Executive Summary
This report covers threat intelligence collected by HookProbe's edge IDS deployment during July 2026. All data comes from a production Raspberry Pi 5 running the NAPSE AI-native intrusion detection engine, HYDRA threat intelligence pipeline, and AEGIS autonomous defense system.
HookProbe processed 3821567 security events this month, classified 80954 ML verdicts, tracked 35526 unique IP addresses, and analyzed 0 network flows totaling 0 GB of traffic.
3821567
Security Events
80954
ML Verdicts
35526
IPs Profiled
0
New IoCs
Threat Event Breakdown
The HYDRA threat intelligence pipeline processed 3821567 events across three defense layers:
Defense Layer
Events
Unique IPs
% of Total
Rate Limiting (DDoS/Brute-Force)
946559
98
24%
Blocklist Enforcement
1717048
658
44%
ML Score Threshold
1157960
38
30%
ML Classification Results
The SENTINEL ML ensemble classified 80954 IP behaviors this month:
- Benign: 79379 (98%) — normal traffic, no action taken
- Suspicious: 1041 (1%) — elevated monitoring, behavioral tracking
- Malicious: 534 (0%) — escalated to cognitive throttling or blocking
IP Risk Distribution
HYDRA profiled 35526 unique IP addresses with composite risk scores:
- Critical (0.8+): 4 IPs (0%)
- High (0.5-0.8): 11056 IPs (31%)
- Medium (0.2-0.5): 23590 IPs (66%)
- Low (<0.2): 876 IPs (2%)
Indicators of Compromise
0 new IoCs were discovered this month (88 active total). All indicators are IP-based, sourced from behavioral analysis by the SENTINEL ML pipeline and correlated with Spamhaus DROP and FireHOL blocklists.
Attack Pattern Intelligence
The SENTINEL pattern mining engine discovered 1238 attack patterns and identified 0 coordinated campaigns. The predictive engine generated 5702 proactive alerts for preemptive defense.
Network Flow Analysis
NAPSE processed 0 network flows totaling 0 GB of inspected traffic. Autonomous blocking issued 0 throttle/block actions against 0 unique IPs.
Security Posture
The QSecBit security score averaged 89.3/100 throughout July 2026, maintaining GREEN (Protected) status. The score remained stable, indicating consistent defense posture without degradation events.
Key Takeaways
- Rate limiting remains the primary defense mechanism, handling 24% of all security events from just 98 aggressive source IPs
- The ML pipeline correctly identified 98% of traffic as benign — low false positive rate
- 4 critical-risk IPs were identified and tracked — representing active threat actors
- All detection and response ran autonomously on a Raspberry Pi 5 with zero manual intervention
About This Report
This threat intelligence is generated from a production HookProbe deployment running on a Raspberry Pi 5 (8GB RAM). The system uses NAPSE (AI-native IDS), HYDRA (threat intelligence pipeline), SENTINEL (ML classification), and AEGIS (autonomous defense) — all open-source under AGPL v3.0.
Data is collected, processed, and published automatically. No data is fabricated or simulated. View the source code on GitHub.
Originally published at hookprobe.com. HookProbe is an open-source AI-native IDS that runs on a Raspberry Pi.
GitHub: github.com/hookprobe/hookprobe
Top comments (0)