One source.
Many applications.

RIFFSEC data can be used in any cybersecurity tool from traffic filtering to incident analysis. You get structured, processed intelligence - ready to act.

Contact us

Trusted Us

CERT
Raben
DC9
Fundacja Batorego
BFG
CERT
Raben
DC9
Fundacja Batorego
BFG
API & feeds

API & feeds

Easy access to data via private API (STIX/TAXII), available to clients with valid key.

Can be integrated with firewalls or DNS filters

Can be integrated with firewalls or DNS filters

RIFFSEC provides curated feeds of phishing and malicious domains that can be used in DNS filters, proxies, or firewalls to automatically block known threats.

Works with most SIEM, SOAR, and XDR platforms

Works with most SIEM, SOAR, and XDR platforms

Data delivered over TAXII can be ingested by Splunk, Microsoft Sentinel, QRadar, Cortex XSOAR, and other security platforms — enriching alerts with context from dark web sources.

Data can be processed automatically or manually

Data can be processed automatically or manually

Clients can either download datasets manually in XLS format from the RIFFSEC web panel, or integrate them automatically via API for continuous ingestion.

Contact us
In SOC & CSIRT

In SOC & CSIRT

RIFFSEC data supports incident validation, enrichment, and escalation workflows used by security teams.

Validate alerts using data from the darkweb and forums

Validate alerts using dark web context

Check whether leaked credentials, internal domains, or infrastructure indicators appear in underground sources. Validation with RIFFSEC shortens triage and helps eliminate false positives.

Correlate incidents with earlier signals

Correlate incidents with previous activity

RIFFSEC connects phishing, leaks, and domain activity with known threat actors and campaigns, giving analysts a clearer picture of attack context and timeline.

Accelerate root cause investigation

Accelerate investigation and escalation

We are developing Hunter Workspace — a real-time visual environment that will allow analysts to link and explore all RIFFSEC data interactively, improving investigation speed and collaboration.

Contact us
SIEM & XDR

In SIEM & XDR

Power your tools with actionable context.

Automatic alerts for new phishing and domain activity

Automatic alerts for new phishing and domain activity

RIFFSEC detects new phishing campaigns, look-alike domains, and suspicious DNS changes. Indicators can be used directly in correlation and detection rules within SIEM and XDR systems.

Link discovered IPs to past campaigns

Link discovered IPs to past campaigns

Infrastructure reuse analysis links newly found IPs and URLs with known attacks, helping identify recurring threat actors and reused assets.

Monitor technical indicators of compromise

Monitor technical indicators of compromise

Stay informed about malware hashes, C2 servers, and compromised hosts observed in the wild. RIFFSEC continuously updates feeds to maintain detection precision.

Contact us
In threat analysis

In threat analysis

Data for analysts and threat hunters.

Review cybercriminal group activity

Review cybercriminal group activity

Correlate data across sources (domains, IPs, CVEs)

Correlate data across sources (domains, IPs, CVEs)

Support for reporting and escalation

Support for reporting and escalation

Keep it to yourself
Partners & Trust

Partners & Trust

Adam Haertle

Adam Haertle

Zaufana Trzecia Strona

Companies that have fallen victim to such attacks ask me what I recommend to avoid similar incidents in the future. Until now, I didn't have a simple answer to this question.
Natalia Łuczak

Natalia Łuczak

4Prime

RIFFSEC are true cybersecurity practitioners. They explain complex issues clearly and deliver valuable, relevant data instead of noise.
Robert Grabowski

Robert Grabowski

CERT Orange Poland

Data from the RIFFSEC is a valuable external source of power for our Cyber Shield and influences the effectiveness of its operation
Maciej Broniarz

Maciej Broniarz

DC9 Group

Every year at DC9 Group we handle incidents that might not have occurred if password compromise had been detected early. RIFFSEC solution supports cyber hygiene.
We should have nice header here

Come to the dark… web.
We have cookies.
Gigabytes of cookies!

Request your first Report