> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onefirewall.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 561 Attacks in Thirty Minutes

> Reading the metrics behind a 30-minute attack window from a live threat intelligence feed

<img style={{ borderRadius: '0.5rem' }} src="https://mintcdn.com/onefirewall/mGgHxMsQTm71_QZa/images/case2.png?fit=max&auto=format&n=mGgHxMsQTm71_QZa&q=85&s=5e13b691f254f9b723c42291f5a1da49" width="1453" height="590" data-path="images/case2.png" />

This panel covers a single 30-minute window. In that window, OneFirewall logged **561 attacks**, with the highest-scoring source an IP out of Hong Kong routed through LARUS Limited's AS, carrying a Crime Score of **522**.

***

## Source composition

Two of the reporting sources listed are public fail2ban aggregators: Blocklist.net.ua and Blocklist.de. These services report IPs currently attempting SSH and login brute-forcing against a broad, independently monitored host pool. That's the input class threat intelligence in this system is built from: observed, repeated hostile behavior reported by third parties, correlated alongside Alliance member submissions.

## Volume and update frequency

The panel reports **47,797 new IPs first seen**, up **19%** over the comparison period, and **454,298 submissions**, up **304%**. A spike of that size typically indicates either infrastructure cycling through fresh IP ranges or a scanning campaign sweeping in a large batch of previously unflagged hosts. A blocklist updated once a day would lag behind a change of this magnitude before it could be pulled and applied. The submission rate reflects how quickly new indicators become available for enforcement.

## Sources and infrastructure

Top reporting countries for this window were the Netherlands, the US, Romania, and Singapore, with **UNMANAGED LTD (AS47890)** identified as the top offending ASN. The bar chart shows how much of this traffic was matched and blocked across the enforcement types already in place — Checkpoint and Fortinet feeds — with the same intelligence enforced consistently across both.

***

Proof of Value engagements analyze a client's own edge traffic against this feed. [Start a Proof of Value](https://onefirewall.com/proof-of-value).
