Detection Analytics
Understanding detection trends and analytics in your dashboard.
The Analytics page shows detection trends over time, helping you understand scanning patterns and evaluate trap effectiveness across your protected sites.
Trap Activity Chart
The main visualization is a horizontal bar chart showing which traps receive the most interactions. This helps you identify:
- High-activity traps -- endpoints that agents consistently discover and probe
- Low-activity traps -- endpoints that may need better placement or linking
- Activity spikes -- sudden increases that may indicate a new scanning campaign
Time Period Selection
Use the time period selector to adjust the analytics window:
- 24 hours -- recent activity, useful for monitoring active scanning
- 7 days -- weekly trends, good for spotting recurring scan patterns
- 30 days -- monthly view, best for evaluating overall trap effectiveness
All charts and metrics update to reflect the selected period.
Site Filtering
If you protect multiple domains, filter analytics to a specific site using the site selector. This lets you compare detection rates across different properties and identify which sites are being targeted most heavily.
Identifying Scanning Patterns
Analytics data reveals patterns in how agents scan your infrastructure:
- Regular intervals -- if hits appear on a schedule, the agent is likely running periodic scans
- Burst activity -- a cluster of hits in a short window suggests a targeted scan
- Trap traversal -- agents that hit multiple traps in sequence may be following breadcrumb cross-references between your trap endpoints
Correlate analytics with deployment changes. If you recently added new traps or switched from beacon to proxy mode, the analytics page shows whether the change increased detection coverage.
See Also
- Dashboard Overview -- real-time summary metrics
- Threats Caught -- individual session investigation
- Security Posture Score -- how detection data feeds your posture grade