Nine windows into the attacker's ecosystem. One pane of glass.
General Intels operates the whole chain end-to-end: the collection pipeline, the index and the delivery layer are all ours. Each module opens one window; the platform correlates what they see.
One console
Every module shares the same search grammar, the same entity pages, the same case workflow. Learn it once; use it across the leak, the market and the conversation.
One API
Console and API run on the same permissions and the same data: an X-API-Key sees exactly what its organization sees. No "API edition" asterisks.
Audited by design
Every search, including our own, lands in an Activity log your org admin can read. We audit access to our own data.
One actor. Every window. One page.
Modules are windows; entity pages are where their views converge. A handle seen on a forum, an account negotiating on Jabber and a supplier in the stealer economy resolve to a single actor cluster, with the evidence chain attached.
- Pivot in one click: from a leaked credential to the channel that sold it to the actor who listed it.
- ATT&CK-mapped behavior: techniques attach to the cluster, so the dossier drops straight into your threat model.
- History that survives deletion: the cluster keeps the archived copies after the actor cleans up.
ACTOR CLUSTER · BZK-041
sample · maskedKnown handles
sat••••, b1••••k +1
First observed
2024-11
Languages
Multiple
Assessed role
Initial access broker
Seen through
ATT&CK techniques
Listings · 12 wk
The forum handle, the Jabber account and the stealer supply chain resolve to one cluster, automatically.
We live left of boom
Our collection concentrates where intelligence still changes the outcome: before initial access, around credentials, and on the extortion economy's own turf. Your EDR owns the rest of the matrix.
Highlighted: tactics the enrichment layer classifies into; tick marks count the techniques mapped there. Technique-level mappings ship on every campaign, actor and CVE record.
The nine windows
Coverage is not a paid axis: eight of the nine are open on every tier, and what a tier sets is the daily API ceiling on each rather than which ones you get. The ninth is Sours, scoped in a closed briefing.
Sherlog
Credential & Cookie Intelligence
When an employee's password lands in a stealer log, you know before it's for sale.
Dragnet
Underground Content Intelligence
If the underground is talking about you, we have the record.
Cvekit
Vulnerability Intelligence
Which CVEs actually burn? Prioritize with evidence.
Malveine
Threat Intel Console & Feeds
Intelligence that arrives as rules your stack can run.
Jabbernaut
Messaging Intelligence · XMPP
Forums are the storefront; the real deals close on Jabber. We're there.
Telepathy
Messaging Intelligence · Telegram
Half the market moved to Telegram. Searching it should not mean scrolling it.
Guildwire
Messaging Intelligence · Discord
Discord keeps no archive you can read. This one you can.
Baitback
Impersonation Defense
Someone is building a fake you. Find the impostor before your staff answers to it.
Sours
Operator Surveillance
While the attacker hunts for victims, you watch the attacker. Details in a closed briefing.
Under all nine
Every record passed through Centragon before you opened a window.
One enrichment layer classifies each collected post by what it is, who it targets, how serious it is and which ATT&CK techniques it describes, so the nine modules return fields instead of paragraphs. It is not a module, and there is nothing to buy separately.
32
categories
27
ATT&CK techniques
8
tactics
Your competitors will learn about the leak from the invoice.
Learn about it from the log batch.
NDA-friendly briefings · global coverage · no slideware