Threat feed
DataPlane Telnet Login
Last fetched
Brute Force · refreshed hourly · last verified
DataPlane Telnet Login is a Brute Force threat-intelligence feed, refreshed hourly, indexed by WhisperGraph.
What is DataPlane Telnet Login
DataPlane Telnet Login is the Telnet-targeting companion to DataPlane.org's SSH-focused feeds also indexed here, listing IPs observed completing a Telnet login attempt against the project's honeypot sensors. Telnet brute force is strongly associated with IoT-botnet propagation (Mirai and its many derivatives scan for default-credential Telnet devices at internet scale), so this feed is a useful signal specifically for that threat class rather than generic scanning. As with the project's SSH feeds, a connection to a sensor that advertises no legitimate Telnet service is definitionally abusive. It is indexed here as a DataPlane.org sensor-grounded reference for IoT-botnet-style Telnet abuse.
- Source
- https://dataplane.org/
- Refresh cadence
- hourly
Category drift. The curated category for this feed is Brute Force, while WhisperGraph currently files it under bruteforce.
Indicators currently listed
No indicator in WhisperGraph currently links to DataPlane Telnet Login. That is not the same as the feed being empty — the graph indexes a subset of every feed’s published entries.
Related pages
Pivot from DataPlane Telnet Login into the indicators it lists.
Queries
Resolves the feed's categories.
MATCH (f:FEED_SOURCE {name: $slug})
OPTIONAL MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
WITH f, collect(c.name) AS categories
RETURN f.name AS slug, f.id AS id, categoriesRun yourself →The indicator-kind rollup and sample listed above.
MATCH (f:FEED_SOURCE {name: $slug})<-[:LISTED_IN]-(x)
WITH labels(x)[0] AS kind, count(*) AS listed, collect(x.name)[0..5] AS sample
RETURN kind, listed, sample
ORDER BY listed DESCRun yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.