Export
Downloadable data and public feeds.
Most active source IPs. Compatible with fail2ban, pfSense, and similar tools. Plain text (one IP per line) or CSV with full metadata.
Most active autonomous systems. Useful for network-level blocking when many IPs from the same provider are probing your infrastructure.
Structured JSON summary of the last 24 hours: event counts, top countries, top paths, top IPs, and recent events. Suitable for dashboards and integrations.
Paths and payloads in this feed are attacker-supplied requests directed at the honeypot — not indicators of compromise in any real system. Data licensed under CC-BY 4.0.
All data is provided as-is for informational and defensive purposes. TarPit-Lab makes no guarantees about completeness or accuracy. Do not use IP or ASN blocklists as the sole basis for blocking decisions. All IPs and ASNs appear because they initiated unsolicited connections to a honeypot. See Legal Notice and Privacy Policy for more.
Database contains 4,080,412 total events.