The internet, by the numbers
A live visual census of the scanned IPv4 space — where the hosts are, what they run, and where the risk concentrates.
World heatmap
Where the hosts — and the hazards — live
Flip between raw host density, critical vulnerabilities, and unauthenticated exposures. The shading is log-scaled, so a couple of giant countries don't wash everyone else out.
Hover any country for its exact counts.
Live host clusters
Where the internet piles up
Every dot is a live cluster of hosts at its real coordinates, sized linearly — so a dot's area is true host count, not the log shading above. A handful of metros carry a wildly outsized share.
Switch to no-auth exposed and the map re-weights to hosts running an unauthenticated service — exposure clusters somewhere quite different from raw host density.
Hover any cluster for its city and exact counts.
Riskiest countries
Big isn't the same as dangerous
Raw totals just rank the largest networks. Dividing critical-severity services by host count surfaces the countries actually running the most exploitable software — small nations on old firmware rise to the top.
Minimum 200 hosts, to keep tiny samples out.
Application preferences
What the internet actually runs
Which web server software the internet runs — nginx vs Apache vs the rest.
Switch categories to see the mail, SSH, FTP and DNS landscapes.
Top products
Every banner we recognise
Across all ports, the most common service software — web servers, SSH daemons, mail agents, routers (RouterOS/MikroTik) and firewalls (Sophos). Click a bar to explore those hosts.
Vulnerabilities
Where the CVEs concentrate
Grouped by the affected service, or as individual CVEs — red when actively exploited (CISA KEV), amber when a public exploit exists.
Version-based matches are an upper bound — backports patch silently. Reconcile a host →
Product mix by country
Every nation has a stack
The share of each country's detected services by product. Some lean hard on nginx, others on IIS or LiteSpeed — a fingerprint of dominant local hosts and habits.
TLS & crypto hygiene
How well the encrypted web is set up
CA-signed vs self-signed certificates, how many have expired, and JARM fingerprints that cluster servers running the exact same TLS stack — a giveaway for shared appliances and CDNs.
What these pages look like
We render and read every page
A vision model classifies each captured screenshot. Most are error pages and login portals — but a long tail of exposed dashboards, cameras, and the occasional defacement hides in there.
Networks (ASN)
The internet is a patchwork of networks
Each tile is one autonomous system, sized by host count and coloured by risk (teal → red = critical services per host).
Want to see how a network actually connects? The AS upstream explorer → traces any network's path to the internet — the transit providers it buys from, up to the tier-1 core.
On the treemap: hit replay (or toggle the size metric) to redraw; hover a tile for detail, or click to trace that network's path to the internet.
Top ports
What's listening
443 and 80 lead, as you'd expect — but the long tail of management, database and remote-access ports is exactly where accidental exposure tends to hide.
Hosts by continent
A snapshot, not the whole planet
Distribution skews to wherever scanning has reached so far. It's a picture of the mapped corpus as it grows — not a claim about the entire internet.
Most common favicons
An icon is a fingerprint
Identical favicons reveal the same app or appliance deployed across thousands of hosts. Click one to find every host serving it.
Risk & encryption posture
The corpus in one bar chart
How many hosts carry critical flaws, sit unauthenticated, or run TLS at all. Version-based CVE counts are an upper bound; the exposure and TLS numbers are exact.
Aggregates exclude hosts that have opted out. Numbers cached ~15 min.