DNS Daddy Threat Observatory — live DNS threat map: see DNS-related threats emerge, connect and evolve

DNS DADDY
Threat Observatory
awaiting ingest
0 / 0 24H

loading threat intelligence…

resolving geospatial layer…
latest intelligencefull feed
  • awaiting upstream telemetry…
DNS Daddy · Threat Observatory — see DNS-related threats emerge, connect and evolveabout

A live, evidence-backed companion to DNS Daddy, built to explore malicious DNS infrastructure, threat intelligence and defensive context.

Every dot has a source. Every connection has evidence. Every change has a timestamp.

DNS Daddy explores how DNS can be protected. Visit the main project → The Threat Observatory explores the threats that make that protection necessary.

latest intelligence received
awaiting first ingest
latest source observation
awaiting first ingest
latest successful ingest
awaiting first ingest
Live indicators
····
Critical severity
····
C2 endpoints
····
Hosting territories
····

Top territories

Ranked by live indicator count

  1. awaiting attribution data

Observation timeline

Last seven days · total observations against critical-severity share

Severity distribution

CRIT0
HIGH0
MED0
LOW0

Dominant families

  • no family attribution

Infrastructure relationships

Stored links between entities · click an edge to read the exact supporting evidence

no stored relationships yet — nothing is inferred to fill the gap

How to read this

Every dot has a source; every connection has evidence

observedA named provider stated this directly about this entity.correlatedDerived by matching statements from two or more providers.inferredDerived by DNS Daddy from resolution and registry data, not stated by a provider.communitySubmitted by a community reporter and carries a report status.

Map points describe where infrastructure is hosted, not who is behind it. Where a source publishes no location, DNS Daddy resolves the host and geolocates the address, and the point is marked inferred. Where neither is possible, nothing is plotted.

Freshest observations

Most recently confirmed malicious infrastructure

full feed
no indicators matched — nothing is substituted

0 stored observations · 0 located · 0 seen in the last 24h · 0 evidenced relationships · 0 community reports · top territory Unattributed

DNS Daddy

Open DNS security research, tools and experimentation. DNS Daddy explores how DNS can be protected; the Threat Observatory explores the threats that make that protection necessary.

DNS Daddy Threat Observatory is a student-built open-source cybersecurity project exploring threat intelligence, DNS infrastructure and explainable security analysis.

Support DNS Daddy Threat Observatory

DNS Daddy Threat Observatory is a student-built open-source cybersecurity project exploring threat intelligence, DNS infrastructure and explainable security analysis. Help cover API usage, hosting and ongoing development. Entirely optional — nothing here is paywalled.

Support DNS Daddy

Ecosystem

Observatory

Open source

DNS Daddy Threat Observatory — an experimental, open research project. Intelligence is sourced from third-party feeds under their own licences and is advisory only. Every dot has a source; every connection has evidence; every change has a timestamp.