Probatio Cyber Defence GmbH

Stop beaconing C2 before it becomes an incident

ThreatDB is a turnkey IP threat-intelligence platform. It watches your existing Zeek log streams, detects beaconing command-and-control activity, enriches every hit with ASN, VirusTotal and AbuseIPFeed data, and hands your team a prioritised list of blockable indicators with full evidence.

  • Zeek-native works with your existing logs
  • 3+ enrichment sources ASN · VirusTotal · AbuseIPFeed
  • Explainable every hit backed by evidence

What ThreatDB does

Four capabilities that together turn raw network logs into decisions.

Continuous monitoring

Every outbound connection is tracked over time, not snapshotted once. Baselines of normal behaviour are built and updated automatically, so deviations stand out immediately.

Beacon detection

Periodic, low-and-slow C2 beacons are identified from intervals, jitter and cadence patterns — the kind of traffic that slips past threshold-based alerts.

Multi-source enrichment

Every candidate IP and domain is enriched automatically with ASN / RIPE context, VirusTotal reputation and AbuseIPFeed abuse reports, so you see the whole picture in one row.

Block recommendations

ThreatDB proposes concrete, explainable block actions per indicator — with the evidence that triggered it — so analysts can act with confidence instead of guesswork.

How it works

A short pipeline from Zeek log to analyst decision.

  1. Zeek logs → Elasticsearch

    Your Zeek conn and dns log streams are indexed into Elasticsearch. No agents on endpoints, no changes to your existing pipeline.

  2. 12-hour beacon detection

    Over a rolling 12-hour window, ThreatDB looks for periodic contact patterns — intervals, jitter, burst structure — that are characteristic of command-and-control beacons.

  3. Multi-source enrichment

    Suspected indicators are enriched with ASN/RIPE, VirusTotal and AbuseIPFeed data, plus observed traffic context, into a single scored record.

  4. Dashboard & block list

    Analysts review a prioritised queue in the dashboard, inspect the full evidence chain per alert, and export or apply block recommendations.

See it running

A live, read-only demo instance is available without sign-up. Explore a sample beacon alert, its enrichment sources and the block recommendation — all the way through.

Open live demo

Contact

Questions, a pilot for your environment, or just want to talk through your log pipeline?

Company

Probatio Cyber Defence GmbH

Country

Austria