See the attack.
Build the defense.

Bring real attacker observations from FraudGuard’s own honeypot network into your threat hunts, detections, and security operations. Add ACE context to help your team prioritize what matters.

Observed at the source Example events
Inside the observationHTTP
Source IP
203.0.113.42
Target service / port
Ollama / 11434
GET/api/tags
Event typeai_model_enumeration

The activity behind the intelligence

From our sensors.
Into your investigations.

FraudGuard operates the honeypots. Attack Stream brings the observations to your team, so you can connect external attacker activity with what you see in your own environment.

Meet the ACE v2 engine
01 Who connected
Source IP and port, with timestamps that place the observation in context.
02 What they targeted
The service, protocol, and port reached on FraudGuard’s honeypot infrastructure.
03 What was observed
The event type, plus HTTP method, path, and user agent when applicable.

Put the observations to work

Fresh evidence.
For the questions your team asks.

Bring the feed into your own workflows
for hunting, detection, and response.

Hunt with outside context

Compare sources in your logs with activity observed by FraudGuard. Investigate repeated behavior and targeted services.

Threat hunting · Investigation

Build informed detections

Use observed login attempts, web probes, and service-specific activity to inform your rules and test detection ideas.

Detection engineering · Research

Prioritize with ACE context

Add available risk, recommended action, and recent activity context to help analysts decide what deserves attention.

SOC triage · Enrichment

Available today

An ongoing feed.
Your own pipeline.

Your collector polls for new events and keeps its place in the feed. Choose JSON or JSONL, then route observations into the tools your team already uses.

Add optional ACE enrichment when you want risk context alongside the event.

Read the integration docs
From observation to operations Pull API
FraudGuard honeypotsObserved attacker activity
Attack Stream APINew events as your collector polls
JSON
JSONL
Your ingestion pipelineSIEM · SOAR · Detection workflows

Live-forward delivery through your own collector.

A few useful details

Before you connect.

Explore the API docs
How is this different from the IP Reputation API?

The IP Reputation API evaluates an IP you submit. Attack Stream delivers ongoing observations from FraudGuard’s honeypots, giving your team events to correlate, investigate, and use in its own detections.

Can I use it with my SIEM or SOAR?

Yes. Pull structured JSON or JSONL into your ingestion pipeline, then use the events for correlation, alerting, and response. Your team controls how the data is processed; integration details are in the API docs.

What does ACE enrichment add?

Optional enrichment adds the source IP’s current risk, recommended action, confidence, and recent activity context when available. You get the observation and its ACE context together.

Does the feed include historical backfill?

No. The first request returns recent events, and subsequent requests move forward through the feed. Attack Stream v1 does not provide historical backfill. Retain collected events in your own pipeline, within your agreed access terms.

How do I get access, and what does it cost?

Attack Stream is available through reviewed Enterprise access. Contact us with your organization and intended use so we can discuss data scope, volume, support, and pricing.

Can I use it for clients or in a commercial product?

MSSP, MDR, consulting, and research uses are reviewed case by case. Redistribution, resale, public data publishing, commercial model training, and embedding telemetry in customer-facing products require a separate commercial or OEM licensing agreement.

Connect your team to the source

Put real observations
behind your next detection.

Tell us what your team is building.
We’ll help scope the feed and access for your workflow.