DNS Daddy Threat Observatory

Public threat intelligence, provenance and infrastructure context.

Explore the indicators and sources behind DNS Daddy's protective DNS intelligence.

Indicators
····
Observations currently indexed across all publishable sources.
Providers
····
Actively collecting sources over datasets represented.
Last ingest
····
Time since the last successful upstream collection.
Feed status
····
No successful ingest has been reported for this deployment.
DNS DADDY
Threat Observatory
awaiting ingest
0 / 0 24H

loading threat intelligence…

resolving geospatial layer…
latest intelligencefull feed
  • awaiting upstream telemetry…

Every dot has a source. Every connection has evidence. Every change has a timestamp. About the data →

latest intelligence received
awaiting first ingest
—
latest source observation
awaiting first ingest
—
latest successful ingest
awaiting first ingest
—
Live indicators
····
Critical severity
····
C2 endpoints
····
Hosting territories
····

Top territories

Ranked by live indicator count

  1. awaiting attribution data

Observation timeline

Last seven days · total observations against critical-severity share

Severity distribution

CRIT0
HIGH0
MED0
LOW0

Dominant families

  • no family attribution

Infrastructure relationships

Stored links between entities · click an edge to read the exact supporting evidence

no stored relationships yet — nothing is inferred to fill the gap

How to read this

Every dot has a source; every connection has evidence

observedA named provider stated this directly about this entity.correlatedDerived by matching statements from two or more providers.inferredDerived by DNS Daddy from resolution and registry data, not stated by a provider.communitySubmitted by a community reporter and carries a report status.

Map points describe where infrastructure is hosted, not who is behind it. Where a source publishes no location, DNS Daddy resolves the host and geolocates the address, and the point is marked inferred. Where neither is possible, nothing is plotted.

Freshest observations

Most recently confirmed malicious infrastructure

full feed
no indicators matched — nothing is substituted

0 stored observations · 0 located · 0 seen in the last 24h · 0 evidenced relationships · 0 community reports · top territory Unattributed

Corpus 0 indicators