[ GAME SYSTEM OVERVIEW ]
GLOBAL THREAT LEADERBOARD
Hit a high score of 100 points and get automatically null-routed at the BGP edge across participating networks.
🏢 TOP HOSTILE ASNS
High Risk| # | ASN | Network Name | Threat Score |
|---|---|---|---|
| Loading live ASN threat score... | |||
🌍 TOP HOSTILE COUNTRIES
Global Geo| # | Code | Country / Region | Threat Score |
|---|---|---|---|
| Loading country threat data... | |||
⚡ TOP ATTACK VECTORS
Vector Breakdown| # | Vector Category | Reports |
|---|---|---|
| Loading attack vectors... | ||
[ GLOBAL QUERY ENGINE ]
SEARCH & DRILL-DOWN IP INTELLIGENCE
Scan high scores across all autonomous systems and export machine-readable lists
| Player IP | Country | ASN & Network Name | Threat Score | Reporter Status | Actions |
|---|
[ MULTI-TENANT ORGANIZATIONAL CONSOLE ]
My Organization
org-slugManage your team, registered subnets, and invite users with zero user limits
Team Roster (0)
Unlimited Members Supported| Player Name | Role | Level | Action |
|---|
Registered Subnets (0)
Your own known-good ranges (a single /32 up through wide blocks). These are excluded from your own BGP feed and now protected from being banned platform-wide at all — by your own submissions, another org's, or auto-detection.
| CIDR Subnet | Description | Action |
|---|
🔑 API Keys (0)
| Name | Capabilities | Created | Last Used | Action |
|---|
Pending Team Invitations
| Email Address | Role | Shareable Invite Link | Expires | Action |
|---|
⚙️ Organization Defaults & Policy Settings
🚫 Organization Private Blacklist
| CIDR Subnet / IP | Reason | Action |
|---|
🛡️ Automated Carrier Infrastructure Guardrails
Hardened immunity matrix protecting public DNS resolvers (8.8.8.8, 1.1.1.1, Quad9), root name servers (A–M), emergency endpoints, and IXP peering LAN fabrics against accidental blackholing.
| Infrastructure Name | Category | CIDR / Subnet | Description | Protection Status |
|---|
🔗 BGP Peers
Your org's BGP sessions with Quaggy. Manage peers (add/edit/feeds/router config) on the BGP tab.
| Neighbor IP | Local ASN | Remote ASN | Description | Session State |
|---|
🏠 My Self-Hosted BGP Nodes
Register your own qbgp+gobgp instance (running in your own network) so it shows up here with live status, and so its peering IP is selectable in the router config generator.
| Name | Peering IP | Local ASN | Status | Last Heartbeat | Action |
|---|
[ ROUTE-REFLECTOR GRID ]
BGP PEERING SESSIONS
Sync BGP null-route announcements directly to your edge routers
| Neighbor IP | Remote ASN | Export Policy / Communities | Global Feed | Description | Session State | Prefixes (rx/accepted) | Latency | Actions |
|---|
[ DISPUTE RESOLUTION MATRIX ]
IP REMOVAL DISPUTES & VOTING
Submit false-positive removal requests or vote on dispute resolutions for cross-org blocks
| Target IP | Requested By | Reason | Votes (Approve/Reject) | Status | Resolver / Mod | Action |
|---|
🍯 HONEYPOT SENSOR FLEET
Decoy sensors report every touch back here as a scoring event. Being noticed by one of these means you're now a player.
| Sensor | Hostname | Status | Active Ports | Events (24h) | Sessions (24h) | Last Seen | Action |
|---|
🖥️ KUBERNETES MICROSERVICE HEALTH
Live pod status straight from k3s (qk3s01) — phase, restarts, image, and uptime for every Quaggy service.
| Service | Pod | Phase | Ready | Restarts | Image | Started |
|---|
📊 SERVICE METRICS
Live-scraped from each service's own Prometheus endpoint on page load — how qProcessor/qFeeds/qNotifier/qCollector are actually performing right now, not just whether their pod is up.
🏢 ORGANIZATIONS OVERVIEW
Every organization on the platform, one row each — trust tier, members, self-service ranges, custom blacklist entries, BGP peers, active API keys, and most recent report activity.
| Organization | Trust Tier | Report Weight | Members | Ranges | Blacklist Entries | BGP Peers | Active API Keys | Last Activity |
|---|
📡 BGP MESH NODE STATUS
Real-time node status, GoBGP gRPC health, peer connections, error counts, and prefix telemetry, reported by each qbgp instance's own heartbeat.
| Node ID | Microservice | Daemon Status | GoBGP gRPC | Connected Peers | Trying Peers | Errors | Advertised Prefixes | Last Update | Maintenance |
|---|
🌐 BGP Peers by Organization
| Organization | BGP Peers |
|---|
👤 System Users & Credentials
| User ID | Username | Org | Level / Role | API Key | Status |
|---|
System Organizations & Trust Tiers
| Organization Name | Slug | Trust Tier | Report Weight | Members | Subnets | Actions |
|---|
📡 External Threat Intelligence Feed Catalog
Automated ingestion engine (qFeeds) polls third-party threat feeds on a scheduled cycle, applies mandatory security guardrails (reject /0, prefix floors, entry caps), and syncs to Redis for BGP peering export.
| Feed Name | Family | Parser | Refresh | Community | Ingested Entries | Last Fetch | Global Status | Action |
|---|
📦 STIX 2.1 & TAXII 2.1 Outbound Threat Exchange
OASIS Standard STIX 2.1 JSON bundle export & TAXII 2.1 server discovery endpoints for SIEM/SOAR integration (Splunk, QRadar, Sentinel, MISP).
Returns STIX 2.1 JSON bundle of all active corroborated blackhole indicator objects.
OASIS TAXII 2.1 Discovery & Collections envelope API for automated SIEM poll clients.
⚡ Dynamic Platform Scoring & System Configuration
These live parameters control the scoring engine across all running qProcessor nodes without binary restarts.
🛡️ Global Carrier Infrastructure Whitelist
Protects the shared platform blacklist itself — public DNS resolvers, root name servers, emergency endpoints, and IXP peering LAN fabrics can never be blackholed regardless of report volume.
| Infrastructure Name | Category | CIDR / Subnet | Description | Protection Status |
|---|
📜 Admin Audit Trail
Most recent 200Covers the highest-value admin/org-admin mutations (users, org trust tiers, BGP peers, org/global blacklist and whitelist, invites) - not literally every action in the platform.
| When | Actor | Action | Target | Detail |
|---|
[ MULTI-TENANT ALERT DELIVERY ]
NOTIFICATION CHANNELS
Configure real-time threat alert webhooks, Discord/Slack/Mattermost bots, and SMTP email notifications for your organization.
| Scope / Org | Channel Name | Type | Subscribed Events | Status | Actions |
|---|---|---|---|---|---|
| Loading notification channels... | |||||
[ JOIN THE GRID ]
DEPLOYMENT DOCS
Every hostile IP that crosses 100 points gets exiled from the mesh. Here's how to watch it happen on your own network — or feed the machine yourself.
📡 Tier 1 — We Run The Mesh, You Just Connect
Quaggy's own BGP mesh (running on our edge nodes) originates a real-time null-route feed straight from the live scoreboard — the instant an IP hits 100 points, it's announced. Peer your existing router or firewall against it and every one of those exiles gets null-routed at your own edge automatically. No Quaggy software to install — this is standard eBGP.
- Go to My Organization → BGP Peers and click ➕ Add BGP Peer — give it your router's peering IP and your ASN (no ASN of your own? the default private ASN 64512 works fine).
- Click the new peer's ⚙️ Config button, pick your platform — Cisco IOS/IOS-XE, Juniper JunOS, or FRR (this covers UniFi UDM/USG too, since it runs FRR underneath) — and copy the generated config straight into your device.
- Watch the Session State column on that same page flip to
ESTABLISHED. That's it — you're live.
From here you're just watching the game: prefix counts and session health update in real time on the BGP Peers page as players get taken off the board.
📤 Tier 2 — Send Data: Report What's Attacking You
Point qcollector at your own logs (SSH, mail, web server, honeypot, firewall, ...) to report attacks into Quaggy's scoring engine. Every report you send adds to the target's score — enough of them, from enough different sources, and that IP goes on the watch list and, eventually, dies. Since you're already peered in Tier 1, your own reports can come back around as a null-route on your own router.
- Grab an API key/token from My Org → Members (or your own user token under Account Settings).
- Clone and install (Linux, x86_64/arm64/armv7):
git clone https://github.com/quaggy-org/qCollector.git && cd qCollector sudo ./install.sh --api-key YOUR_API_KEY --api-token YOUR_API_TOKEN
This installs the binary, a systemd unit, and a starter
/etc/qcollector/qcollector.yaml with your credentials
filled in. Edit it to add a watcher, e.g.:
watchers:
- name: "ssh_watcher"
file: "/var/log/auth.log"
file_type: "static" # static | rotate | dated
catalogs:
- "ssh" # reuse a built-in rule catalog
Then systemctl restart qcollector. Prefer Docker? The
repo also ships a docker-compose.yaml — see its
README.md for that path.
Built-in catalogs (baked into the binary, no extra download):
ssh,
nginx,
apache,
postfix,
cowrie,
fail2ban,
asterisk,
freeswitch,
opensips,
systemd_auth, and
malware_signatures.
Need something they don't cover? Add a custom rules: block
alongside a catalog in the same watcher — see qCollector's
README.md for the pattern syntax. (Note: the central,
admin-managed "Collector Rules" screen is a work in progress and
isn't populated yet — for now, custom patterns live in your own
qcollector.yaml, not a shared server-side list.)
🛰️ Tier 3 — Self-Hosted BGP: Run The Mesh Node Yourself
Don't have a router that speaks BGP? Run Quaggy's own qbgp + gobgp pair yourself instead of peering existing hardware — it's the exact same two containers our own edge nodes run.
- Register your node under My Org → My Self-Hosted BGP Nodes (peering IP, local ASN).
- Click 📄 qbgp.yaml on your new node to download its config — this already has your node name and API endpoint filled in.
- Fill in the
<API_KEY>/<API_TOKEN>placeholders with a credential that hasBGP_MANAGEcapability. - Clone qBGP, drop your downloaded config in, and bring both containers up (needs
network_mode: hostfor gobgp to actually establish eBGP sessions on your real interface):
git clone https://github.com/quaggy-org/qBGP.git && cd qBGP cp /path/to/your/downloaded/qbgp.yaml qbgp.yaml cp gobgp.conf.example gobgp.conf # fill in your real ASN/router-id/neighbors docker compose up -d
No Docker? ./install.sh installs the
qbgp binary + systemd unit directly, but you'll still
need GoBGP running separately —
see the repo's README.md.
Once running, your node's live status (session state, prefix counts) shows up automatically under My Org — it phones home via a heartbeat, no extra setup needed.
[ AUTONOMOUS AGGREGATION ENGINE ]
SUBNET QUARANTINE & AGGREGATION
Autonomous BGP route promotion aggregating hostile host IPs into parent CIDR blackholes (/24 & /48).
| Parent Subnet CIDR | IP Family | Banned IP Count | Subnet Hostility Ratio | Aggregation Reason | Status | Actions |
|---|---|---|---|---|---|---|
| Loading quarantined subnets... | ||||||