Threat Intelligence

A bad-actor registry that grows itself.

Omega Point Threat ID is a community IP-reputation list built from many independent eyes — OSINT, dark-web signals, and member sensors — fused with cross-source corroboration. Join free for the feed, or run a sensor for a dollar and make the whole network, and your own protection, sharper.

More sensors → better list → better protection

Every sensor reports what it sees. Threat ID fuses those observations with OSINT and dark-web signals; a bad actor confirmed by more than one independent source scores higher. That sharper list flows straight into the products that check IPs — Omega Guard, FraudTrax, Hatchet Trace, and SVT, plus the ODIN engine — so each new sensor protects every member.

1 · Observe

Sensors & sources

Member sensors, our honeypots, OSINT sweeps, and Tor collection surface hostile IPs in the wild.

2 · Corroborate

Fuse & score

Observations are de-duplicated and cross-checked. A distinct corroborating source raises confidence; known-good hosts are never falsely escalated.

3 · Protect

Feed & verdicts

The scored registry powers the member feed and enriches every Omega Guard, FraudTrax, and Hatchet Trace verdict — catching threats a single source would miss.

From noise to a verified, reportable threat

The registry turns scattered signals into intelligence you can act on — and hand to the right authorities.

Identify

Surface

Hostile IPs and infrastructure from many independent eyes — sensors, OSINT, and dark-web collection.

Verify

Corroborate

Cross-source confirmation: acted on when more than one independent source agrees, not a single unproven hit.

Detect early

Warn

The flywheel flags emerging threats before any one feed would, and feeds Omega Guard, FraudTrax, Hatchet Trace & SVT verdicts in real time.

Escalate

Report

Attributable, timestamped intelligence — ready to support an abuse, IC3, CISA, or law-enforcement report so verified threats reach the right desk faster.

IP reputation is corroborating evidence, not proof; findings support human review and lawful escalation.

Free to join. A dollar to contribute.

Community membership is free and gets you the feed. Sensors are a $1 one-time provision each — and they earn their keep by making your own verdicts and the shared list better.

Community

Free

Sign up and pull the community feed — an aged, corroborated subset of the registry — as a blocklist for your own tooling. Request sensors any time.

$0Membership
FeedAccess
Sensor add-on

$1 / sensor

Provision a lightweight sensor tied to your account. It reports telemetry back into Threat ID, boosting your own Omega Guard / FraudTrax enrichment and the shared registry. Revocable any time.

$1One-time
LiveTelemetry
Built safe by design

Thin sensor, fat server

A sensor runs on your machine, so we assume it can be opened up and inspected — and we designed it to hold nothing worth stealing. All correlation, scoring, and list logic stays server-side on sovereign infrastructure. Each sensor carries only a unique, rotating, revocable credential and can do exactly one thing: submit observations to a hardened, rate-limited, anomaly-checked endpoint. It cannot read the feed, reach other sensors, or breach anything — even fully cracked open.

A line of purpose-built sensors

We don't ship one sensor — we ship a line of them. Each is a thin agent hardened for one job and named for an American patriot or warrior. Same safe design, same server-side brain, purpose-built fronts. Pick the sensor that matches the surface you need to defend. The flagship is Swamp Fox — Brig. Gen. Francis Marion, namesake of Marion County, IL.

Live
Class

Network-device

Reports hostile IPs from a watched host or device — a thin agent tails one log with a chosen profile.

Live / wire
Class

Web-cloud

Reports attacker IPs from web, edge, and WAF logs. Self-host is live; a Cloudflare pull is wired in.

Live
Class

Brand-domain

Reports hostile domains — typosquats, phishing, dark-web — via Hatchet Trace. ht-tor already feeds the registry.

Roadmap
Class

Identity-social

Reports hostile accounts and impersonators, powered by Omega Lens and FraudTrax. Lands with the multi-entity registry.

One thin agent, many jobs

A single hardened agent runs every network-device sensor. A profile selects the log source and detection pattern, so the same code guards very different surfaces. Every sighting is tagged with its callsign, unit, and host for provenance.

ssh-honeypot

SSH watch

Brute-force and invalid-user attempts against a decoy or a real production host. ssh-bruteforce

web-edge

Web probes

Traversal, SQLi, .env/.git grabs, and CMS scanners in web access logs. web-probe

firewall

Port scans

Port scanners and DROP/REJECT hits from ufw / iptables kernel logs. port-scan

mail

Mail gate

SMTP / IMAP authentication abuse against postfix and dovecot. smtp-abuse

router

Gateway

Home-LAN / OpenWrt router and gateway probes. router-scan

iot

Device

IoT and device brute-force — telnet/http, Mirai-style. iot-bruteforce

Two named series

Every sensor carries a callsign. Series I honors legendary American commanders by their battlefield nicknames. Series II is named in tribute to Medal of Honor recipients of Iraq and Afghanistan.

Series I

Warriors

Legendary American commanders, by the nicknames their troops gave them.

  • Swamp FoxFlagshipBrig. Gen. Francis Marion · Revolutionary War
  • StonewallLt. Gen. Thomas J. Jackson · Civil War
  • Old Blood and GutsGen. George S. Patton · WWII
  • Old HickoryMaj. Gen. Andrew Jackson · War of 1812
  • BullFleet Adm. William F. Halsey · WWII
  • Stormin' NormanGen. H. Norman Schwarzkopf · Gulf War
  • ChestyLt. Gen. Lewis B. Puller · WWII / Korea
  • Black JackGen. of the Armies John J. Pershing · WWI
  • Howlin' MadGen. Holland M. Smith · WWII
  • Mad AnthonyMaj. Gen. Anthony Wayne · Revolutionary War
  • Light-Horse HarryMaj. Gen. Henry Lee III · Revolutionary War
  • Vinegar JoeGen. Joseph Stilwell · WWII
Series II

Medal of Honor — Iraq & Afghanistan

Named in tribute to Medal of Honor recipients of the Global War on Terror. A sensor named for a recipient stands watch and defends.

  • MonsoorMA2 Michael A. Monsoor, USN (SEAL) · Ramadi, Iraq 2006 (P)
  • SmithSFC Paul R. Smith, USA · Baghdad, Iraq 2003 (P)
  • BellaviaSSG David G. Bellavia, USA · Fallujah, Iraq 2004
  • PayneMSG Thomas P. Payne, USA · hostage rescue, Iraq 2015
  • GiuntaSSG Salvatore A. Giunta, USA · Korengal, Afghanistan 2007
  • MeyerSgt Dakota L. Meyer, USMC · Ganjgal, Afghanistan 2009
  • RomeshaSSG Clinton L. Romesha, USA · COP Keating, Afghanistan 2009
  • CarterSSG Ty M. Carter, USA · COP Keating, Afghanistan 2009
  • CarpenterCpl William K. Carpenter, USMC · Marjah, Afghanistan 2010
  • PetrySFC Leroy A. Petry, USA · Paktia, Afghanistan 2008
  • ByersCPO Edward C. Byers Jr., USN (SEAL) · hostage rescue, Afghanistan 2012
  • ChapmanTSgt John A. Chapman, USAF · Takur Ghar, Afghanistan 2002 (P)

(P) denotes a posthumous award. These names are used with respect, to honor the recipients' valor. A sensor bearing a recipient's callsign stands a quiet watch in their memory.

Live threat intelligence

Threats we've identified

Confirmed-malicious IPs caught by the Omega Point sensor network and corroborated by multiple independent sources. High-confidence only — accuracy over volume.

malicious IPs listed
last updated
Loading live registry…

Machine-readable feeds: blocklist .txt · .csv · STIX 2.1 · JSON  ·  Methodology & appeals

Omega Point Solutions — AbuseIPDB Verified Contributor

Frequently asked

What is Omega Point Threat ID?

A community bad-actor IP registry that grows itself. It fuses observations from member sensors, OSINT, dark-web collection, and public tips with cross-source corroboration, then feeds that reputation into the products that check IPs — Omega Guard, FraudTrax, Hatchet Trace, and SVT.

How much does it cost?

Community membership and the threat feed are free. Sensors are a one-time $1 provision fee each; running a sensor sharpens both the shared registry and your own protection.

How do sensors stay secure?

Thin sensor, fat server: a sensor holds only a unique, revocable credential and can do exactly one thing — submit observations to a hardened, rate-limited endpoint. All scoring stays server-side, so a cracked-open sensor reveals nothing and can breach nothing.

Can anyone report a threat or fraud?

Yes — anyone can report a malicious IP, scam or impostor account, or fraudulent identity through the public tip line. Tips go to an analyst for review; verified indicators may be added after corroboration. IP reputation is corroborating evidence, not proof.

Public tip line

Report a threat or fraud

Seen a malicious IP, a scam/impostor account, or a fraudulent identity? Report it — anyone can. Tips go to an analyst for review; verified indicators may be added to the registry after corroboration.

Reports are confidential and are not published. Submit only lawfully obtained information. Tips are corroborating leads, not proof.

Join

Get your free membership

Enter your email to create a community membership and receive your feed access token.