Traffic Origin

Prev Next

Traffic Origin shifts cybersecurity from reactive to proactive by exposing the true upstream origins of IP traffic, even when adversaries hide behind residential proxies, VPNs, laptop farms, or other obfuscation techniques.

Derived from real-world detection events, it unmasks the masking layer used by state-sponsored actors and cybercriminals. For a given indicator, Traffic Origin can reveal:

  • Upstream countries and routing sources connected to an IP

  • High-confidence risk indicators, such as traffic routed from sanctioned or high-risk regions (for example, DPRK, Iran, or Russia) via residential proxies

  • Full contextual visibility in the Silent Push platform, correlating a benign surface flag (for example, US or UK) with hidden high-risk upstream links

Access Traffic Origin data in Total View

Traffic Origin is integrated into the Total View section of the Silent Push platform. For any supported indicator, there are two complementary views: one for quick triage and one for in-depth analysis.

Highlights section — quick glance

In the upper-right corner of the Highlights panel in Total View, a compact Traffic Origin widget lists upstream countries where the IP was detected, ordered by detection rate (highest to lowest).

Use this widget when you need an immediate answer: does this IP only look local, or is there upstream activity from unexpected regions behind a proxy, VPN, or residential obfuscation layer?

Traffic Origin tab — full details

For a full investigation, open the dedicated Traffic Origin tab in Total View. This tab shows the indicator's historical detection record in map and table views.

Use the tab when you need per-detection context: first seen and last seen times, coordinates, country, user agent, and the ability to trace movement patterns such as IP hopping, botnet activity, or APT infrastructure.

Note

The Traffic Origin tab is visible only if your organization has Traffic Origin enabled. Zooming the map beyond level 10 requires GeoIP permissions.

How to open both views

  1. On the Silent Push landing page, enter a domain, IPv4/IPv6 address, ASN, or URL in the search bar.

  2. Press Enter or click Total View.

  3. In Total View:      

    • Check the upper-right corner of the Highlights section for the Traffic Origin country summary.

    • Click the Traffic Origin tab in the tab bar (next to Threat Feeds, Infrastructure Variance, and other Total View tabs) for the map and table.

Optional: Traffic Origin in Threat Check

Enterprise workflows can also validate an IP against Traffic Origin through Threat Check. That path returns whether traffic from the IP has been detected in specified countries and is designed for high-volume lookups, not map investigation. Use Total View when you need the visual record; use Threat Check when you need a fast allow/deny or country-hit check.

Why Traffic Origin matters

Static IP geolocation is not enough. Adversaries routinely use dynamic IPs, proxies, and VPNs to mask origin. Traffic Origin helps teams:

  • Detect suspicious activity. Identify whether an IP is associated with unauthorized or sanctioned regions, including risks such as data exfiltration or compliance violations.

  • Enforce policy. Confirm that activity stays inside approved operational areas and support geofencing and access-control decisions.

  • Strengthen investigations. Give incident responders evidence they can correlate with other Silent Push indicators.

  • Improve threat intelligence. Surface patterns such as country hopping that can indicate botnets, phishing infrastructure, or APTs.

For example, if your organization does not operate in certain regions, Traffic Origin detections in those regions can justify an immediate review even when the surface IP appears domestic.

Practical benefits

Used inside Total View, Traffic Origin helps reduce false confidence in “clean” geo flags, prioritize high-risk detections, and support regulatory requirements such as geofencing, export controls, and identity-assurance workflows (KYC, KYE, AML). It is most valuable for SOC, fraud, and compliance teams that handle global traffic and remote access.