Threat intelligence · United Kingdom

We find and report malicious domains.

Independent investigation, evidence, and escalation — until the threat is taken down.

0
Domains reported
0
Takedowns
0
Partners notified
0
Active cases
01

What we do

02

How we work

A repeatable pipeline built for evidence and speed. Every case follows the same four stages.

01

Intake

A domain comes in via report or from our own monitoring. We log it, hash the evidence, and open a case.

02

Investigate

OSINT, passive DNS, WHOIS history, and infrastructure mapping. We connect the domain to its operators and hosting.

03

Verify

No takedown moves without proof. We confirm the abuse, document it, and build a defensible evidence package.

04

Escalate

We route the case to the right registrar, registry, host, or regulator — and push until the threat is gone.

03

Our principles

Evidence first

Every claim is backed by documented, reproducible proof — never assumptions.

Independent

No platform allegiances. We work for the integrity of the open web.

Fast escalation

Time matters. Verified threats reach the right authority without delay.

Confidential

Reporters and sources are protected. Details stay inside the case.

04

Get in touch

Found something malicious, or need a domain investigated? Reach the right desk directly — we read every message.

Built with v0