Categories
Dataset thresholds
ip_all
Contains all IP addresses that have logged into any honeypot at least once.
ip_2 (recommended)
Contains IP addresses that logged into a honeypot at least 2 times. This helps eliminate false positives, typos, or one-off scanning attempts.
ip_5
Contains IP addresses that logged into a honeypot at least 5 times. Suitable for more conservative use and lower-noise analysis.