Skip to content

Threat feed

DataPlane Telnet Login

Last fetched

Brute Force · refreshed hourly · last verified

DataPlane Telnet Login is a Brute Force threat-intelligence feed, refreshed hourly, indexed by WhisperGraph.

What is DataPlane Telnet Login

DataPlane Telnet Login is the Telnet-targeting companion to DataPlane.org's SSH-focused feeds also indexed here, listing IPs observed completing a Telnet login attempt against the project's honeypot sensors. Telnet brute force is strongly associated with IoT-botnet propagation (Mirai and its many derivatives scan for default-credential Telnet devices at internet scale), so this feed is a useful signal specifically for that threat class rather than generic scanning. As with the project's SSH feeds, a connection to a sensor that advertises no legitimate Telnet service is definitionally abusive. It is indexed here as a DataPlane.org sensor-grounded reference for IoT-botnet-style Telnet abuse.

Refresh cadence
hourly

Category drift. The curated category for this feed is Brute Force, while WhisperGraph currently files it under bruteforce.

Indicators currently listed

No indicator in WhisperGraph currently links to DataPlane Telnet Login. That is not the same as the feed being empty — the graph indexes a subset of every feed’s published entries.

Related pages

Pivot from DataPlane Telnet Login into the indicators it lists.

Queries

Resolves the feed's categories.


MATCH (f:FEED_SOURCE {name: $slug})
OPTIONAL MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
WITH f, collect(c.name) AS categories
RETURN f.name AS slug, f.id AS id, categories
Run yourself →

The indicator-kind rollup and sample listed above.


MATCH (f:FEED_SOURCE {name: $slug})<-[:LISTED_IN]-(x)
WITH labels(x)[0] AS kind, count(*) AS listed, collect(x.name)[0..5] AS sample
RETURN kind, listed, sample
ORDER BY listed DESC
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.