Threat Intelligence · Monitoring · Scanning

Threat intelligence for all needs.

RADECTI watches your attack surface, brand and domains, then correlates what it finds in a real intelligence platform. You pull a clean feed into your SIEM and scan files and IOCs on demand. Analyst-led managed detection and DFIR are coming.

How we work MITRE ATT&CK mapped Evidence-backed findings No public sandbox uploads GDPR-aligned
The RADECTI threat feed in the customer console: a coverage panel listing lookalike and typosquat domains (3 findings), ransomware leak sites, dark-web mentions, external attack surface (2 findings) and email spoofability, each with what it checks and when it last ran.
A file-scan verdict card: Invoice_2026-07.pdf returned Undetermined — no known-bad signature matched — across 4 engines, with its IOCs published to your feed.
107k
Actionable indicators
added in the last 30 days, marked for detection
16
Curated intel feeds
quality over raw feed count
36.6M
Total corpus
built since 2021, decay-scored, deduplicated
9/day
New events ingested
rolling 30-day average

Live figures from our own platform, last updated 2026-09-14.

Two ladders, one engine

An analyst and a business are not buying the same thing.

So we price them differently. The analysis engine is the same; what changes is whether it runs against your own estate.

Built and running

Researcher

€25 / month
incl. VAT

Malware analysts and security researchers, paying out of their own pocket.

  • Static analysis — PE, ELF, .NET, scripts, Office, PDF, LNK, archives
  • Reverse-engineering workspace — decompiler, functions, cross-references
  • YARA family matching against 12,390 curated rules, run on our own hardware
  • Tiered verdict with the evidence chain that produced it
  • Coverage manifest — what was parsed, what was skipped, and why
See the full ladder
Built and running

Brand Watch

€149 / month
excl. VAT

One business that also does its own analysis — one domain, one brand.

  • Everything in Researcher
  • 1,000 files a day — twenty times the Researcher allowance
  • Results kept 90 days
  • Lookalike and typosquat domain monitoring, with evidence captured
  • External attack surface — subdomains from Certificate Transparency, plus services, TLS and exposures on domains you verify with a DNS record (two minutes)
See the full ladder

Six plans in total: three for one analyst, three for a business. Compare them all. Checkout is not open yet.

How it works

From monitoring to your screen.

The same engine powers every plan. What differs is whether it watches your own estate, and what happens after a finding fires.

1 · We monitor

Attack-surface and typosquat monitors continuously watch your domains, hosts and brand against real sources, plus nightly dark-web and ransomware leak-site monitoring. Credential-leak lookup is coming.

2 · We correlate

Findings land in our threat-intelligence platform, scoped to you alone, deduplicated and confidence-graded. No noise dump.

3 · You get it your way

Today: pull a clean feed into your SIEM, scan and look up IOCs on demand. Coming soon (Enterprise): our analysts turn findings into a managed case and drive the response.

Beyond the feed

Available today, with a managed team on the way.

Threat Intelligence

Curated, primary-source intelligence and brand monitoring, graded for confidence before it reaches you.

Attack Surface & Brand

Every host, service and exposure the internet can see on your domains, plus lookalike-domain detection, with the evidence captured. Ransomware leak-site exposure is watched nightly and reported narrowly: the victim organisation, the source, and the date first seen. We never republish the contents of a dump.

Scanning & IOC Lookup

On-demand analysis of IPs, domains, URLs and files: static inspection, hash and IOC reputation lookups, and urlscan screenshots.

Static Malware Analysis

Static analysis of suspicious files with technical reporting and YARA detection-rule drafts. Dynamic sandbox coming soon

Detection & case management On the roadmap

A hardened SIEM with rules mapped to MITRE ATT&CK, feeding cases and tickets your own team works. We supply the software and the intelligence. Staffed monitoring is not part of this tier.

DFIR, IR & Threat Hunting Coming soon

Remote triage, memory and disk forensics, incident response and hypothesis-driven hunts, on our Enterprise roadmap.

Why RADECTI

Built for small teams and independent analysts.

Serious threat intelligence has usually meant an annual contract and a sales cycle. We put a real feed within reach of a single subscription, priced openly. A human-led Enterprise tier is in build, for teams that want experienced people on the case.

Self-serve by design

Built to be used without a sales cycle. Request access and we set you up. No procurement, no lock-in.

EU-hosted, no US subprocessors

Your data is stored and processed on infrastructure we run in the EU, and no part of the pipeline hands it to a US provider — so there is no CLOUD Act exposure to work around. GDPR-aligned handling by design. NIS2 incident reporting is planned for our Enterprise tier.

Analyst-led (on the roadmap)

The planned Enterprise tier puts an experienced analyst on the case. Coming soon

Start with the feed. A managed team is on the way.

Get threat intelligence flowing into your stack today, and register interest in the analyst-led Enterprise tier we're building.