DNS Daddy Threat Observatory
Public threat intelligence, provenance and infrastructure context.
Explore the indicators and sources behind DNS Daddy's protective DNS intelligence.
loading threat intelligence…
- awaiting upstream telemetry…
Every dot has a source. Every connection has evidence. Every change has a timestamp. About the data →
Top territories
Ranked by live indicator count
- awaiting attribution data
Observation timeline
Last seven days · total observations against critical-severity share
Severity distribution
Dominant families
- no family attribution
Infrastructure relationships
Stored links between entities · click an edge to read the exact supporting evidence
How to read this
Every dot has a source; every connection has evidence
Map points describe where infrastructure is hosted, not who is behind it. Where a source publishes no location, DNS Daddy resolves the host and geolocates the address, and the point is marked inferred. Where neither is possible, nothing is plotted.
Freshest observations
Most recently confirmed malicious infrastructure
0 stored observations · 0 located · 0 seen in the last 24h · 0 evidenced relationships · 0 community reports · top territory Unattributed