Dshield
Podcast
DShield is a community-based collaborative firewall log correlation system.[2] It receives logs from volunteers worldwide and uses them to analyze attack trends. It is used as the data collection engine behind the SANS Internet Storm Center (ISC). DShield was officially launched end of November 2000 by Johannes Ullrich. Since then, it has grown to be a dominating attack correlation engine with worldwide coverage.
DShield is regularly used by the media to cover current events. Analysis provided by DShield has been used in the early detection of several worms, like "Ramen", Code Red, "Leaves", "SQL Snake" and more. DShield data is regularly used by researchers to analyze attack patterns.
The goal of the DShield project is to allow access to its correlated information to the public at no charge to raise awareness and provide accurate and current snapshots of internet attacks. Several data feeds are provided to users to either include in their own web sites or to use as an aide to analyze events. Source
Actions
Media Outlet details
| Scope | Local |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesScans for Proxmox Servers
Click HERE to learn more about classes Johannes is teaching for SANS Published: 2026-09-09. Last Updated: 2026-09-09 17:46:24 UTC by Johannes Ullrich (Version: 1) About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The vulnerability only affects version 7, which has not been supported for a couple of years now.
Redtail Payload Analysis [Guest Diary]
[This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program] Following a RedTail Linux Payload from DShield to Dynamic Analysis During monitoring of my DShield honeypot, I observed an attacker uploading a collection of Linux executables targeting several processor architectures. The files included ARM, ARM64, i686, RISC-V and x86-64 variants named as part of a RedTail deployment package.
September 2026 Microsoft Patch Tuesday
Click HERE to learn more about classes Renato is teaching for SANS Published: 2026-09-08. Last Updated: 2026-09-08 19:20:30 UTC by Johannes Ullrich (Version: 1) This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday.
Honeypot-Omaha and batch.py [Guest Diary]
Click HERE to learn more about classes Guy is teaching for SANS [This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program] Honeypot-Omaha is a DShied Sensor located at the Internet Storm Center (ISC) that is set up as a decoy for the original target and deployed over the internet. It is a flawed and very vulnerable system that was intentionally designed to attract threat actors with malicious intents.
Guildma (Astaroth) malware infection from Brazilian Portuguese email
Click HERE to learn more about classes Brad is teaching for SANS Published: 2026-09-01. Last Updated: 2026-09-01 00:33:21 UTC by Brad Duncan (Version: 1) Introduction On Monday 2026-08-31, I used a link from a malicious Brazilian Portuguese email to infect a Windows host in my lab. This was a Guildma (Astaroth) malware infection. The link from the email is geofenced for Brazil, meaning that it would only deliver the malware if I checked it from a Brazil-based IP address.
The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary
Click HERE to learn more about classes Renato is teaching for SANS Published: 2026-08-31. Last Updated: 2026-08-31 20:00:34 UTC by Renato Marinho (Version: 1) One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session — history, filesystem output, working paths, and the agent's local tool manifest.
Internet Storm Center
Click HERE to learn more about classes Didier is teaching for SANS Published: 2026-08-30. Last Updated: 2026-08-30 07:14:49 UTC by Didier Stevens (Version: 1) YARA-X's 1.20.0 release brings 14 improvements and 13 bugfixes. One new CLI option is --ignore-invalid-rules that allows one to skip rules that fail to compile. There have also been new releases of YARA: YARA 4.5.6, YARA 4.5.7 and YARA 4.5.8 with 32 bugfixes in total.
Some Malicious PE Stats
Click HERE to learn more about classes Xavier is teaching for SANS Published: 2026-08-27. Last Updated: 2026-08-28 07:04:13 UTC by Xavier Mertens (Version: 1) During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of months ago, I shared some stats about the trend in 64bits VS. 32bits malware[1]. Can we go a bit further?
A polymorphic phishing page (that occasionally breaks itself)
As I’ve mentioned before in some of my diaries, from time to time, I like to go over phishing messages that get caught in my various spam traps or sent to us here at the Internet Storm Center. After looking at enough phishing messages, one quickly gets used to seeing the same lures, the same credential-harvesting pages and, quite often, the same obfuscation techniques over and over again.
Who Has Admin Rights in your Entra ID Directory?
A common thing that folks should "worry" about in Entra (or any platform really) is "who has rights to administer"? Who can delete or change key things, or modify them in ways that might not be obvious (accidentally or on purpose). Yes, we trust our people, but if they've moved on to other roles or to other organizations, they change from "our people" to "used to be our people". Also, it's common to have too many admins.