📄2. Guardpot Platform Administration

2.9 Intelligence Area Module

6 min read85 viewsUpdated May 20, 2026

The Intelligence Area provides access to threat intelligence feeds, event monitoring, and forensic analysis for cross-referencing attack data against known malicious indicators. Clicking Intelligence Area in the left sidebar expands a submenu with three options, as shown in Figure 2.9-1.

Figure 2.9-1 – Intelligence Area Submenu

Submenu Option

Description

Events

System-wide event monitoring and analysis

Threat Intelligence

Advanced IP address intelligence and security analysis

Forensic Intelligence

Real-time attack forensic analysis and detailed session data


2.9.1 Events

The Events page provides system-wide event monitoring with real-time counters and dual view modes, as shown in Figure 2.9.1-1.

Figure 2.9.1-1 – Events Page Overview

2.9.1.1 Event Counters

The top of the page displays the header "Events" with the subtitle "System-wide event monitoring and analysis" and three summary counters showing total system-wide statistics:

Counter

Description

Connection

Total connection events (e.g., 4,902,910)

Interaction

Total interaction events (e.g., 52,959)

Credential

Total credential events (e.g., 387,251)

2.9.1.2 View Mode Controls

The right side of the toolbar provides view mode toggles and a refresh button:

Control

Function

Cards

Display events as individual cards in a grid layout

Table

Display events in a tabular format

Refresh

Reload the latest events


2.9.1.3 Cards View

The Cards view displays events as individual cards in a scrollable grid, as shown in Figure 2.9.1.3-1.

Figure 2.9.1.3-1 – Events Cards View

A Search events field allows filtering events by name or other criteria. The display header shows the current page scope (e.g., "Showing 3000 of 3000 events").

Each event card contains the following information:

Field

Description

Event Title

Event type and source (e.g., "postgresql-login - Unknown", "Port Scan - 213.2xx.xxx.xxx")

Category

Event classification: Credential or Connection

Flags

F (Flagged) and A (Alerted) indicators

Source IP

Attacker IP address (e.g., 213.2xx.xxx.xxx)

Guardpot

The honeypot that captured the event (e.g., "Auto Detected")

Timestamp

Relative time since the event occurred (e.g., "Just now", "2m ago")

Description

Detailed event description (e.g., "postgresql-login from 213.2xx.xxx.xxx")

Pagination controls at the bottom allow navigation through multiple pages of events (e.g., "Page 1 of 250").


2.9.1.4 Table View

The Table view displays events in a structured tabular format, as shown in Figure 2.9.1.4-1.

Figure 2.9.1.4-1 – Events Table View

A Search in table text bar allows filtering by IP address, agent name, description, or other criteria.

The table includes the following columns:

Column

Description

Type

Event classification: Credential or Connection

Title

Event identifier (e.g., "postgresql-login - Unknown", "Port Scan - 213.2xx.xxx.xxx")

Source IP

Attacker IP address

Guardpot

The honeypot that captured the event

Description

Detailed event description

F

Flagged indicator

A

Alerted indicator

Time

Relative timestamp (e.g., "2m ago")

Actions

Available actions for the event


2.9.1.5 Event Detail View

Clicking on an event card or table row opens a detailed analysis view for the specific IP address, as shown in Figure 2.9.1.5-1.

Figure 2.9.1.5-1 – Event Detail View

The detail view provides comprehensive threat analysis across multiple panels:

Security & Reliability Scores:

Score

Description

Security

Threat security rating (e.g., "E" for Elevated risk)

Reliability

Intelligence reliability score (e.g., "S" for Strong)

Total Attacks

Total number of attacks from this IP (e.g., 1,531)

Region

Geographic region (e.g., "Europe & Central Asia")

IP Information — Geolocation Details:

Field

Description

Country

Source country (e.g., Germany)

City

Source city (e.g., Augsburg)

Timezone

Local timezone with UTC offset

First Seen

First observed timestamp (e.g., 16.01.2026 23:39:04)

Last Seen

Most recent observed timestamp (e.g., 20.05.2026 07:40:20)

Provider

ISP or hosting provider (e.g., FPS12)

Location

Geographic coordinates (e.g., 48.35, 10.92)

MITRE Attacks:

Displays MITRE ATT&CK framework mappings for observed attack techniques from this IP.

Attack Map:

Visual representation showing the attacker's geographic location and targeted destinations.

Protocol Activity — Network Interactions Analysis:

A breakdown of network interactions by protocol with hit counts and percentages (e.g., postgresql-login: 899 hits (58.7%), tcp-portscan: 632 hits (41.3%)).

Top Targeted Countries — Attack Destinations:

Displays the countries most targeted by this attacker with percentage distribution and total attack counts.

Weekly Attacks — Temporal Analysis:

A timeline chart showing attack frequency across weeks and months, with active dates plotted chronologically.

Network Topology — Agent Connections & Interactions:

A timeline visualization showing which Guardpot agents interacted with this IP and when, with date markers spanning the observation period.


2.9.2 Threat Intelligence

The Threat Intelligence page provides advanced IP address lookup with comprehensive security analysis, as shown in Figure 2.9.2-1.

Figure 2.9.2-1 – Threat Intelligence Page

2.9.2.1 Page Header

The page displays the following header and description:

Threat Intelligence Area Advanced IP Address Intelligence & Security Analysis Real-time threat intelligence from Guardpot sources

Four feature highlights are displayed:

Feature

Description

Geolocation

Geographic origin identification

Threat Score

Risk assessment scoring

Attack History

Historical attack patterns

MITRE ATT&CK

Attack technique mapping

2.9.2.2 IP Address Lookup

An Enter IP address text bar allows you to query any IP address for threat intelligence. Type an IP (e.g., 1.1.1.1) and press Enter to perform the lookup.

2.9.2.3 Lookup Results

Upon querying an IP address, the following analysis panels are displayed:

Security & Reliability Scores:

Score

Description

Security

Threat security rating (e.g., "S" for Safe)

Reliability

Intelligence reliability score (e.g., "E")

Total Attacks

Total attacks observed from this IP

Region

Geographic region (e.g., "South Asia")

IP Information — Geolocation Details:

Field

Description

Country

Source country (e.g., India)

City

Source city (e.g., Pune)

Timezone

Local timezone with UTC offset

First Seen

First observed timestamp (displays N/A if no data)

Last Seen

Most recent observed timestamp (displays N/A if no data)

Provider

ISP or hosting provider (e.g., CLOUDFLARENET)

Location

Geographic coordinates (e.g., 18.54, 73.84)

Analysis Panels (with empty states when no data exists):

Panel

Empty State Message

World Analysis

"No geographic data — No map data available"

Protocol Activity

"No protocol data — Waiting for network activity..."

Top Targeted Countries

"No attack data — Waiting for threat intelligence..."

Weekly Attacks

"No temporal data — Waiting for temporal analysis..."

Network Topology

"No topology data — Waiting for network analysis..."

Attack Timeline

"No events recorded — No attack events available"


2.9.3 Forensic Intelligence

The Forensic Intelligence page provides detailed session-level forensic analysis of attacker interactions, as shown in Figure 2.9.3-1.

Figure 2.9.3-1 – Forensic Intelligence Page

2.9.3.1 Page Header

The page displays the following header and description:

Latest Forensic Intelligences Real-time attack forensic analysis and detailed session data

The session counter displays total sessions (e.g., "Page 1 of 594 • 11873 sessions").

2.9.3.2 Search and Filter

The right side of the toolbar provides search and filtering capabilities:

Control

Function

Search sessions

Text search across session data

Filter Sessions

Filter by Guardpot name or Attacker IP address

2.9.3.3 Session Table Columns

Each session row displays the following information:

Column

Description

Session

Guardpot name, attacker IP, OS, location, and public IP

Location

Geographic region of the attacker

Time

Session start and end timestamps with duration (e.g., "02.04.2026 18:09:32 → 02.04.2026 18:10:08 • 36s")

Status

Session state (e.g., "Ended")

Action

Available actions for the session

2.9.3.4 Session Detail Example

Field

Example Value

Guardpot

Auto Detected

Attacker IP

77.9x.xxx.xxx

OS

Linux (x64)

Location

Bursa, Turkey

Public IP

188.1xx.xxx.xxx

Region

Asia

Start Time

02.04.2026 18:09:32

End Time

02.04.2026 18:10:08

Duration

36s

Status

Ended

Was this article helpful?

Your feedback helps us improve our documentation.

Send feedback