Everything below was collected by us or read from its publisher. None of it was bought.
A threat-intel vendor's scale claim is worth what it is willing to break down. So here is the pipeline's output by source class: what counts as one event in each, which eight came off collectors we run and which two are open catalogues we read at source, which classes are still expanding, and further down the things we deliberately refuse to count.
1,731,980
events collected across 7 live source classes, trailing week. One event is one artefact: a message, a post, a listing or an infected device. It is not a row in a database and not a credential. Classes still being brought online are listed below, marked, and counted as zero here.
1M
Discord server messages
Last 7 days
One message in a monitored server, channel or thread. A file counts once, with the message that carried it, and stays retrievable after that message is gone.
FEEDS GUILDWIRE165K
Underground forum posts
Last 7 days
One post or reply on a monitored forum, captured with its screenshot and attachments, and kept after deletion.
FEEDS DRAGNET61K
Telegram channel messages
Last 7 days
One message in a monitored channel, group or megagroup. Forwards of the same message count once, against the place we first read it.
FEEDS TELEPATHY38K
Stealer-log devices
Last 7 days
One infected device, not one credential. A single device yields dozens of credentials and hundreds of cookies, so this counts machines, not rows.
FEEDS SHERLOG37K
XMPP / Jabber messages
Last 7 days
One message in a monitored room. This is the layer where the deal closes, and the one almost nobody else indexes.
FEEDS JABBERNAUT35K
Threat indicators
Last 7 days
One distinct indicator: an address, domain, URL or file hash published as malicious. The same indicator carried by several publishers counts once, against the first time we read it. Confidence scoring, ASN and MITRE mapping and decay ride on top and are not counted here.
FEEDS MALVEINE2K
CVE records
Last 7 days
One vulnerability record. Counts newly published CVEs; the enrichment stream (EPSS moves, KEV additions) rides on top and is not counted here.
FEEDS CVEKITNot yet collected
Marketplace listings
One listing on a monitored market: access, data, cards, infrastructure. Re-listings of the same goods count once.
FEEDS DRAGNETNot yet collected
Paste-site drops
One paste containing credentials, keys or leaked records. Empty and duplicate pastes are discarded before counting.
FEEDS SHERLOGNot yet collected
Ransomware victim listings
One victim entry on a leak site, captured with its countdown and proof pack, and archived when the crew pulls it.
FEEDS DRAGNETCounts are floored to the leading unit and taken off the pipeline's own records. Bars are scaled to the largest live class, not to each other. Classes marked "expanding" are being brought online and are not yet counted.
What we refuse to count
Every vendor's collection figure is a choice about what to include. Inflating it is trivial and nobody audits it, so the only meaningful disclosure is the exclusion list.
Recycled combolists
A combolist assembled from other people's logs is deduplicated against the primary records it was built from, and it never inflates a stealer count. Most vendors quote the combined number, because it is the bigger one.
The same listing, re-posted
Access brokers re-advertise unsold goods and ransomware crews re-publish pulled victims. Repeats are collapsed onto the original record, which keeps the archive honest and the counter boring.
Bot noise and channel spam
Monitored channels are full of automated advertising. It is filtered out before counting rather than after, because a big number made of spam is a lie that is technically true.
Anything we bought
Nothing on this page was licensed from a broker. Eight of the ten classes came off collectors we run. The other two, the vulnerability records and the threat indicators, are open catalogues: published by other people, read free and directly from them rather than resold to us through anybody. That is the point of publishing any of it.
These are our numbers.
Ask your current vendor to break down theirs.
NDA-friendly briefings · global coverage · no slideware