AI-ready threat intelligence

Query live attacker intelligence from your own AI tools.

BlackDome captures real attacker behaviour across global honeypots, previews the evidence safely, and exposes it through a free MCP server so Claude, Cursor, ChatGPT, and your own agents can ask questions grounded in live threat evidence.

Live

Watching the honeypot fleet for attacker activity…

63.6M
Events Captured
3,055
Active Attackers (24h)
1.1M
Credentials Captured
6
Global Edge Nodes

Most threat feeds sell conclusions without the session evidence.

BlackDome owns the contact layer. We see the scans, logins, commands, credentials, payloads, and infrastructure as they happen, then make that evidence queryable for humans, APIs, and AI agents.

Captured this week

Auto-generated from live telemetry · 72h community delay
256
New IOCs (7d)
72
Malicious verdicts
76
High severity
3,055
Attackers (24h)
Top MITRE techniques:T1078 · 181T1105 · 73T1059 · 20

Evidence Flow

Captured evidence becomes intelligence your tools can use.

Start with observed telemetry or a suspicious-email submission, preserve the supporting evidence, then connect it to the workflow that needs it.

1Observe

Observe first-party attacker evidence from honeypot sessions and artifacts.

2Connect

Connect the observed evidence to an AI tool or security workflow through MCP.

3Investigate

Investigate suspicious mail and track analysis evidence and response-work status.

Who It's For

Built for teams that need evidence their tools can query.

AI Security Builders

Connect BlackDome MCP and let your LLM query live honeypot evidence.

Connect MCP

Red Teams

Pull fresh IOC bundles, credential patterns, and attack reports from active telemetry.

Buy Data

MSSP / MDR

Use evidence-backed intelligence through a workflow that fits your security team.

Talk to Sales