πŸ“„2. Guardpot Platform Administration

2.14 Reports Module

3 min read69 viewsUpdated May 20, 2026

The Reports module generates detailed security reports in multiple formats with flexible time periods and Guardpot-specific filtering. The module header displays the title "Reports" with the subtitle "Company-based insights: activity, geolocation, honeypots and more." as shown in Figure 2.14-1.

Figure 2.14-1 – Reports Interface


2.14.1 Filter Controls

The top-right corner of the module provides filter controls for narrowing report scope, as shown in Figure 2.14.1-1.

Figure 2.14.1-1 – Reports Filter Controls

2.14.1.1 Guardpot Filter

A Guardpot selector dropdown allows you to filter reports by a specific honeypot agent. Select an existing Guardpot to scope all report data to that agent, or leave it unselected for company-wide reporting.

2.14.1.2 Reporting Periods

Three time period tabs define the date range for all reports:

Period

Range

Daily

Last 24 hours

Weekly

Last 7 days

Monthly

Last 30 days

Select a period tab to update all report cards to reflect the chosen time range.


2.14.2 Report Types

The Reports module offers nine report categories, each displayed as a card with a description and instant download buttons, as shown in Figure 2.14.2-1.

Figure 2.14.2-1 – Report Cards

2.14.2.1 Overview Threat Summary

Totals by period, top services, geo heat, top credentials, attack trends

Provides a high-level summary of the threat landscape including total attack counts, most targeted services, geographic heat map, top captured credentials, and overall attack trends for the selected period.

2.14.2.2 Detailed Attack Analysis

Protocol distribution, daily bars, top attacker IPs, MITRE mapping

Delivers in-depth attack analysis with protocol distribution charts, daily attack volume bars, top attacking IP addresses, and MITRE ATT&CK framework technique mappings.

2.14.2.3 Vulnerability & Risk

Discovered services, CVE matches, AI risk summary and recommendations

Presents vulnerability findings including discovered services, CVE identifier matches, AI-generated risk assessments, and prioritized remediation recommendations.

2.14.2.4 Alarm & Incident Management

Daily alarm volume, policy distribution, MTTR, resolved vs open, top solvers

Focuses on operational metrics including daily alarm volume trends, policy distribution across alarm types, Mean Time to Resolution (MTTR), resolved versus open alarm ratios, and top performing responders.

2.14.2.5 IoC & CTI

Indicators of compromise with reliability, targeted services and methods

Lists Indicators of Compromise with reliability scores, targeted services, and attack methods used, supporting cyber threat intelligence workflows.

2.14.2.6 Global Threat Report

Top 5 countries overview for the selected period

Provides a geographic summary of the top 5 attacking countries with attack counts and trends for the selected time period.

2.14.2.7 Agent Health & Status

Per-agent status, OS, version, last activity and attacks handled (all or filtered)

Reports on honeypot agent operational health including status, operating system, software version, last activity timestamp, and total attacks handled per agent.

2.14.2.8 Top Attackers

Top source IPs with country, total attacks, targeted services and activity window

Identifies the most active attacker IP addresses with country of origin, total attack counts, targeted services, and activity time windows.

2.14.2.9 Service Targeting Matrix

Most attacked services, unique attackers per service and top agent/service combinations

Displays a matrix of the most frequently attacked services, unique attacker counts per service, and the top agent and service combinations targeted.


2.14.3 Download Formats

Each report card includes three instant download buttons for exporting the report in the desired format:

Format

Button

Description

PDF

Download as formatted PDF document

CSV

Download as comma-separated values for spreadsheet analysis

Excel

Download as Excel spreadsheet for further manipulation

Clicking any format button immediately generates and downloads the corresponding report based on the currently selected Guardpot filter and time period. No additional configuration is required.

Was this article helpful?

Your feedback helps us improve our documentation.

Send feedback