Real intelligence today. A managed team on the roadmap.
The self-serve platform is live now for SMEs and individuals. The analyst-led, managed side, covering MDR, DFIR and incident response, is what we're building next.
What you can use today.
Threat intelligence feed
Curated, primary-source findings for your domains and brand, confidence-graded and deduplicated before they reach you.
- Pull into your SIEM or SOAR
- Scoped to your tenant alone
- Exportable reports on demand
IOC lookup
On-demand reputation and context for an IP, domain, URL or hash, drawn from our own collection and curated feeds.
- Answer in seconds from cache
- Full analysis when it is new
- Available over the API
External attack surface
A continuous outside-in view of your domains: the hosts you forgot and the services you did not mean to expose.
- Subdomains from certificate transparency
- Exposed files, end-of-life software, weak headers
- TLS certificate expiry and validity
Lookalike and typosquat domains
Domains registered to impersonate yours, reported only once they actually exist and resolve.
- DNS, WHOIS and MX evidence
- Screenshot of what the domain serves
- Free public check available
Dark-web and leak-site monitoring
Nightly crawls over Tor for your brand and domains across dark-web sources and ransomware leak sites.
- Victim, source and date first seen
- Tracked by gang, not in isolation
- We never retrieve or show dump contents
Static malware analysis
Submit a file and get format and packer identification, reputation and hash lookups, YARA family matching and a draft rule.
- No public sandbox upload, ever
- Technical report you can hand on
- Dynamic detonation is on the roadmap
What we are building next.
Planned for the Enterprise tier. None of it is for sale yet. Talk to us if you want to shape it.
Managed detection and response
Analyst review on a hardened SIEM with rules tuned to your environment and mapped to MITRE ATT&CK.
Incident response and DFIR
Remote triage, memory and disk forensics and root-cause analysis, on a retainer or ad hoc.
Threat hunting
Hypothesis-driven hunts across your telemetry, with the detection rules left behind afterwards.
Start with the self-serve platform today, or register interest in the managed Enterprise tier.