BoarNet · Research
CVE exploitation timeline
When did each CVE first appear in BoarNet honeypot capture data, how widely is it being scanned, which ASNs are driving the volume. Aggregate-only — per-IP detail lives in the dashboard for authenticated researchers.
Fresh
0
disclosed ≤90d, post-fleet
Resurgent
0
dormant→active campaigns
Long-tail
0
ongoing background scans
Observed total
0
0 tracked overall
No CVEs yet
The CISA KEV pull cron should populate metadata within 30 minutes of activation.
Showing the most-active 200. “In the wild” means at least 5 distinct IPs across at least 3 ASNs and 3 countries on at least 2 different days in the last 7 — a threshold designed to filter single-researcher PoCs without missing real but small campaigns.