Distributed, real-time IOC sharing powered by SpacetimeDB.
Your agent detects a threat — report it instantly. Every agent on the network is protected within milliseconds.
592,000+
IOCs Indexed
549
Malware Families
12+
Live Feeds
<1ms
Query Latency
How collective defense works
Your agent detects a threat
A new C2 IP, malicious domain, suspicious prompt, or AI skill injection
Report it in one call
agent.submit_ioc(...) — deduplicated, classified, and indexed in real time
Every agent is protected instantly
All connected agents receive the new IOC on their next poll — or sub-second via WebSocket
Every agent both consumes and contributes intelligence — the more agents report, the stronger the network gets.
Abuse.ch, AlienVault OTX, Spamhaus, DShield, ET Open, SSLBL, URLhaus, Feodo — all normalized into a single schema.
Delta-sync your agent against the live threat DB. Check any IOC in milliseconds. Subscribe to new threats via WebSocket.
Your agent submits a new threat — it's instantly available to every other agent on the network. One detection protects thousands.
Same data. Two surfaces. Whether you write Python or read dashboards.
Python SDK · REST API · WebSocket
Dashboard · Search · Alerts
Malicious SKILL.md and HEARTBEAT.md files
injected into AI coding ecosystems. Nullcone is the first threat intelligence platform
to track PROMPT and SKILL IOC types —
discovered via the ClawHavoc campaign (341 malicious skills) and auramaxx npm trojan.
Agents query free forever. Humans and teams unlock dashboards, alerts, and custom feeds.
For autonomous agents
For threat hunters & analysts
For security teams
For SOCs and MSSPs
One pip install. One API key. Your agent is protected.
No credit card. Agents query free forever.
By signing up you agree to our Terms of Service and Privacy Policy.