2.9 Intelligence Area Module
The Intelligence Area provides access to threat intelligence feeds, event monitoring, and forensic analysis for cross-referencing attack data against known malicious indicators. Clicking Intelligence Area in the left sidebar expands a submenu with three options, as shown in Figure 2.9-1.

Figure 2.9-1 – Intelligence Area Submenu
Submenu Option | Description |
|---|---|
Events | System-wide event monitoring and analysis |
Threat Intelligence | Advanced IP address intelligence and security analysis |
Forensic Intelligence | Real-time attack forensic analysis and detailed session data |
2.9.1 Events
The Events page provides system-wide event monitoring with real-time counters and dual view modes, as shown in Figure 2.9.1-1.

Figure 2.9.1-1 – Events Page Overview
2.9.1.1 Event Counters
The top of the page displays the header "Events" with the subtitle "System-wide event monitoring and analysis" and three summary counters showing total system-wide statistics:
Counter | Description |
|---|---|
Connection | Total connection events (e.g., 4,902,910) |
Interaction | Total interaction events (e.g., 52,959) |
Credential | Total credential events (e.g., 387,251) |
2.9.1.2 View Mode Controls
The right side of the toolbar provides view mode toggles and a refresh button:
Control | Function |
|---|---|
Cards | Display events as individual cards in a grid layout |
Table | Display events in a tabular format |
Refresh | Reload the latest events |
2.9.1.3 Cards View
The Cards view displays events as individual cards in a scrollable grid, as shown in Figure 2.9.1.3-1.

Figure 2.9.1.3-1 – Events Cards View
A Search events field allows filtering events by name or other criteria. The display header shows the current page scope (e.g., "Showing 3000 of 3000 events").
Each event card contains the following information:
Field | Description |
|---|---|
Event Title | Event type and source (e.g., "postgresql-login - Unknown", "Port Scan - 213.2xx.xxx.xxx") |
Category | Event classification: Credential or Connection |
Flags | F (Flagged) and A (Alerted) indicators |
Source IP | Attacker IP address (e.g., |
Guardpot | The honeypot that captured the event (e.g., "Auto Detected") |
Timestamp | Relative time since the event occurred (e.g., "Just now", "2m ago") |
Description | Detailed event description (e.g., "postgresql-login from 213.2xx.xxx.xxx") |
Pagination controls at the bottom allow navigation through multiple pages of events (e.g., "Page 1 of 250").
2.9.1.4 Table View
The Table view displays events in a structured tabular format, as shown in Figure 2.9.1.4-1.

Figure 2.9.1.4-1 – Events Table View
A Search in table text bar allows filtering by IP address, agent name, description, or other criteria.
The table includes the following columns:
Column | Description |
|---|---|
Type | Event classification: Credential or Connection |
Title | Event identifier (e.g., "postgresql-login - Unknown", "Port Scan - 213.2xx.xxx.xxx") |
Source IP | Attacker IP address |
Guardpot | The honeypot that captured the event |
Description | Detailed event description |
F | Flagged indicator |
A | Alerted indicator |
Time | Relative timestamp (e.g., "2m ago") |
Actions | Available actions for the event |
2.9.1.5 Event Detail View
Clicking on an event card or table row opens a detailed analysis view for the specific IP address, as shown in Figure 2.9.1.5-1.

Figure 2.9.1.5-1 – Event Detail View
The detail view provides comprehensive threat analysis across multiple panels:
Security & Reliability Scores:
Score | Description |
|---|---|
Security | Threat security rating (e.g., "E" for Elevated risk) |
Reliability | Intelligence reliability score (e.g., "S" for Strong) |
Total Attacks | Total number of attacks from this IP (e.g., 1,531) |
Region | Geographic region (e.g., "Europe & Central Asia") |
IP Information — Geolocation Details:
Field | Description |
|---|---|
Country | Source country (e.g., Germany) |
City | Source city (e.g., Augsburg) |
Timezone | Local timezone with UTC offset |
First Seen | First observed timestamp (e.g., 16.01.2026 23:39:04) |
Last Seen | Most recent observed timestamp (e.g., 20.05.2026 07:40:20) |
Provider | ISP or hosting provider (e.g., FPS12) |
Location | Geographic coordinates (e.g., 48.35, 10.92) |
MITRE Attacks:
Displays MITRE ATT&CK framework mappings for observed attack techniques from this IP.
Attack Map:
Visual representation showing the attacker's geographic location and targeted destinations.
Protocol Activity — Network Interactions Analysis:
A breakdown of network interactions by protocol with hit counts and percentages (e.g., postgresql-login: 899 hits (58.7%), tcp-portscan: 632 hits (41.3%)).
Top Targeted Countries — Attack Destinations:
Displays the countries most targeted by this attacker with percentage distribution and total attack counts.
Weekly Attacks — Temporal Analysis:
A timeline chart showing attack frequency across weeks and months, with active dates plotted chronologically.
Network Topology — Agent Connections & Interactions:
A timeline visualization showing which Guardpot agents interacted with this IP and when, with date markers spanning the observation period.
2.9.2 Threat Intelligence
The Threat Intelligence page provides advanced IP address lookup with comprehensive security analysis, as shown in Figure 2.9.2-1.

Figure 2.9.2-1 – Threat Intelligence Page
2.9.2.1 Page Header
The page displays the following header and description:
Threat Intelligence Area Advanced IP Address Intelligence & Security Analysis Real-time threat intelligence from Guardpot sources
Four feature highlights are displayed:
Feature | Description |
|---|---|
Geolocation | Geographic origin identification |
Threat Score | Risk assessment scoring |
Attack History | Historical attack patterns |
MITRE ATT&CK | Attack technique mapping |
2.9.2.2 IP Address Lookup
An Enter IP address text bar allows you to query any IP address for threat intelligence. Type an IP (e.g., 1.1.1.1) and press Enter to perform the lookup.
2.9.2.3 Lookup Results
Upon querying an IP address, the following analysis panels are displayed:
Security & Reliability Scores:
Score | Description |
|---|---|
Security | Threat security rating (e.g., "S" for Safe) |
Reliability | Intelligence reliability score (e.g., "E") |
Total Attacks | Total attacks observed from this IP |
Region | Geographic region (e.g., "South Asia") |
IP Information — Geolocation Details:
Field | Description |
|---|---|
Country | Source country (e.g., India) |
City | Source city (e.g., Pune) |
Timezone | Local timezone with UTC offset |
First Seen | First observed timestamp (displays N/A if no data) |
Last Seen | Most recent observed timestamp (displays N/A if no data) |
Provider | ISP or hosting provider (e.g., CLOUDFLARENET) |
Location | Geographic coordinates (e.g., 18.54, 73.84) |
Analysis Panels (with empty states when no data exists):
Panel | Empty State Message |
|---|---|
World Analysis | "No geographic data — No map data available" |
Protocol Activity | "No protocol data — Waiting for network activity..." |
Top Targeted Countries | "No attack data — Waiting for threat intelligence..." |
Weekly Attacks | "No temporal data — Waiting for temporal analysis..." |
Network Topology | "No topology data — Waiting for network analysis..." |
Attack Timeline | "No events recorded — No attack events available" |
2.9.3 Forensic Intelligence
The Forensic Intelligence page provides detailed session-level forensic analysis of attacker interactions, as shown in Figure 2.9.3-1.

Figure 2.9.3-1 – Forensic Intelligence Page
2.9.3.1 Page Header
The page displays the following header and description:
Latest Forensic Intelligences Real-time attack forensic analysis and detailed session data
The session counter displays total sessions (e.g., "Page 1 of 594 • 11873 sessions").
2.9.3.2 Search and Filter
The right side of the toolbar provides search and filtering capabilities:
Control | Function |
|---|---|
Search sessions | Text search across session data |
Filter Sessions | Filter by Guardpot name or Attacker IP address |
2.9.3.3 Session Table Columns
Each session row displays the following information:
Column | Description |
|---|---|
Session | Guardpot name, attacker IP, OS, location, and public IP |
Location | Geographic region of the attacker |
Time | Session start and end timestamps with duration (e.g., "02.04.2026 18:09:32 → 02.04.2026 18:10:08 • 36s") |
Status | Session state (e.g., "Ended") |
Action | Available actions for the session |
2.9.3.4 Session Detail Example
Field | Example Value |
|---|---|
Guardpot | Auto Detected |
Attacker IP | 77.9x.xxx.xxx |
OS | Linux (x64) |
Location | Bursa, Turkey |
Public IP | 188.1xx.xxx.xxx |
Region | Asia |
Start Time | 02.04.2026 18:09:32 |
End Time | 02.04.2026 18:10:08 |
Duration | 36s |
Status | Ended |
