BGP and ASN context
Relate an address to an observed route and network origin instead of treating every IP as an isolated indicator.
MapAttack · Specialised SIEM
Centralise your alerts. Understand their network origins. Give your security decisions context.
Attack analysis and Internet exposure
Product currently in development
MapAttack brings together alerts from IDS, WAF and monitored services, then connects them with BGP routing context. Move from an isolated IP address to the prefix, ASN, operator, country, targeted service and evidence behind a decision.
SUPPORTED INPUTS INCLUDE

Operational questions
From sensor to decision
Each stage remains inspectable. MapAttack prepares operational outputs; enforcement stays under the control of the team and its equipment.
Bring supported formats together and standardise dates, addresses, ports, rules and classifications.
Connect a source to the most specific prefix in the active BGP snapshot, its ASN and available operator or geographic information.
Move from live activity to search, replay, grouping and the individual events behind each count.
Review rules and exceptions, record a reason and retain an auditable decision within the relevant tenant scope.
Provide tenant-specific IPv4/IPv6 text feeds or ASN route exports for equipment configured by the team.
Product focus
Relate an address to an observed route and network origin instead of treating every IP as an isolated indicator.
Open grouped volumes to inspect the rules, sources, targets and events that support the analysis.
Use monitoring, time filters and replay of up to the last 24 available geolocated hours in the same workflow.
Organise visibility scopes, roles, decisions, reasons and IP/CIDR exceptions for service-provider operations.
Checkpoint recovery, durable journalling and deduplication provide observable control points for ingestion.
Prepare IPv4/IPv6 feeds and ASN prefix files while keeping firewall enforcement separate and explicit.
Product interface
These screens show the current product direction with generated demonstration data. They are not customer records.

Define a period and network scope, filter by IP/CIDR or ASN, then inspect the events behind the result.
Product interface preview · Illustrative demonstration data · Volumes and timings are not production or performance measurements.
Apply a reasoned decision to selected detection rules and preserve the decision record.
Product interface preview · Illustrative demonstration data · Volumes and timings are not production or performance measurements.
Review observed network origins and move from individual addresses to prefix and ASN context.
Product interface preview · Illustrative demonstration data · Volumes and timings are not production or performance measurements.
Organise analysis and policy around explicit customer or infrastructure perimeters.
Product interface preview · Illustrative demonstration data · Volumes and timings are not production or performance measurements.
Expose dedicated IPv4 and IPv6 text lists for supported consumers and existing scripts.
Product interface preview · Illustrative demonstration data · Volumes and timings are not production or performance measurements.Designed for operational teams
Understand an activity spike against an exposed service, verify the events and hand over an evidence-based investigation.
Organise the evidence behind an investigation.Find the network behind several sources, examine targeted destinations and prepare an ASN prefix export when required.
Move from addresses to operational network context.Work by customer scope with roles, documented decisions, network exceptions and dedicated IP feed keys.
Structure analysis around explicit responsibilities.MapAttack
Tell us which services, detection sources and operational scopes you need to bring together. We will determine whether the current MapAttack development scope fits the intended use.