Sentinel protection metrics, updated every 15 minutes.

Detected attacks, enforced blocks, distinct sources, countries of origin and block duration: this report shows the protection work performed by Sentinel across the connected network. Every metric comes from real events and is consolidated automatically.

Real operational data · automatically updated every 15 minutes

Attacks detected—in the last 24 hours
Active blocks—temporary and permanent
Distinct sources—observed in the last 30 days
Countries observed—with available geolocation

Threat Pulse · Sentinel network

An immediate reading of what is happening.

Sentinel turns thousands of technical signals into clear indicators. These are not commercial estimates: every figure comes from real events and is recalculated every 15 minutes.

Average rate · 24 hours—events detected per hour
Peak · last 7 days—busiest day
Top technical origin—share of the total at 30 days
Leading signal—share of classified events

Operational overview

More context, not just a counter.

Time windows distinguish a recent spike from persistent activity. Source counts are deduplicated before publication.

Recent developments

Attacks detected day by day

Last 7 days

Loading trend...

Origin and response

Where hostile activity originates and how long blocks remain active.

The country represents the geolocated technical origin, not necessarily the attacker’s actual location.

Geographical distribution

Countries with the most attacks

Last 30 days

Podium composition...

CountryAttacksBlocked sourcesRelative intensity
Loading the rankings...

Techniques observed

Which controls are detecting and blocking the most activity.

The types describe the recorded events; the reasons explain why the sources in the protection list have been blocked.

Aggregated events

Most frequent attack types

30 days

Loading typologies...

Blocks currently active

Why sources are blocked

Now

Loading reasons...

Protection is measured through concrete results.

Every metric comes from events actually detected and actions actually enforced: stopped attempts, blocked sources, block duration and geographic distribution. The report is designed to show security volume, effectiveness and trends; individual IP addresses are operational details and are not part of this public view.

Sources and methodology

How public data is built and controlled.

This section makes explicit origin, frequency, time windows and dataset limits, so the numbers can be interpreted correctly even outside their graphical context.

Technical sources

Aggregated events collected by Sentinel agents, log watchers, the WAF and security integrations enabled on connected systems.

Frequency

The public file is automatically rebuilt every 15 minutes. The date of the last valid update is shown at the top and included in the metadata of the dataset.

Time windows

Summaries use 24-hour, 7-day and 30-day windows. Active blocks are a snapshot taken when the dataset is generated.

Metric processing

Events are consolidated by period, technique, country and block reason. The result highlights the work performed by the protection controls and makes different time windows comparable.

Dataset in JSON formatStructured aggregate data, updated automatically.
Download dataMethodology reviewed on 2 September 2026 · Responsible organisation: G Tech Group S.R.L.S.

How to read data

Operational metrics for assessing pressure and response.

Technical traffic origin

Country distribution identifies where more hostile activity originates and helps tune geo-blocking, reputation and access rules.

Distinct sources

The metric groups distinct technical origins within the period, preventing repeated events from the same source from inflating the result.

Update every 15 minutes

The dataset is automatically rebuilt from scratch. If generation or metric validation fails, the latest valid snapshot remains available.

Remaining block duration

The time bands describe when the currently active blocks will expire; the permanent ones require an authorised revocation.

Do you want this visibility on your servers?

Sentinel centralises fleet events and enforces protection close to the applications.