Cyber Threat Intelligence

What does the underground know about you? We know it before it's for sale.

General Intels unifies leaked credentials and cookies, underground forums, actor chatter and vulnerability intelligence in one console and one API. Continuous collection across underground sources, in the languages they're actually spoken.

Ingestion Vectors

Underground forums165K posts · 10%
XMPP / Jabber37K messages · 2%
Telegram channels61K messages · 4%
Discord servers1M messages · 82%
Stealer logs38K devices · 2%
Source Classes5 of 8 Live
Indexed · 7d1.6M
Live Telemetry Feed UTC

Indicator Ingested

06:10:31

URL 123.11.x.x · 2 indicators

Indicator Ingested

06:10:31

URL 27.202.x.x · 2 indicators

Indicator Ingested

06:10:31

URL 27.202.x.x · 2 indicators

Indicator Ingested

06:10:31

URL 222.127.x.x · 2 indicators

DECAY5.8K indicators decaying out of the feed in 24hINFRA2.0K live indicators concentrated on a single hosting ASGEOmalicious infrastructure seen in 13 countries · US · RU · CN leading · +7 moreTTPT1071 most-observed technique this week · 151 indicatorsSCORE1% of active indicators at confidence ≥80ROOMS6.1K rooms watched · 219K messages indexedEPSS50 CVEs jumped in EPSS this week · biggest +0.54KEVCVE-2026-85046 added to CISA KEV · CVSS 8.8CHATTER4.9K underground posts indexed todayNEW+1.1K indicators scored today · 2 new campaigns

12B+

leaked records indexed

840+

underground sources monitored in their native languages

387K

CVEs enriched with EPSS, KEV & exploit status

7 min

typical minutes from log batch to searchable index

01The three blind spots

The attack doesn't start at your perimeter. Neither should your visibility.

Three places where conventional monitoring finds out last, and where we live.

“Your customers are your breach notification.”

By the time you notice a credential dump, it has already been tried. Sherlog catches the stealer log in the channel where it's first collected, so the exploitation window closes before it opens.

“The underground closes its deals where your feeds aren't looking.”

Telegram channels, underground forums, Jabber negotiations: the venues rebadged feeds never reach are our primary sources.

“Your CVE list is long. Your patch window isn't.”

Cvekit merges EPSS, KEV, exploit maturity and ransomware linkage into one signal: what you should actually patch this week, with the evidence attached.

02The platform

Nine windows into the attacker's ecosystem

Each module is one window. Together they show the leak, the market, the conversation and the actor in a single pane.

Eight of the nine are open on every tier: what a tier sets is how hard you can push the API, not which modules you get. The ninth is Sours, above, and it opens in a closed briefing. See what each tier includes . It is published, not quoted.

03How it works

From a dark channel to your firewall, in three steps

LIVE PIPELINE

continuous · 24/7
THE UNDERGROUND · 840+ SOURCESNATIVE LANGUAGESYOUR SOCNATIVE PROTOCOLS01stealer logsdevices02forumsposts03cve advisoriesrecords04indicatorsindicators05jabber roomsmessages06discord serversmessages07telegram channelsmessages08marketplaceslistings09paste dropsdrops10leak sitesvictimsCONSOLEanalystsliveconsole.generalintels.comX-API-KEYautomationon demand/sherlog/leak/searchTAXII · EDLsoc feedspoll · 5 min/taxii2/{root}/collectionsGI ENGINEPARSE · NORMALIZE · DEDUPE · ENRICH · CORRELATE
THE UNDERGROUND · 840+ SOURCES · NATIVE LANGUAGESYOUR SOC · NATIVE PROTOCOLS01stealer logsdevices02forumsposts03cve advisoriesrecords04indicatorsindicators05jabber roomsmessages06discord serversmessages07telegram channelsmessages08marketplaceslistings09paste dropsdrops10leak sitesvictimsCONSOLEanalystsliveconsole.generalintels.comX-API-KEYautomationon demand/sherlog/leak/searchTAXII · EDLsoc feedspoll · 5 min/taxii2/{root}/collectionsGI ENGINEPARSE · NORMALIZE · DEDUPE · ENRICH · CORRELATE

The underground

01Collect

Chat channels, forums, jabber rooms, stealer logs, marketplaces, paste drops, CVE advisories, ransomware leak sites. We run the underground collection ourselves; none of it is a rebadged third-party feed. The advisory and indicator sources are public ones, read directly.

The engine

02Index

Full-text search across every source, IoC extraction, enrichment. A log batch becomes a searchable, correlated record in minutes.

Your SOC

03Operationalize

Console for analysts, X-API-Key for automation, and STIX 2.1 / TAXII 2.1 / Sigma / EDL delivery for the SOC.*

Collection velocity · last 7 days

+1.7M artefacts

captured, parsed and made searchable over the trailing week · one event is one artefact

1.3M messages

discord servers

165K posts

forums

61.2K messages

telegram channels

38.6K devices

stealer logs

37.8K messages

jabber rooms

35.3K indicators

indicators

2.1K records

cve advisories

* Feed delivery is a Enterprise-tier capability.

04Runs in your stack

Intelligence that speaks your SOC's native protocols

No connector marketplace, no professional-services quote. We publish in the open standards your stack already ingests, so the integration is a URL and a key.*

DELIVERY LAYER

hover a rail · the stacks it feeds light up

one URL · one key
General Intelscollection · index · delivery publishing
01

STIX 2.1

objects & relationships

bundle.json · 412 objectson confirm
02

TAXII 2.1

subscription delivery

GET /taxii2/{root}/collections/{id}/objectspoll · 5 min
03

Sigma

detection rules

GET /sigma/{campaign_id}/{target}on change
04

EDL

firewall blocklists

GET /delivery/edl/network-blocklistttl · 15 min
05

REST + X-API-Key

everything else

curl -H "X-API-Key: ●●●" /sherlog/leak/search?q=on demand
YOUR SOCsiem · firewall · soarno connector required
Splunk
TAXII · Sigma
Microsoft Sentinel
TAXII · Sigma
IBM QRadar
TAXII · Sigma
Elastic Security
Sigma · REST
MISP
STIX
OpenCTI
TAXII · STIX
TheHive
REST
Cortex XSOAR
TAXII · REST
Palo Alto NGFW
EDL
Fortinet FortiGate
EDL

* STIX/TAXII/Sigma/EDL delivery ships with the Enterprise tier. Product names belong to their owners; no partnership implied.

05A signal no one else has

Everyone watches the data. We also watch who's hunting.

The Hunt Scene is the public, fully anonymized shadow of Sours: the shape of attacker attention, refreshed weekly. No competitor can print this chart, because they don't have the source.

Across the underground, threats speak in their own words, and nobody was listening. We were founded to listen: on the forum, in the channel, on Jabber.
Read the manifesto

SOURS SIGNAL · AGGREGATED

2026-W35 · anonymized

Hunters are converging

20% -2% vs last wk
OPERATOR AOPERATOR BTOGETHER · 20%THIS WEEK'S HUNTING · 100%APART · 80%

of this week's hunting landed on targets that two or more operators were working at once: the crowd closing on the same victim.

Hunt success rate

62%

of hunts found their mark

Operator persistence

3 targets

worked by the median hunter · 1 in 7 worked 10+

k-anonymized

1-week delay

shares, not volumes

06From the research desk

What we learn in the underground, we publish

All research
07Before you ask

The questions that open every first call

Answered here, so the call can start somewhere more useful.

All 18 questions , including the ones we'd rather you didn't ask.

Your competitors will learn about the leak from the invoice.

Learn about it from the log batch.

NDA-friendly briefings · global coverage · no slideware