MapAttack · Specialised SIEM

See the Internet behind every alert.

Centralise your alerts. Understand their network origins. Give your security decisions context.

Attack analysis and Internet exposure

Product currently in development

A specialised SIEM built for everyday operations

MapAttack brings together alerts from IDS, WAF and monitored services, then connects them with BGP routing context. Move from an isolated IP address to the prefix, ASN, operator, country, targeted service and evidence behind a decision.

SUPPORTED INPUTS INCLUDE

  • Snort and network IDS
  • ModSecurity and WAF
  • Fail2ban and exposed services
MapAttack supervision screen showing a world map, event activity and attack context using illustrative data
Product interface preview · Illustrative demonstration data · Volumes and timings are not production or performance measurements.

Operational questions

Start with what your team needs to establish

01Where do the alerts originate?
Source addresses, BGP prefixes, ASNs, operators and available geographic origins.
02What is being targeted?
Destinations, exposed services, ports and the detection rules involved.
03Is the activity isolated or recurring?
Grouping by source, attack and source/attack pair, with volumes and distinct targets.
04Why was this decision made?
The observed context, rule, policy, reason and decision record remain available for review.

From sensor to decision

One chain for signals, context and controlled action

Each stage remains inspectable. MapAttack prepares operational outputs; enforcement stays under the control of the team and its equipment.

MapAttack workflow from security event collection through BGP enrichment, investigation and policy decisions to usable IP lists
  1. 01

    Collect and normalise

    Bring supported formats together and standardise dates, addresses, ports, rules and classifications.

  2. 02

    Add network context

    Connect a source to the most specific prefix in the active BGP snapshot, its ASN and available operator or geographic information.

  3. 03

    Observe and investigate

    Move from live activity to search, replay, grouping and the individual events behind each count.

  4. 04

    Prioritise and decide

    Review rules and exceptions, record a reason and retain an auditable decision within the relevant tenant scope.

  5. 05

    Prepare action

    Provide tenant-specific IPv4/IPv6 text feeds or ASN route exports for equipment configured by the team.

Product focus

Context that follows the investigation

01

BGP and ASN context

Relate an address to an observed route and network origin instead of treating every IP as an isolated indicator.

02

Explainable counts

Open grouped volumes to inspect the rules, sources, targets and events that support the analysis.

03

Live and historical inquiry

Use monitoring, time filters and replay of up to the last 24 available geolocated hours in the same workflow.

04

Tenant governance

Organise visibility scopes, roles, decisions, reasons and IP/CIDR exceptions for service-provider operations.

05

Operational collection

Checkpoint recovery, durable journalling and deduplication provide observable control points for ingestion.

06

Usable outputs

Prepare IPv4/IPv6 feeds and ASN prefix files while keeping firewall enforcement separate and explicit.

Designed for operational teams

Three focused working contexts

01

Security teams

Understand an activity spike against an exposed service, verify the events and hand over an evidence-based investigation.

Organise the evidence behind an investigation.
02

Hosting providers and operators

Find the network behind several sources, examine targeted destinations and prepare an ASN prefix export when required.

Move from addresses to operational network context.
03

MSPs

Work by customer scope with roles, documented decisions, network exceptions and dedicated IP feed keys.

Structure analysis around explicit responsibilities.

MapAttack

Discover what your alerts reveal about your Internet exposure.

Tell us which services, detection sources and operational scopes you need to bring together. We will determine whether the current MapAttack development scope fits the intended use.

Request a demonstration