signals / honeypot fleet
Telescope
A live feed from honeypots distributed across the globe.
Passive collection from a worldwide fleet of honeypots. Every scan, exploit attempt, credential probe, and payload that lands on one is captured, geolocated, deduplicated, and streamed in real time. Query by source IP, ASN, port, TTP, or payload hash — or subscribe to the raw event firehose.
Coming Soon →signals / irc + telegram surveillance
Eagle Eye
Continuous world-wide reconnaissance across public IRC and Telegram.
Wire-tap-grade collection over the global IRC constellation and the public Telegram surface. Every network, every channel, every group, every nick and handle. Cross-referenced identities, message archives, join/part and add/leave telemetry — indexed, searchable, and updated in real time.
Coming Soon →infrastructure / discovery
DNS Map
The most comprehensive DNS discovery graph on the internet.
Passive + active resolution across the whole namespace. TLD-wide walking, zone-transfer fallout, wildcard demolition, CT-log fusion, and per-record temporal history. Query by name, IP, ASN, or fingerprint.
Coming Soon →ip classification engine
ICE
Context for every IP address on the internet.
Bogons, hosting, residential, mobile carrier, corporate, government, exit nodes, sinkholes, scanners, honeypots — a live classification lattice for the entire IPv4 and IPv6 space, delivered as a queryable service and bulk exports.
Coming Soon →controlled / research access
SpooferGate
Vetted-only tunnel for source-spoofed packets — research use.
A private, audited egress path for network researchers who need to send packets with non-owned source addresses. Strictly for measurement, DDoS defense R&D, and academic study. Application, review, and legal-use agreement required.
Coming Soon →egress / rotating pool
Proxy Revolver
Rotating outbound IPs from a constantly refreshing pool.
Live-updated pool of exit addresses across geographies and ASNs. HTTP, HTTPS, SOCKS5. Sticky sessions optional. Rotation strategy per key. Health-checked, jurisdiction-filtered, and self-hosted end-to-end.
Coming Soon →reference / log enrichment
PortMap
Every port, every default, every service. Free forever.
The comprehensive dictionary of TCP/UDP ports: IANA registrations, real-world usage, vendor defaults, protocol fingerprints, and CVE cross-references. Ship as JSON, CSV, or SQLite for drop-in log enrichment.
Coming Soon →routing / real-time anomaly
BGP Watchdog
Live BGP surveillance and hijack detection, visualized.
Streamed from a global route-collector mesh. Real-time origin AS changes, MOAS conflicts, sub-prefix hijack alerts, and unusual path-vector shifts — plotted on an interactive AS-topology map with historical replay.
Sneak Peek →breach / stealer log query
StealCity
Search stealer logs and infostealer dumps for your identifiers.
Aggregated corpus of infostealer output, credential dumps, and paste-site leakage — indexed by email, domain, and credential fingerprint. Query if your accounts or brand appear. Deletion assistance for verified owners.
Coming Soon →offense / distributed reconnaissance
HAVOC
A globally distributed platform for wide-surface reconnaissance.
Fan-out worker fleet for port scans, DNS enumeration, HTTP probing, ICMP measurement, traceroute, MTR, and TLS interrogation — sharded across regions, autoscaled on Spot, and streamed back to a single command center. Launch a job from the UI or the API, watch it tile out across dozens of workers, and pull the results as they land.
Coming Soon →signals / dns honeypot fleet
Blackhole
A swarm of DNS honeypots for open-resolver research and threat intel.
Distributed sinkhole authoritative + resolver honeypots watching for open-resolver abuse, cache-poisoning attempts, spoofed-source floods, and reflection-amplification staging. Every query is captured with source IP, EDNS fingerprint, timing, and payload — cross-referenced with known campaigns and streamed as a live threat-intel feed.
Coming Soon →