
Source diversity
The sources that flagged this activity include Olidata, an Italian MSP partner; Blocklist.de’s fail2ban reporting service; Suricata-based network detection; DeceptionGrid, a honeypot network with no legitimate traffic to hide behind; and AquilaX, an AI-driven software security source, among others. These are distinct source types — public blocklists, commercial partners, honeypots, AI-assisted detection — with no operational relationship to one another. Independent agreement across source types is a factor in the trust weighting applied when a Crime Score is calculated.Classification, not just a score
The right panel classifies the campaign into MITRE ATT&CK attack patterns — password guessing is shown as one example — paired with courses of action that map to specific configuration changes: account lockout policies against brute forcing, port closure and network segmentation against service scanning, file and process permission hardening against service-stop attempts, and credential-handling controls against valid-account abuse.Score versus technique
A Crime Score indicates confidence that an asset is malicious. MITRE ATT&CK mapping indicates which technique is in use, and therefore which control addresses it. Blocking the IP addresses this instance. Applying the mapped course of action addresses the technique, which remains relevant the next time a different IP uses the same approach.Proof of Value engagements map campaigns like this one against a client’s own logs. Start a Proof of Value.

