Sample evidence
Preview redacted attacker telemetry, top scanners, indicator shape, payload clues, and observed session patterns from BlackDome honeypot sessions.
View Sample Evidence ->BlackDome captures real attacker sessions through honeypots, packages the evidence, and makes it queryable through MCP, API, reports, and data packages.
Start free with public evidence and MCP. Move up to real-time API access, paid intelligence packages, and contact-led pilot discussions when the workflow is proven.
Preview redacted attacker telemetry, top scanners, indicator shape, payload clues, and observed session patterns from BlackDome honeypot sessions.
View Sample Evidence ->Connect Claude, Cursor, ChatGPT, Slack workflows, or your own LLM so agents can query evidence instead of guessing from stale dashboards.
Connect MCP ->Buy IOC bundles, attack-pattern reports, and targeted intelligence packages generated from real attacker contact.
View Packages ->Contact-led Enterprise and OEM design-partner discussions can explore scoped pilot delivery paths when the workflow is ready.
View Pricing ->BlackDome sells observed evidence and the means to use it: intelligence, ThreatDrop analysis, MCP/API access, exports, and data packages.
Use observed sessions, indicators, artifacts, and completed analysis evidence before drawing a conclusion.
ThreatDrop records analysis evidence, notification attempts, replies, and observed takedown-workflow status.
Use the same first-party evidence through MCP, APIs, exports, and purchased data packages.
These are the named BlackDome offers that sit under the intelligence platform.
Observed IOCs, attacker infrastructure, payload context, and STIX export.
Explore ->Credential attempts captured during active exploitation across exposed protocols.
Explore ->Forward suspicious emails and turn results into evidence reports and workflows.
Explore ->Phishing, impersonation, and takedown workflows backed by live attacker signal.
Explore ->BlackDome is not just another dashboard. The long-term architecture is AI-readable evidence, bounded action, and verifiable decisions across security workflows.
The research layer behind bounded agent decisions, typed events, and audit-ready proof trails.
Decision records are designed to carry evidence, reasoning, and action context for review.
BlackDome data is structured so LLM tools can query sessions, IOCs, credentials, and anomalies directly.
Connect MCP for free, inspect the public intelligence layer, then upgrade to real-time data, Red Team packages, or a contact-led scoped pilot discussion when you need more.