π Operational Security theater
Monitors the anonymization and obfuscation infrastructure adversaries rely on for operational security: Tor, VPNs, proxies, bulletproof hosting and fast-flux networks. Surfaces OPSEC failures and infrastructure reuse that enable attribution and de-anonymization.
Live indicators
549.7K
in this theater
High severity
0
score β₯ 0.75 (top 60)
Actors tracked
3
documented
Mapped sources
5
in catalog
🏹 Threat Actors
📚 Priority sources & datasets
🔄 Live Datasets & APIs (2 key-free Β· ingestible)
📜 Operational Security Playbook
- Collect Tor exit/relay lists, known VPN and residential-proxy ranges, and bulletproof-hosting ASNs from public and abuse feeds.
- Cluster indicators by ASN, registrar, TLS certificate and hosting reseller to map anonymization infrastructure ownership.
- Analyze operator OPSEC failures β session token reuse, clearnet leaks, timezone and language artifacts β that bridge anonymous and attributable identities.
- Attribute infrastructure to specific bulletproof providers or actor tenancy via co-tenancy, payment trails and infrastructure-reuse pivots.
- Disseminate curated anonymizer/proxy enrichment tags so downstream theaters can weight or exclude noisy anonymized sources.
- Feed high-confidence bulletproof ranges into blocklists and sinkholes, and escalate persistent hosts for takedown coordination.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🎯 Add to case
🧩 Advanced Capabilities
🔗 Cross-domain pivots
🔄 Data Feeds & Datasets
| Feed | Category | Format | Status |
|---|---|---|---|
| Gitleaks Rules (secret exposure) | Catalog: Operational Security | text | off |
| FireHOL IP Blocklists | Catalog: Operational Security | text | off |
Workstation Β· Copilot Β· AI Skills Β· Automation Β· Playbooks Β· Lookups Β· Docs Β· Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron