I.T.S. TECH HUB
Traffic analysis.
A live, privacy-conscious view of website activity: where visits are coming from, how traffic is classified, and which routes are being probed.
VISITOR MAP · LAST 3 DAYS
Recent traffic signals.
Approximate IP-derived locations for recorded HTML page visits. Human means at least five visible seconds plus browser interaction; unconfirmed traffic remains Unknown.
Loading the visitor map…
Locations
Hacking attempts and reconnaissance signals.
I.T.S. uses proprietary traffic-analysis technology—including rules, session evidence, timing correlation, geolocation, protocol fingerprinting, and AI-assisted pattern review—to identify relationships that individual requests do not reveal. The public User Agent table shows the value reported by each client. Deeper TCP/IP and path-level indicators are correlated only when the corresponding telemetry is available; a signal by itself is not proof of an attack.
Loading security-signal analysis…
ATTACK GEOGRAPHY
Probe activity by country
| Country | Requests |
|---|
PROBED ROUTES
Most frequently probed routes
| Page path | Requests |
|---|
REPEAT ACTIVITY
Repeated scanning source IPs
Only source IP addresses with more than 10 recorded attack-probe requests are included.| Source IP | Requests |
|---|
CLIENT SIGNATURES
User Agents used by repeated scanners
Browser, crawler, script, and automation signatures reported by the same high-volume source IPs.| User Agent | Source IPs | Requests |
|---|
SIGNALS ACROSS THE STACK
How suspicious activity is correlated.
Attack activity rarely announces itself through a single request. I.T.S. examines combinations of technical and behavioral signals such as:
- Repeated attack probes across targeted routes.
- Requests without a recognized browser session.
- Unusually high request volume or repeated rate bursts.
- No pointer, mouse, keyboard, or scrolling activity detected.
- Requests that never produce verified human-behavior evidence.
- Activity distributed across different IP addresses that appears unrelated, but targets different pages with a similar cadence in nearby time slots.
- The reported User Agent and inconsistencies with header ordering, session behavior, client capabilities, and request cadence that can expose spoofing or a shared automation family.
- When transport telemetry is available, TCP/IP fingerprints such as TCP option order, MSS, receive-window size and scaling, TTL, DF and fragmentation behavior, and retransmission cadence.
- Path-MTU inference from MSS and fragmentation behavior, together with unusual frame-padding patterns, as supporting network evidence rather than standalone proof.
- During authorized investigation, low-level responses to a simple ICMP echo request can reveal supporting host and network characteristics through TTL, latency, fragmentation behavior, and response consistency. A ping response alone is never proof, and many networks block or normalize ICMP.
CORRELATED ATTACK SOURCES
Problematic IPs and locations.
Approximate origins of IP addresses with more than 10 recorded attack-probe requests. Normal visitor traffic is excluded.
Loading the attack-source map…