Tactics & tags
ECHO classifies activity at two levels. Behavior tags are derived per-IP from rolled-up activity (8 active). Event tags are applied per-event by ingestion rules (36 active). Click any tag for the live IP feed.
Behavior tags
IPs with 10+ failed SSH attempts in the rolling window.
IPs trying 5+ distinct usernames with 10+ total failures — credential-stuffing pattern.
IPs active across 24h+ with 50+ total events — sustained, not opportunistic.
IPs hitting both ironcat AND ironcatlabs hosts — geographically distributed targeting.
IPs scanning 15+ distinct paths with 20+ 404 responses — directory-busting / path discovery.
IPs active across 7d+ with 200+ events — committed campaign infrastructure.
IPs with 1000+ total events. The truly relentless.
IPs observed on both SSH and HTTP — sophisticated multi-vector reconnaissance.