Network security · Estonia
SciScope is a specialist network-security company. We build and tune network security monitoring, train the analysts who run it, design capture-the-flag exercises, and handle packet capture at exercise scale — and we publish the SciScope Scanner Feed — curated IP threat intelligence built from our own sensors.
Everything we do comes back to seeing network traffic clearly — building the monitoring, teaching the people, exercising the teams, and handling the data. Small company, senior work, no hand-offs.
Design, deployment and tuning of intrusion detection and network security monitoring: sensor placement, rule and alert tuning, triage workflows — making an NSM stack earn its keep instead of drowning your analysts.
Hands-on courses for SOC and Blue Team analysts — reading real traffic, not slideware. From protocol fundamentals to hunting across flow records, DNS telemetry and IDS alerts.
Design and delivery of technical CTF and defence exercises — realistic scenarios, scoring that rewards understanding over guesswork, and infrastructure that survives contact with the players.
Full-lifecycle packet-capture services for large international cyber defence exercises: capture design and sizing beforehand, integrity monitoring during play, and post-exercise processing into clean, per-team datasets.
Product · Scanner Feed
The SciScope Scanner Feed is our curated IP-reputation feed, built from a distributed network of passive sensors. We score the real scanners and attackers hitting the internet — and refuse to flag the search crawlers, public DNS resolvers and security scanners that popular blocklists quietly sweep up.
SciScope OÜ is a small, senior network-security company based in Estonia, with years of hands-on work in the engine rooms of large international cyber defence exercises and production monitoring networks. We stay small on purpose: the person you talk to is the person doing the work.
We run our own sensor network and collect our own measurements. When we publish a number, we measured it — nothing is resold from a black box.
Scores ship with breakdowns, findings ship with timestamps, and reports say what was observed — not what would sound impressive.
IP addresses are personal data. Our collection and processing is built on the network-security legitimate interest: data minimisation, retention limits, defensive use only.
No forms, no qualification calls with sales. Email what you're trying to do — monitoring that needs tuning, a team that needs training, an exercise that needs building or capturing — and you'll hear back from the person who would actually do the work.