BlackDome captures real attacker behaviour across global honeypots, previews the evidence safely, and exposes it through a free MCP server so Claude, Cursor, ChatGPT, and your own agents can ask questions grounded in live threat evidence.
Watching the honeypot fleet for attacker activity…
BlackDome owns the contact layer. We see the scans, logins, commands, credentials, payloads, and infrastructure as they happen, then make that evidence queryable for humans, APIs, and AI agents.
Evidence Flow
Start with observed telemetry or a suspicious-email submission, preserve the supporting evidence, then connect it to the workflow that needs it.
Observe first-party attacker evidence from honeypot sessions and artifacts.
Connect the observed evidence to an AI tool or security workflow through MCP.
Investigate suspicious mail and track analysis evidence and response-work status.
Platform Pillars
Each path is grounded in captured evidence from BlackDome honeypots or a ThreatDrop submission. Start free and go deeper when you need it.
First-party observed attacker evidence with APIs, exports, and data packages.
Free MCP server: let your AI tools query IOCs, sessions, credentials, payloads, and actors.
Forward suspicious emails for analysis, evidence, notification attempts, replies, and observed response status.
Who It's For
AI Security Builders
Red Teams
MSSP / MDR