[ GAME SYSTEM OVERVIEW ]

GLOBAL THREAT LEADERBOARD

Hit a high score of 100 points and get automatically null-routed at the BGP edge across participating networks.

GAME OVER // BANNED IPS
Synchronized to BGP Edge RIB
SUBNET BANS (/24 & /48)
Multi-Player Subnet Aggregation
HOT ASNS IN DANGER ZONE
Flagged Hostile Networks
THREATS IDENTIFIED / HOUR
New Bans, Last 60 Minutes

🏢 TOP HOSTILE ASNS

High Risk
# ASN Network Name Threat Score
Loading live ASN threat score...

🌍 TOP HOSTILE COUNTRIES

Global Geo
# Code Country / Region Threat Score
Loading country threat data...

⚡ TOP ATTACK VECTORS

Vector Breakdown
# Vector Category Reports
Loading attack vectors...

🔒 INDIVIDUAL IP INTELLIGENCE LOCKED

Individual IP address listings, threat history logs, BGP peer configurations, and search tools are reserved for authenticated audience accounts.

[ MULTI-TENANT ORGANIZATIONAL CONSOLE ]

My Organization

org-slug

Manage your team, registered subnets, and invite users with zero user limits

Team Roster (0)

Unlimited Members Supported
Player Name Email Role Level Action

Registered Subnets (0)

Your own known-good ranges (a single /32 up through wide blocks). These are excluded from your own BGP feed and now protected from being banned platform-wide at all — by your own submissions, another org's, or auto-detection.

CIDR Subnet Description Action

🔑 API Keys (0)

Name Capabilities Created Last Used Action

Pending Team Invitations

Email Address Role Shareable Invite Link Expires Action

⚙️ Organization Defaults & Policy Settings

🚫 Organization Private Blacklist

CIDR Subnet / IP Reason Action

🛡️ Automated Carrier Infrastructure Guardrails

Hardened immunity matrix protecting public DNS resolvers (8.8.8.8, 1.1.1.1, Quad9), root name servers (A–M), emergency endpoints, and IXP peering LAN fabrics against accidental blackholing.

Infrastructure Name Category CIDR / Subnet Description Protection Status

🔗 BGP Peers

Your org's BGP sessions with Quaggy. Manage peers (add/edit/feeds/router config) on the BGP tab.

Neighbor IP Local ASN Remote ASN Description Session State

🏠 My Self-Hosted BGP Nodes

Register your own qbgp+gobgp instance (running in your own network) so it shows up here with live status, and so its peering IP is selectable in the router config generator.

Name Peering IP Local ASN Status Last Heartbeat Action

[ ROUTE-REFLECTOR GRID ]

BGP PEERING SESSIONS

Sync BGP null-route announcements directly to your edge routers

Neighbor IP Remote ASN Export Policy / Communities Global Feed Description Session State Prefixes (rx/accepted) Latency Actions

[ DISPUTE RESOLUTION MATRIX ]

IP REMOVAL DISPUTES & VOTING

Submit false-positive removal requests or vote on dispute resolutions for cross-org blocks

Target IP Requested By Reason Votes (Approve/Reject) Status Resolver / Mod Action

🍯 HONEYPOT SENSOR FLEET

Decoy sensors report every touch back here as a scoring event. Being noticed by one of these means you're now a player.

Sensor Hostname Status Active Ports Events (24h) Sessions (24h) Last Seen Action

🖥️ KUBERNETES MICROSERVICE HEALTH

Live pod status straight from k3s (qk3s01) — phase, restarts, image, and uptime for every Quaggy service.

Live Pod Status
Service Pod Phase Ready Restarts Image Started

📊 SERVICE METRICS

Live-scraped from each service's own Prometheus endpoint on page load — how qProcessor/qFeeds/qNotifier/qCollector are actually performing right now, not just whether their pod is up.

Live Snapshot

🏢 ORGANIZATIONS OVERVIEW

Every organization on the platform, one row each — trust tier, members, self-service ranges, custom blacklist entries, BGP peers, active API keys, and most recent report activity.

0 orgs
Organization Trust Tier Report Weight Members Ranges Blacklist Entries BGP Peers Active API Keys Last Activity

📡 BGP MESH NODE STATUS

Real-time node status, GoBGP gRPC health, peer connections, error counts, and prefix telemetry, reported by each qbgp instance's own heartbeat.

Heartbeat Stream Active
Node ID Microservice Daemon Status GoBGP gRPC Connected Peers Trying Peers Errors Advertised Prefixes Last Update Maintenance

🌐 BGP Peers by Organization

Organization BGP Peers

👤 System Users & Credentials

User ID Username Email Org Level / Role API Key Status

System Organizations & Trust Tiers

Organization Name Slug Trust Tier Report Weight Members Subnets Actions

📡 External Threat Intelligence Feed Catalog

Automated ingestion engine (qFeeds) polls third-party threat feeds on a scheduled cycle, applies mandatory security guardrails (reject /0, prefix floors, entry caps), and syncs to Redis for BGP peering export.

Feed Name Family Parser Refresh Community Ingested Entries Last Fetch Global Status Action

📦 STIX 2.1 & TAXII 2.1 Outbound Threat Exchange

OASIS Standard STIX 2.1 JSON bundle export & TAXII 2.1 server discovery endpoints for SIEM/SOAR integration (Splunk, QRadar, Sentinel, MISP).

STIX 2.1 & TAXII 2.1 Ready
📄 STIX 2.1 Outbound Bundle Feed
GET /v2/stix2/bundle

Returns STIX 2.1 JSON bundle of all active corroborated blackhole indicator objects.

📡 TAXII 2.1 Server Discovery & API Root
GET /v2/taxii2/ | /v2/taxii2/api1/collections/active-blackholes/objects/

OASIS TAXII 2.1 Discovery & Collections envelope API for automated SIEM poll clients.

⚡ Dynamic Platform Scoring & System Configuration

These live parameters control the scoring engine across all running qProcessor nodes without binary restarts.

🛡️ Global Carrier Infrastructure Whitelist

Protects the shared platform blacklist itself — public DNS resolvers, root name servers, emergency endpoints, and IXP peering LAN fabrics can never be blackholed regardless of report volume.

Infrastructure Name Category CIDR / Subnet Description Protection Status

📜 Admin Audit Trail

Most recent 200

Covers the highest-value admin/org-admin mutations (users, org trust tiers, BGP peers, org/global blacklist and whitelist, invites) - not literally every action in the platform.

When Actor Action Target Detail

[ MULTI-TENANT ALERT DELIVERY ]

NOTIFICATION CHANNELS

Configure real-time threat alert webhooks, Discord/Slack/Mattermost bots, and SMTP email notifications for your organization.

Scope / Org Channel Name Type Subscribed Events Status Actions
Loading notification channels...

[ JOIN THE GRID ]

DEPLOYMENT DOCS

Every hostile IP that crosses 100 points gets exiled from the mesh. Here's how to watch it happen on your own network — or feed the machine yourself.

📡 Tier 1 — We Run The Mesh, You Just Connect

Quaggy's own BGP mesh (running on our edge nodes) originates a real-time null-route feed straight from the live scoreboard — the instant an IP hits 100 points, it's announced. Peer your existing router or firewall against it and every one of those exiles gets null-routed at your own edge automatically. No Quaggy software to install — this is standard eBGP.

  1. Go to My Organization → BGP Peers and click ➕ Add BGP Peer — give it your router's peering IP and your ASN (no ASN of your own? the default private ASN 64512 works fine).
  2. Click the new peer's ⚙️ Config button, pick your platform — Cisco IOS/IOS-XE, Juniper JunOS, or FRR (this covers UniFi UDM/USG too, since it runs FRR underneath) — and copy the generated config straight into your device.
  3. Watch the Session State column on that same page flip to ESTABLISHED. That's it — you're live.

From here you're just watching the game: prefix counts and session health update in real time on the BGP Peers page as players get taken off the board.

📤 Tier 2 — Send Data: Report What's Attacking You

Point qcollector at your own logs (SSH, mail, web server, honeypot, firewall, ...) to report attacks into Quaggy's scoring engine. Every report you send adds to the target's score — enough of them, from enough different sources, and that IP goes on the watch list and, eventually, dies. Since you're already peered in Tier 1, your own reports can come back around as a null-route on your own router.

  1. Grab an API key/token from My Org → Members (or your own user token under Account Settings).
  2. Clone and install (Linux, x86_64/arm64/armv7):
git clone https://github.com/quaggy-org/qCollector.git && cd qCollector
sudo ./install.sh --api-key YOUR_API_KEY --api-token YOUR_API_TOKEN

This installs the binary, a systemd unit, and a starter /etc/qcollector/qcollector.yaml with your credentials filled in. Edit it to add a watcher, e.g.:

watchers:
  - name: "ssh_watcher"
    file: "/var/log/auth.log"
    file_type: "static"        # static | rotate | dated
    catalogs:
      - "ssh"                  # reuse a built-in rule catalog

Then systemctl restart qcollector. Prefer Docker? The repo also ships a docker-compose.yaml — see its README.md for that path.

Built-in catalogs (baked into the binary, no extra download): ssh, nginx, apache, postfix, cowrie, fail2ban, asterisk, freeswitch, opensips, systemd_auth, and malware_signatures. Need something they don't cover? Add a custom rules: block alongside a catalog in the same watcher — see qCollector's README.md for the pattern syntax. (Note: the central, admin-managed "Collector Rules" screen is a work in progress and isn't populated yet — for now, custom patterns live in your own qcollector.yaml, not a shared server-side list.)

🛰️ Tier 3 — Self-Hosted BGP: Run The Mesh Node Yourself

Don't have a router that speaks BGP? Run Quaggy's own qbgp + gobgp pair yourself instead of peering existing hardware — it's the exact same two containers our own edge nodes run.

  1. Register your node under My Org → My Self-Hosted BGP Nodes (peering IP, local ASN).
  2. Click 📄 qbgp.yaml on your new node to download its config — this already has your node name and API endpoint filled in.
  3. Fill in the <API_KEY>/<API_TOKEN> placeholders with a credential that has BGP_MANAGE capability.
  4. Clone qBGP, drop your downloaded config in, and bring both containers up (needs network_mode: host for gobgp to actually establish eBGP sessions on your real interface):
git clone https://github.com/quaggy-org/qBGP.git && cd qBGP
cp /path/to/your/downloaded/qbgp.yaml qbgp.yaml
cp gobgp.conf.example gobgp.conf     # fill in your real ASN/router-id/neighbors
docker compose up -d

No Docker? ./install.sh installs the qbgp binary + systemd unit directly, but you'll still need GoBGP running separately — see the repo's README.md.

Once running, your node's live status (session state, prefix counts) shows up automatically under My Org — it phones home via a heartbeat, no extra setup needed.

[ AUTONOMOUS AGGREGATION ENGINE ]

SUBNET QUARANTINE & AGGREGATION

Autonomous BGP route promotion aggregating hostile host IPs into parent CIDR blackholes (/24 & /48).

Parent Subnet CIDR IP Family Banned IP Count Subnet Hostility Ratio Aggregation Reason Status Actions
Loading quarantined subnets...