Threat Intelligence

What we see attacking identity, written down.

We run an identity provider, so we get a close view of credential phishing, brand impersonation and the infrastructure behind them. When we analyse something, we publish it — including the parts that are inconvenient for us.

Observed, not inferred
Where a detail is deduced rather than measured, the advisory says so.
Infrastructure, never victims
We name domains, addresses and operators. We do not identify who was affected.
Defanged by default
Hostile addresses are published inert, and never as working links.

Advisories

Contact

Abuse desks, registrars, CERTs and researchers: [email protected]. We answer, and we will share captured payloads and hashes on request.