Threat Intelligence Feed

Threat intelligence from live attacker contact, not recycled feeds.

BlackDome's honeypot network captures attacker TTPs, IOCs, and observed session patterns across 13 protocols and a global edge network.

Differentiator

Commercial threat feeds recycle the same stale indicators. BlackDome's feed comes from live attacker contact with our honeypot network — every IOC is observed, not aggregated.

14.2K
Captured IOCs
10
IOC Types
63.6M
Captured Events
72h
Preview Delay

What You Get

Everything needed to move from raw attacker activity to production-ready detections.

IOC Streams

IPs, domains, URLs, hashes, and attacker infrastructure extracted from active sessions hitting the BlackDome sensor mesh.

STIX 2.1 Bundles

Normalized export packages with structured indicators and context so analysts can automate enrichment and investigation.

Candidate delivery paths

Contact-led pilots can explore suitable delivery formats for a specific workflow.

How It Works

Built to fit the way threat intel teams already ingest, enrich, and action data.

1

Honeypots capture

Distributed protocol sensors record live attacker activity across exposed services and deception endpoints.

2

Indicators are extracted

BlackDome normalizes sessions, extracts indicators, and groups related activity into analyst-consumable threat records.

3

STIX export and pilot discussion

Use current STIX export, or discuss candidate delivery paths through a scoped pilot.

4

Your SIEM ingests

Forward the feed into Splunk, Sentinel, QRadar, Elastic, or your own enrichment layer for hunts and detections.

Integrations

Common destinations teams may consider when evaluating a scoped delivery pilot.

Splunk
Enterprise Security
Microsoft Sentinel
Log Analytics
QRadar
SIEM
Elastic
Security

Choose Your Delivery Tier

Analyst and Pro are the current self-service tiers. Enterprise and OEM discussions begin with a scoped design-partner pilot.

Community

$0/mo

Delayed IOC access for researchers, labs, and early evaluations.

  • 100 IOCs/day
  • 72-hour delay
  • CSV export
  • IOC browser
Start Free
BEST VALUE

Pro

$299/mo

Current API access with STIX export for enrichment workflows.

  • Plan-limited IOCs
  • Real-time API access
  • STIX 2.1 export
  • Observed-evidence reports
  • 5K API requests/day
Start Pro

Enterprise

Contact us

Design-partner discussion for a scoped Enterprise delivery pilot.

  • Scoped pilot discovery
  • Evidence and workflow review
  • Candidate delivery paths for the pilot
Discuss a Pilot

OEM

Contact us

Design-partner discussion for a scoped OEM delivery pilot.

  • Scoped OEM discovery
  • Candidate integration paths
  • Evidence delivery review
Discuss a Pilot
Redacted Sample

Sample response shape without giving away the intelligence

This preview proves the field structure, confidence scoring, and capture cadence. Full indicator values, STIX exports, search, and pagination require an API key.

GET /api/blackdome/iocs/public?limit=3
72-hour delayed, redacted public view
Get full real-time access
{
  "objects": [
    {
      "type": "email",
      "redacted_value": "ra...@rac...",
      "confidence": 100,
      "severity": "high",
      "first_seen": "2026-09-03T08:02:47.099730+00:00",
      "last_seen": "2026-09-03T08:02:47.099730+00:00",
      "access": "redacted_public_preview",
      "labels": [
        "high",
        "threatdrop",
        "email_assessment",
        "phishing"
      ]
    },
    {
      "type": "domain",
      "redacted_value": "zkht...com",
      "confidence": 100,
      "severity": "high",
      "first_seen": "2026-09-03T08:02:47.097730+00:00",
      "last_seen": "2026-09-03T08:02:47.097730+00:00",
      "access": "redacted_public_preview",
      "labels": [
        "high",
        "threatdrop",
        "email_assessment",
        "phishing"
      ]
    },
    {
      "type": "domain",
      "redacted_value": "ract...com",
      "confidence": 100,
      "severity": "high",
      "first_seen": "2026-09-03T08:02:47.087939+00:00",
      "last_seen": "2026-09-03T08:02:47.087939+00:00",
      "access": "redacted_public_preview",
      "labels": [
        "high",
        "threatdrop",
        "email_assessment",
        "phishing"
      ]
    }
  ]
}

Feed live attacker signal into your SOC

Start with delayed community visibility, then move to current API access and STIX export as your detections need live attacker signal.