Threat intelligence from live attacker contact, not recycled feeds.
BlackDome's honeypot network captures attacker TTPs, IOCs, and observed session patterns across 13 protocols and a global edge network.
Commercial threat feeds recycle the same stale indicators. BlackDome's feed comes from live attacker contact with our honeypot network — every IOC is observed, not aggregated.
What You Get
Everything needed to move from raw attacker activity to production-ready detections.
IOC Streams
IPs, domains, URLs, hashes, and attacker infrastructure extracted from active sessions hitting the BlackDome sensor mesh.
STIX 2.1 Bundles
Normalized export packages with structured indicators and context so analysts can automate enrichment and investigation.
Candidate delivery paths
Contact-led pilots can explore suitable delivery formats for a specific workflow.
How It Works
Built to fit the way threat intel teams already ingest, enrich, and action data.
Honeypots capture
Distributed protocol sensors record live attacker activity across exposed services and deception endpoints.
Indicators are extracted
BlackDome normalizes sessions, extracts indicators, and groups related activity into analyst-consumable threat records.
STIX export and pilot discussion
Use current STIX export, or discuss candidate delivery paths through a scoped pilot.
Your SIEM ingests
Forward the feed into Splunk, Sentinel, QRadar, Elastic, or your own enrichment layer for hunts and detections.
Integrations
Common destinations teams may consider when evaluating a scoped delivery pilot.
Choose Your Delivery Tier
Analyst and Pro are the current self-service tiers. Enterprise and OEM discussions begin with a scoped design-partner pilot.
Community
Delayed IOC access for researchers, labs, and early evaluations.
- 100 IOCs/day
- 72-hour delay
- CSV export
- IOC browser
Pro
Current API access with STIX export for enrichment workflows.
- Plan-limited IOCs
- Real-time API access
- STIX 2.1 export
- Observed-evidence reports
- 5K API requests/day
Enterprise
Design-partner discussion for a scoped Enterprise delivery pilot.
- Scoped pilot discovery
- Evidence and workflow review
- Candidate delivery paths for the pilot
OEM
Design-partner discussion for a scoped OEM delivery pilot.
- Scoped OEM discovery
- Candidate integration paths
- Evidence delivery review
Sample response shape without giving away the intelligence
This preview proves the field structure, confidence scoring, and capture cadence. Full indicator values, STIX exports, search, and pagination require an API key.
{
"objects": [
{
"type": "email",
"redacted_value": "ra...@rac...",
"confidence": 100,
"severity": "high",
"first_seen": "2026-09-03T08:02:47.099730+00:00",
"last_seen": "2026-09-03T08:02:47.099730+00:00",
"access": "redacted_public_preview",
"labels": [
"high",
"threatdrop",
"email_assessment",
"phishing"
]
},
{
"type": "domain",
"redacted_value": "zkht...com",
"confidence": 100,
"severity": "high",
"first_seen": "2026-09-03T08:02:47.097730+00:00",
"last_seen": "2026-09-03T08:02:47.097730+00:00",
"access": "redacted_public_preview",
"labels": [
"high",
"threatdrop",
"email_assessment",
"phishing"
]
},
{
"type": "domain",
"redacted_value": "ract...com",
"confidence": 100,
"severity": "high",
"first_seen": "2026-09-03T08:02:47.087939+00:00",
"last_seen": "2026-09-03T08:02:47.087939+00:00",
"access": "redacted_public_preview",
"labels": [
"high",
"threatdrop",
"email_assessment",
"phishing"
]
}
]
}Feed live attacker signal into your SOC
Start with delayed community visibility, then move to current API access and STIX export as your detections need live attacker signal.