πŸ”₯

DarkWick β€” Anti-Abuse Insights

Outbound abuse the honeypot attempted and was blocked from β€” first-party signal, witnessed not inferred.
What happens in the dark, must be brought to light.
Loading egress telemetry…

What it tried to abuse

Blocked outbound connections by target port. On a honeypot the box should reach out to almost nothing β€” so each of these is a session that escaped emulation or a proxy-abuse probe.

Would-be victims

Destinations the box was blocked from contacting. These are the third parties your sensor would otherwise have shown up attacking β€” the exact reports that get a droplet terminated.

Blocked outbound over time

Spikes = an escape attempt or scan burst. A flat/empty chart is the healthy state.

Recent blocked attempts

Most recent outbound connections the egress guard stopped.

Why this is intelligence, not just plumbing. A correctly-run honeypot makes essentially zero legitimate outbound connections. So when the egress guard blocks one, it means something on the box tried to reach out β€” a payload that broke containment, or an attacker testing whether they can pivot through you to hit someone else. DarkWick is the only view that turns "we stopped the box from becoming an attacker" into a visible, dated, destination-level record. It also proves the zero-abuse posture that keeps the sensor alive.