01

signals / honeypot fleet

Telescope

A live feed from honeypots distributed across the globe.

Passive collection from a worldwide fleet of honeypots. Every scan, exploit attempt, credential probe, and payload that lands on one is captured, geolocated, deduplicated, and streamed in real time. Query by source IP, ASN, port, TTP, or payload hash — or subscribe to the raw event firehose.

Coming Soon
02

signals / irc + telegram surveillance

Eagle Eye

Continuous world-wide reconnaissance across public IRC and Telegram.

Wire-tap-grade collection over the global IRC constellation and the public Telegram surface. Every network, every channel, every group, every nick and handle. Cross-referenced identities, message archives, join/part and add/leave telemetry — indexed, searchable, and updated in real time.

Coming Soon
03

infrastructure / discovery

DNS Map

The most comprehensive DNS discovery graph on the internet.

Passive + active resolution across the whole namespace. TLD-wide walking, zone-transfer fallout, wildcard demolition, CT-log fusion, and per-record temporal history. Query by name, IP, ASN, or fingerprint.

Coming Soon
04

ip classification engine

ICE

Context for every IP address on the internet.

Bogons, hosting, residential, mobile carrier, corporate, government, exit nodes, sinkholes, scanners, honeypots — a live classification lattice for the entire IPv4 and IPv6 space, delivered as a queryable service and bulk exports.

Coming Soon
05

controlled / research access

SpooferGate

Vetted-only tunnel for source-spoofed packets — research use.

A private, audited egress path for network researchers who need to send packets with non-owned source addresses. Strictly for measurement, DDoS defense R&D, and academic study. Application, review, and legal-use agreement required.

Coming Soon
06

egress / rotating pool

Proxy Revolver

Rotating outbound IPs from a constantly refreshing pool.

Live-updated pool of exit addresses across geographies and ASNs. HTTP, HTTPS, SOCKS5. Sticky sessions optional. Rotation strategy per key. Health-checked, jurisdiction-filtered, and self-hosted end-to-end.

Coming Soon
07

reference / log enrichment

PortMap

Every port, every default, every service. Free forever.

The comprehensive dictionary of TCP/UDP ports: IANA registrations, real-world usage, vendor defaults, protocol fingerprints, and CVE cross-references. Ship as JSON, CSV, or SQLite for drop-in log enrichment.

Coming Soon
08

routing / real-time anomaly

BGP Watchdog

Live BGP surveillance and hijack detection, visualized.

Streamed from a global route-collector mesh. Real-time origin AS changes, MOAS conflicts, sub-prefix hijack alerts, and unusual path-vector shifts — plotted on an interactive AS-topology map with historical replay.

Sneak Peek
09

breach / stealer log query

StealCity

Search stealer logs and infostealer dumps for your identifiers.

Aggregated corpus of infostealer output, credential dumps, and paste-site leakage — indexed by email, domain, and credential fingerprint. Query if your accounts or brand appear. Deletion assistance for verified owners.

Coming Soon
10

offense / distributed reconnaissance

HAVOC

A globally distributed platform for wide-surface reconnaissance.

Fan-out worker fleet for port scans, DNS enumeration, HTTP probing, ICMP measurement, traceroute, MTR, and TLS interrogation — sharded across regions, autoscaled on Spot, and streamed back to a single command center. Launch a job from the UI or the API, watch it tile out across dozens of workers, and pull the results as they land.

Coming Soon
11

signals / dns honeypot fleet

Blackhole

A swarm of DNS honeypots for open-resolver research and threat intel.

Distributed sinkhole authoritative + resolver honeypots watching for open-resolver abuse, cache-poisoning attempts, spoofed-source floods, and reflection-amplification staging. Every query is captured with source IP, EDNS fingerprint, timing, and payload — cross-referenced with known campaigns and streamed as a live threat-intel feed.

Coming Soon