lurescope/top-attack-lists

Live brute-force telemetry from our own honeypot sensors — top usernames, passwords & empty-password probes with real attempt counts. Updated weekly.

0

stars

10

commits

Sep 13, 2026

updated

brute-force
cybersecurity
honeypot
ioc
security-research
ssh
threat-intelligence
wordlist

README

Top Attack Lists — Live Data From Our Own Honeypots

What attackers actually type when they knock on your door. These lists are generated from LureScope's own passive sensor network — real brute-force telemetry, not recycled wordlists, not crowdsourced reports.

857,835 attack events · 15,697 unique IPs · 159 countries — and counting. Observation window opened 2026-07-28.

Live free tools: Have attackers tried it? · Daily blocklist · Network stats · Threat reports

What's here

FileContents
data/top-usernames.txtTop 47 most-probed usernames (with attempt counts)
data/top-passwords.txtTop 50 most-probed passwords (with attempt counts)
data/empty-password-probes.txtUsernames probed with an empty password — a targeted misconfiguration sweep

Why these lists are different

  • First-party data. Every line comes from unsolicited inbound connections to our own sensors. We never scan anyone, and we don't resell third-party feeds.
  • Counts included. Most public wordlists are unranked. These carry real attempt volumes, so you can weight your detections.
  • It moves. wallet was nowhere in our top 10 on August 5. By August 8 it was #2 overall — 3,253 attempts, every single one with an empty password. Crypto-themed usernames (wallet, binance, blockchain, crypto, bitcoin) now account for 3,646 attempts and form the clearest targeting wave we've observed. See Report #3.
  • Beyond SSH. In August 2026 we added industrial protocol decoys to the network. First ~60 hours: 172 probes from 151 IPs across 7 ICS protocols — FTP leading at 38%, 88% one-shot visitors, nearly all from rented cloud infrastructure. See Report #5 — Who's Scanning the Industrial Internet?.

How to use

  • Detection: flag SSH/auth attempts against these username+password pairs, especially any wallet login attempt with an empty password.
  • Hardening audits: if any account on your systems matches a row in top-usernames.txt with a password from top-passwords.txt, that combination is being actively probed right now.
  • Honeypot research: compare with your own telemetry — we'd love to hear how it overlaps.

Methodology & ethics

  • Passive decoy sensors only (SSH, Windows-service, and industrial protocol emulation). We never initiate connections or interact with attacking systems.
  • Attacker IPs are never published here. These files contain only attempted credentials — which attackers already know, since they supplied them.
  • Hex-encoded artifacts (e.g. \x726f6f74 = root from MSSQL-layer probes) are filtered out of the lists.
  • Geolocation of sources reflects hosting infrastructure, not attacker nationality.

Updates

Weekly, alongside our threat reports. Machine-readable, scored, per-IP indicators with HASSH tooling clusters are available through the LureScope API — free early access, 100 queries/month.

License

CC BY 4.0 — use it, remix it, ship it in your product. Attribution: link to lurescope.com.


Data: LureScope global sensor network · Questions: support@lurescope.com

Contributors

lurescope

10 commits

lurescope/top-attack-lists

Live brute-force telemetry from our own honeypot sensors — top usernames, passwords & empty-password probes with real attempt counts. Updated weekly.

0

stars

10

commits

Sep 13, 2026

updated

brute-force
cybersecurity
honeypot
ioc
security-research
ssh
threat-intelligence
wordlist

README

Top Attack Lists — Live Data From Our Own Honeypots

What attackers actually type when they knock on your door. These lists are generated from LureScope's own passive sensor network — real brute-force telemetry, not recycled wordlists, not crowdsourced reports.

857,835 attack events · 15,697 unique IPs · 159 countries — and counting. Observation window opened 2026-07-28.

Live free tools: Have attackers tried it? · Daily blocklist · Network stats · Threat reports

What's here

FileContents
data/top-usernames.txtTop 47 most-probed usernames (with attempt counts)
data/top-passwords.txtTop 50 most-probed passwords (with attempt counts)
data/empty-password-probes.txtUsernames probed with an empty password — a targeted misconfiguration sweep

Why these lists are different

  • First-party data. Every line comes from unsolicited inbound connections to our own sensors. We never scan anyone, and we don't resell third-party feeds.
  • Counts included. Most public wordlists are unranked. These carry real attempt volumes, so you can weight your detections.
  • It moves. wallet was nowhere in our top 10 on August 5. By August 8 it was #2 overall — 3,253 attempts, every single one with an empty password. Crypto-themed usernames (wallet, binance, blockchain, crypto, bitcoin) now account for 3,646 attempts and form the clearest targeting wave we've observed. See Report #3.
  • Beyond SSH. In August 2026 we added industrial protocol decoys to the network. First ~60 hours: 172 probes from 151 IPs across 7 ICS protocols — FTP leading at 38%, 88% one-shot visitors, nearly all from rented cloud infrastructure. See Report #5 — Who's Scanning the Industrial Internet?.

How to use

  • Detection: flag SSH/auth attempts against these username+password pairs, especially any wallet login attempt with an empty password.
  • Hardening audits: if any account on your systems matches a row in top-usernames.txt with a password from top-passwords.txt, that combination is being actively probed right now.
  • Honeypot research: compare with your own telemetry — we'd love to hear how it overlaps.

Methodology & ethics

  • Passive decoy sensors only (SSH, Windows-service, and industrial protocol emulation). We never initiate connections or interact with attacking systems.
  • Attacker IPs are never published here. These files contain only attempted credentials — which attackers already know, since they supplied them.
  • Hex-encoded artifacts (e.g. \x726f6f74 = root from MSSQL-layer probes) are filtered out of the lists.
  • Geolocation of sources reflects hosting infrastructure, not attacker nationality.

Updates

Weekly, alongside our threat reports. Machine-readable, scored, per-IP indicators with HASSH tooling clusters are available through the LureScope API — free early access, 100 queries/month.

License

CC BY 4.0 — use it, remix it, ship it in your product. Attribution: link to lurescope.com.


Data: LureScope global sensor network · Questions: support@lurescope.com

Contributors

lurescope

10 commits