The challenge
A national security organization needed a clearer view of the threats reaching Dutch infrastructure. Its teams wanted to understand scanning activity and emerging payloads before relying solely on incident reports.
The approach
DTACT’s published project describes distributed honeypots feeding observations into Raven. Enrichment and similarity analysis helped analysts investigate evolving patterns.
The outcome
A connected view of observed attack activity supported threat research and recommendations to public and private sector partners.
