Cyber Threat Intelligence
What does the underground know about you? We know it before it's for sale.
General Intels unifies leaked credentials and cookies, underground forums, actor chatter and vulnerability intelligence in one console and one API. Continuous collection across underground sources, in the languages they're actually spoken.
Ingestion Vectors
Indicator Ingested
06:10:31URL 123.11.x.x · 2 indicators
Indicator Ingested
06:10:31URL 27.202.x.x · 2 indicators
Indicator Ingested
06:10:31URL 27.202.x.x · 2 indicators
Indicator Ingested
06:10:31URL 222.127.x.x · 2 indicators
12B+
leaked records indexed
840+
underground sources monitored in their native languages
387K
CVEs enriched with EPSS, KEV & exploit status
7 min
typical minutes from log batch to searchable index
The attack doesn't start at your perimeter. Neither should your visibility.
Three places where conventional monitoring finds out last, and where we live.
“Your customers are your breach notification.”
By the time you notice a credential dump, it has already been tried. Sherlog catches the stealer log in the channel where it's first collected, so the exploitation window closes before it opens.
“The underground closes its deals where your feeds aren't looking.”
Telegram channels, underground forums, Jabber negotiations: the venues rebadged feeds never reach are our primary sources.
“Your CVE list is long. Your patch window isn't.”
Cvekit merges EPSS, KEV, exploit maturity and ransomware linkage into one signal: what you should actually patch this week, with the evidence attached.
Nine windows into the attacker's ecosystem
Each module is one window. Together they show the leak, the market, the conversation and the actor in a single pane.
Sherlog
Credential & Cookie Intelligence
When an employee's password lands in a stealer log, you know before it's for sale.
EXPLOREDragnet
Underground Content Intelligence
If the underground is talking about you, we have the record.
EXPLORECvekit
Vulnerability Intelligence
Which CVEs actually burn? Prioritize with evidence.
EXPLOREMalveine
Threat Intel Console & Feeds
Intelligence that arrives as rules your stack can run.
EXPLOREJabbernaut
Messaging Intelligence · XMPP
Forums are the storefront; the real deals close on Jabber. We're there.
EXPLORETelepathy
Messaging Intelligence · Telegram
Half the market moved to Telegram. Searching it should not mean scrolling it.
EXPLOREGuildwire
Messaging Intelligence · Discord
Discord keeps no archive you can read. This one you can.
EXPLOREBaitback
Impersonation Defense
Someone is building a fake you. Find the impostor before your staff answers to it.
EXPLORESours
Operator Surveillance
While the attacker hunts for victims, you watch the attacker. We explain the details in a demo, and you'll understand why there.
CLOSED BRIEFINGEight of the nine are open on every tier: what a tier sets is how hard you can push the API, not which modules you get. The ninth is Sours, above, and it opens in a closed briefing. See what each tier includes . It is published, not quoted.
From a dark channel to your firewall, in three steps
LIVE PIPELINE
continuous · 24/7The underground
01Collect
Chat channels, forums, jabber rooms, stealer logs, marketplaces, paste drops, CVE advisories, ransomware leak sites. We run the underground collection ourselves; none of it is a rebadged third-party feed. The advisory and indicator sources are public ones, read directly.
The engine
02Index
Full-text search across every source, IoC extraction, enrichment. A log batch becomes a searchable, correlated record in minutes.
Your SOC
03Operationalize
Console for analysts, X-API-Key for automation, and STIX 2.1 / TAXII 2.1 / Sigma / EDL delivery for the SOC.*
Collection velocity · last 7 days
+1.7M artefacts
captured, parsed and made searchable over the trailing week · one event is one artefact
1.3M messages
discord servers
165K posts
forums
61.2K messages
telegram channels
38.6K devices
stealer logs
37.8K messages
jabber rooms
35.3K indicators
indicators
2.1K records
cve advisories
FIGURES FLOORED · NEVER ROUNDED UP
* Feed delivery is a Enterprise-tier capability.
Intelligence that speaks your SOC's native protocols
No connector marketplace, no professional-services quote. We publish in the open standards your stack already ingests, so the integration is a URL and a key.*
DELIVERY LAYER
hover a rail · the stacks it feeds light up
one URL · one keySTIX 2.1
objects & relationships
TAXII 2.1
subscription delivery
Sigma
detection rules
EDL
firewall blocklists
REST + X-API-Key
everything else
* STIX/TAXII/Sigma/EDL delivery ships with the Enterprise tier. Product names belong to their owners; no partnership implied.
Everyone watches the data. We also watch who's hunting.
The Hunt Scene is the public, fully anonymized shadow of Sours: the shape of attacker attention, refreshed weekly. No competitor can print this chart, because they don't have the source.
Across the underground, threats speak in their own words, and nobody was listening. We were founded to listen: on the forum, in the channel, on Jabber.Read the manifesto
SOURS SIGNAL · AGGREGATED
2026-W35 · anonymizedHunters are converging
of this week's hunting landed on targets that two or more operators were working at once: the crowd closing on the same victim.
Hunt success rate
62%
of hunts found their mark
Operator persistence
3 targets
worked by the median hunter · 1 in 7 worked 10+
k-anonymized
1-week delay
shares, not volumes
What we learn in the underground, we publish
Sherlog · 2 min
Anatomy of a stealer log: from infection to sale in 31 hours
We followed a single log batch from the moment it hit a Telegram channel to the moment its credentials were tested against a corporate VPN. The window is smaller than you think.
Sherlog · 1 min
Session cookies outlive password resets: measuring the window
Across a sample of stealer records, we measured how long stolen session cookies remained valid after the victim's password was changed. The median was not minutes.
Cvekit · 2 min
EPSS + KEV + exploit maturity: a prioritization formula that survives contact
CVSS tells you what could hurt. Exploitation probability, confirmed exploitation and exploit maturity together tell you what is hurting, and they shrink the patch queue by an order of magnitude.
FREE INDEX · CVEKIT.COM
CVE Library
EPSS with its full score history, KEV membership and exploit maturity, on a permanent page per CVE. Free, and with no account.
FREE TOOL · FIELD GUIDE
Underground Lexicon
The terms the markets use daily, translated for defenders, each with why it should change what you do.
the CVE library is the live Cvekit index, on its own domain · lexicon curated by the research desk
The questions that open every first call
Answered here, so the call can start somewhere more useful.
All 18 questions , including the ones we'd rather you didn't ask.
Your competitors will learn about the leak from the invoice.
Learn about it from the log batch.
NDA-friendly briefings · global coverage · no slideware