which ports the internet is knocking on, as a share of all events.

port 23 Telnet
7.9%
port 22 SSH
5.85%
port 24024
0.47%
port 5522
0.46%
port 8080 HTTP alt
0.24%
port 26378
0.21%
port 443 HTTPS
0.2%
port 3389 RDP
0.19%
port 8443 HTTPS alt
0.19%
port 546
0.18%
04 / behaviour

What that traffic was, last 7 days

What kind of contact those events were.

fw_block firewall drops on closed ports
90.54%
ssh_preauth SSH sessions abandoned before authentication
4.25%
web_request HTTP requests to unadvertised endpoints
2.79%
ssh_invalid_user SSH logins for users that do not exist
1.51%
web_probe HTTP probes for known-vulnerable paths
0.88%
ssh_fail failed SSH password attempts
0.03%
05 / origins

Where the flagged addresses are registered

Where the flagged addresses are registered — the traffic's origin, not our sensors'. Mostly rented infrastructure, so this reflects where hosting is cheap rather than anything about the countries themselves.

US United States
7,958
CN China
1,628
GB United Kingdom
1,483
DE Germany
1,176
NL Netherlands
807
SG Singapore
615
JP Japan
554
BR Brazil
448
MY Malaysia
409
HK Hong Kong
394
06 / coverage

Where the sensors are

Where we observe from. Regions without a sensor are marked, and the gap is real: an operation that only scans one part of the world may not reach us yet.

Europe
North America
Africa
·South America not yet
·Asia not yet
·Oceania not yet
07 / the api

The same data, as an API

Everything above comes from the API. Here is a real call and exactly what comes back.

Free Aggregate statistics

# any key, including a Free one
curl -s -H "Authorization: Bearer $SCISCOPE_KEY" \
     https://api.sciscope.ee/v1/stats

# ->
{
  "generated_utc": "2026-09-02T20:29:19Z",
  "totals": {
    "scored_ips": 199239,
    "on_feed": 18782,
    "on_blocklist": 8014,
    "identified_crawlers": 208
  },
  "events_per_day_30d": [ /* 30 days */ ],
  "top_dst_ports_7d":  [ /* 15 rows */ ],
  "event_types_7d":    [ /* by volume */ ],
  "top_feed_countries": [ /* 15 rows */ ]
}

One address, with its evidence

# 198.51.100.24 is a documentation address (RFC 5737), used here as an example
curl -s -H "Authorization: Bearer $SCISCOPE_KEY" \
     https://api.sciscope.ee/v1/ip/198.51.100.24

# ->
{
  "ip": "198.51.100.24",
  "found": true,
  "score": 87.4,
  "raw_score": 91.0,
  "sensor_continents": [ "Africa", "Europe" ],
  "signal_events_30d": 1284,
  "first_seen": "2026-07-09",
  "last_seen": "2026-07-28",
  "last_signal": "2026-07-28",
  "geo": { "country": "US", "asn": 64496, "as_org": "Example Hosting" },
  "tags": [ "scanner", "ssh", "multi-sensor" ],
  "evidence": { /* per-continent: first and last seen, by day */ },
  "updated_utc": "2026-09-02T20:29:19Z"
}

Every flagged address ships with the evidence behind it. If you disagree with a verdict you can see precisely what produced it — which is the whole difference between a feed you can operate and a list you have to trust.

Get a key

Read the numbers. Then try it on your own traffic.

A 14-day trial gives you the full Pro feature set — feed, history, per-IP lookups — with no card and no form. When it ends your key drops to Free rather than dying, so the statistics endpoint above keeps working indefinitely.