Explore the data

What attack traffic, edge filtering, and real reader visits look like against a personal site running production-grade infrastructure. Data refreshes about every 10 minutes.

How this system works →

1,266 hostile events for every legitimate pageview, last 30 days.

← Back to site

Source IPs are redacted to /24 (IPv4) or /48 (IPv6) before materialization. Raw IPs are never stored or displayed.

The contrast

Attacker volume, edge requests, and real pageviews on one scale.

See also: What's Running at jon.rehagen.net/explore

THE CONTRAST

Hostile vs. legitimate traffic

Attack traffic

Bots and scanners hitting decoy endpoints. /.env, /admin, /wp-login, and dozens of other canary and trap paths.

See also: Why I Run Production-Grade Personal Infrastructure

ATTACK ORIGIN

Attackers by country

CANARIES

Canary trigger timeline

ATTACK PATHS

Top attacked paths

USER AGENTS

Top hostile user agents

TIMING

When attackers strike

DECEPTION

LLM-generated responses

Edge

What Cloudflare filters before requests reach the origin.

See also: IAP on Cloud Run: One Flag Changes the Calculus

EDGE ORIGIN

Edge traffic by country

EDGE VOLUME

Edge volume

BLOCKS

Blocks over time

STATUS

HTTP status codes

CACHE

Cache status

BLOCKED ORIGIN

Top blocked countries

BLOCKED PATHS

Top blocked paths

FIREWALL

Firewall actions

RECENT BLOCKS

Recent blocks

RECENT REQUESTS

Recent requests

Real visitors

Self-hosted Umami. Counted without cookies or third-party trackers.

See also: Web Tracking Techniques: A 2026 Field Guide

VISITOR ORIGIN

Where legitimate visitors come from

READS

Most-read pages