Loading egress telemetryβ¦
What it tried to abuse
Blocked outbound connections by target port. On a honeypot the box should reach out to almost nothing β so each of these is a session that escaped emulation or a proxy-abuse probe.
Would-be victims
Destinations the box was blocked from contacting. These are the third parties your sensor would otherwise have shown up attacking β the exact reports that get a droplet terminated.
Blocked outbound over time
Spikes = an escape attempt or scan burst. A flat/empty chart is the healthy state.
Recent blocked attempts
Most recent outbound connections the egress guard stopped.
Why this is intelligence, not just plumbing. A correctly-run honeypot makes essentially
zero legitimate outbound connections. So when the egress guard blocks one, it means something on
the box tried to reach out β a payload that broke containment, or an attacker testing whether they
can pivot through you to hit someone else. DarkWick is the only view that turns "we stopped the box
from becoming an attacker" into a visible, dated, destination-level record. It also proves the
zero-abuse posture that keeps the sensor alive.