Real-time attack data from the ScannerSend honeypot network. Community-fed, machine-readable.
Pass your API key via header or query parameter:
curl -H "X-API-Key: ss_comm_your_key_here" \ https://scannersend.org/api/v1/threat/attacks
| Tier | Requests/Hour | Header |
|---|---|---|
| Public | 60 | X-RateLimit-Remaining |
| Community | 300 | |
| Professional | 3,000 |
Aggregate threat intelligence stats. No authentication required.
Recent attacks. Community: masked IPs. Professional: full IPs + headers.
Crypto wallet addresses from killed mining processes.
Banned IPs with threat scores. Community: masked. Pro: full IPs.
Server-Sent Events real-time feed. Full unmasked attack data live.
Submit attack data from a deployed ScannerSend honeypot node.
Join the network. Free. Any Linux VPS. 5 minutes.
curl -sS https://scannersend.org/node-setup.sh | sudo bash
Each node deploys CryptoAnnihilator + web/SSH honeypots + auto-reporter. "Every siege teaches every keep."
All data collected from attackers connecting to ScannerSend honeypot infrastructure. Professional tier for defensive use only. Redistribution requires written permission.