Collection

Everything below was collected by us or read from its publisher. None of it was bought.

A threat-intel vendor's scale claim is worth what it is willing to break down. So here is the pipeline's output by source class: what counts as one event in each, which eight came off collectors we run and which two are open catalogues we read at source, which classes are still expanding, and further down the things we deliberately refuse to count.

1,731,980

events collected across 7 live source classes, trailing week. One event is one artefact: a message, a post, a listing or an infected device. It is not a row in a database and not a credential. Classes still being brought online are listed below, marked, and counted as zero here.

1M

Discord server messages

Last 7 days

One message in a monitored server, channel or thread. A file counts once, with the message that carried it, and stays retrievable after that message is gone.

FEEDS GUILDWIRE

165K

Underground forum posts

Last 7 days

One post or reply on a monitored forum, captured with its screenshot and attachments, and kept after deletion.

FEEDS DRAGNET

61K

Telegram channel messages

Last 7 days

One message in a monitored channel, group or megagroup. Forwards of the same message count once, against the place we first read it.

FEEDS TELEPATHY

38K

Stealer-log devices

Last 7 days

One infected device, not one credential. A single device yields dozens of credentials and hundreds of cookies, so this counts machines, not rows.

FEEDS SHERLOG

37K

XMPP / Jabber messages

Last 7 days

One message in a monitored room. This is the layer where the deal closes, and the one almost nobody else indexes.

FEEDS JABBERNAUT

35K

Threat indicators

Last 7 days

One distinct indicator: an address, domain, URL or file hash published as malicious. The same indicator carried by several publishers counts once, against the first time we read it. Confidence scoring, ASN and MITRE mapping and decay ride on top and are not counted here.

FEEDS MALVEINE

2K

CVE records

Last 7 days

One vulnerability record. Counts newly published CVEs; the enrichment stream (EPSS moves, KEV additions) rides on top and is not counted here.

FEEDS CVEKIT
expanding

Not yet collected

Marketplace listings

One listing on a monitored market: access, data, cards, infrastructure. Re-listings of the same goods count once.

FEEDS DRAGNET
expanding

Not yet collected

Paste-site drops

One paste containing credentials, keys or leaked records. Empty and duplicate pastes are discarded before counting.

FEEDS SHERLOG
expanding

Not yet collected

Ransomware victim listings

One victim entry on a leak site, captured with its countdown and proof pack, and archived when the crew pulls it.

FEEDS DRAGNET

Counts are floored to the leading unit and taken off the pipeline's own records. Bars are scaled to the largest live class, not to each other. Classes marked "expanding" are being brought online and are not yet counted.

01The other half of the number

What we refuse to count

Every vendor's collection figure is a choice about what to include. Inflating it is trivial and nobody audits it, so the only meaningful disclosure is the exclusion list.

Recycled combolists

A combolist assembled from other people's logs is deduplicated against the primary records it was built from, and it never inflates a stealer count. Most vendors quote the combined number, because it is the bigger one.

The same listing, re-posted

Access brokers re-advertise unsold goods and ransomware crews re-publish pulled victims. Repeats are collapsed onto the original record, which keeps the archive honest and the counter boring.

Bot noise and channel spam

Monitored channels are full of automated advertising. It is filtered out before counting rather than after, because a big number made of spam is a lie that is technically true.

Anything we bought

Nothing on this page was licensed from a broker. Eight of the ten classes came off collectors we run. The other two, the vulnerability records and the threat indicators, are open catalogues: published by other people, read free and directly from them rather than resold to us through anybody. That is the point of publishing any of it.

These are our numbers.

Ask your current vendor to break down theirs.

NDA-friendly briefings · global coverage · no slideware