Search an IP address seen in your logs.
Sotiras publishes privacy-safe intelligence for selected active IPs observed through honeypots, collectors, server logs, and public-facing services.
IP reputation lookup
Enter a public IPv4 or IPv6 address from a firewall, fail2ban, WordPress event, honeypot, or server log.
Event heat map
Public-safe observation density by UTC day and hour. Darker cells mean more events.
Top IPs
IPs with the most public-safe observations in the current window.
Attack types
Normalized behavior categories seen across published intelligence.
Countries
Observed source geography after enrichment, grouped for public display.
Targeted services
Ports and services most often touched by observed traffic.
Source mix
Collector and telemetry families contributing aggregate evidence.
Categories
Public blocklist and behavior labels associated with listed IPs.
Privacy-safe by design
Public pages show aggregate behavior, source mix, timing, and recommended action. They do not publish customer logs, hostnames, usernames, payloads, or tenant-specific evidence.
Connect your signals
Sotiras can correlate public IP intelligence with your WordPress, Linux server, firewall, nginx, Apache, VoIP, and application logs after you connect a collector.
Recently published indicators
Active IPs with approved public intelligence or anonymized Sotiras aggregate evidence.
Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.
Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.
Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.
Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.
Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.
Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.
Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.
Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.