Hunt with outside context
Compare sources in your logs with activity observed by FraudGuard. Investigate repeated behavior and targeted services.
Threat hunting · InvestigationBring real attacker observations from FraudGuard’s own honeypot network into your threat hunts, detections, and security operations. Add ACE context to help your team prioritize what matters.
203.0.113.42/api/tagsai_model_enumerationThe activity behind the intelligence
FraudGuard operates the honeypots. Attack Stream brings the observations to your team, so you can connect external attacker activity with what you see in your own environment.
Meet the ACE v2 enginePut the observations to work
Bring the feed into your own workflows
for hunting, detection, and response.
Compare sources in your logs with activity observed by FraudGuard. Investigate repeated behavior and targeted services.
Threat hunting · InvestigationUse observed login attempts, web probes, and service-specific activity to inform your rules and test detection ideas.
Detection engineering · ResearchAdd available risk, recommended action, and recent activity context to help analysts decide what deserves attention.
SOC triage · EnrichmentAvailable today
Your collector polls for new events and keeps its place in the feed. Choose JSON or JSONL, then route observations into the tools your team already uses.
Add optional ACE enrichment when you want risk context alongside the event.
Read the integration docsLive-forward delivery through your own collector.
The IP Reputation API evaluates an IP you submit. Attack Stream delivers ongoing observations from FraudGuard’s honeypots, giving your team events to correlate, investigate, and use in its own detections.
Yes. Pull structured JSON or JSONL into your ingestion pipeline, then use the events for correlation, alerting, and response. Your team controls how the data is processed; integration details are in the API docs.
Optional enrichment adds the source IP’s current risk, recommended action, confidence, and recent activity context when available. You get the observation and its ACE context together.
No. The first request returns recent events, and subsequent requests move forward through the feed. Attack Stream v1 does not provide historical backfill. Retain collected events in your own pipeline, within your agreed access terms.
Attack Stream is available through reviewed Enterprise access. Contact us with your organization and intended use so we can discuss data scope, volume, support, and pricing.
MSSP, MDR, consulting, and research uses are reviewed case by case. Redistribution, resale, public data publishing, commercial model training, and embedding telemetry in customer-facing products require a separate commercial or OEM licensing agreement.
Connect your team to the source
Tell us what your team is building.
We’ll help scope the feed and access for your workflow.