BlackDome Product Stack

Live attacker evidence for humans, APIs, and AI agents.

BlackDome captures real attacker sessions through honeypots, packages the evidence, and makes it queryable through MCP, API, reports, and data packages.

The offer, in the order customers can use it.

Start free with public evidence and MCP. Move up to real-time API access, paid intelligence packages, and contact-led pilot discussions when the workflow is proven.

01
Free entry point

Sample evidence

Preview redacted attacker telemetry, top scanners, indicator shape, payload clues, and observed session patterns from BlackDome honeypot sessions.

View Sample Evidence ->
02
AI access

MCP and API

Connect Claude, Cursor, ChatGPT, Slack workflows, or your own LLM so agents can query evidence instead of guessing from stale dashboards.

Connect MCP ->
03
Paid data

Red Team packages

Buy IOC bundles, attack-pattern reports, and targeted intelligence packages generated from real attacker contact.

View Packages ->
04
Design partners

Future delivery discussions

Contact-led Enterprise and OEM design-partner discussions can explore scoped pilot delivery paths when the workflow is ready.

View Pricing ->
Evidence delivery

Evidence customers can inspect, investigate, and connect to their workflows.

BlackDome sells observed evidence and the means to use it: intelligence, ThreatDrop analysis, MCP/API access, exports, and data packages.

Evidence before conclusions

Use observed sessions, indicators, artifacts, and completed analysis evidence before drawing a conclusion.

Analysis and response work

ThreatDrop records analysis evidence, notification attempts, replies, and observed takedown-workflow status.

Workflow-ready delivery

Use the same first-party evidence through MCP, APIs, exports, and purchased data packages.

Product lines

These are the named BlackDome offers that sit under the intelligence platform.

Threat Intelligence Feed

Observed IOCs, attacker infrastructure, payload context, and STIX export.

Explore ->

Credential Intelligence

Credential attempts captured during active exploitation across exposed protocols.

Explore ->

ThreatDrop

Forward suspicious emails and turn results into evidence reports and workflows.

Explore ->

Brand Monitoring

Phishing, impersonation, and takedown workflows backed by live attacker signal.

Explore ->
Research Layer

Built for agentic security workflows.

BlackDome is not just another dashboard. The long-term architecture is AI-readable evidence, bounded action, and verifiable decisions across security workflows.

Semiotic Governance

The research layer behind bounded agent decisions, typed events, and audit-ready proof trails.

Proof Packs

Decision records are designed to carry evidence, reasoning, and action context for review.

Agent-Readable Evidence

BlackDome data is structured so LLM tools can query sessions, IOCs, credentials, and anomalies directly.

Start with evidence your AI can query.

Connect MCP for free, inspect the public intelligence layer, then upgrade to real-time data, Red Team packages, or a contact-led scoped pilot discussion when you need more.