Network security · Estonia

Network defence you can measure.

SciScope is a specialist network-security company. We build and tune network security monitoring, train the analysts who run it, instrument large-scale cybersecurity exercises, and run distributed packet capture at tens of gigabits per second. We also publish the SciScope Scanner Feed, curated IP threat intelligence built from our own sensors. Built on 18 years of hands-on network defence: production monitoring networks, international cyber defence exercises, and analyst training since 2014.

IDS / NSM consulting: design, deployment and tuning
TRAINING network monitoring, taught on real traffic
EXERCISES cybersecurity exercise instrumentation and packet capture at tens of Gbit/s
THREAT INTEL Scanner Feed: curated first-party IP intel
01 / services

Four practices. One obsession: the network.

Everything we do comes back to seeing network traffic clearly: building the monitoring, teaching the people, exercising the teams, and handling the data. One discipline, taken to depth. The same practice that designs your monitoring trains your analysts and instruments your exercises. Senior work, no hand-offs.

CONSULTING

IDS / NSM consulting

Design, deployment and tuning of intrusion detection and network security monitoring: sensor placement, rule and alert tuning, triage workflows, making an NSM stack earn its keep instead of drowning your analysts. Grounded in 25+ peer-reviewed publications on intrusion detection and security monitoring.

IDS tuningsensor placement open-source NSM stacksalert triage
TRAINING

Network-monitoring training

Hands-on courses for SOC and Blue Team analysts: reading real traffic, not slideware. From protocol fundamentals to hunting across flow records, DNS telemetry and IDS alerts. We have developed and delivered hands-on classroom training since 2014, and some of that course material is public. Modules, formats and prerequisites, or contact us at trainings@sciscope.ee about a course developed to order.

packet analysisthreat hunting Blue Team skillshands-on labs
EXERCISES

Cybersecurity exercises

Instrumentation and delivery for technical cyber defence exercises: realistic scenarios, scoring that rewards understanding over guesswork, and infrastructure that survives contact with the players. Built on hands-on work in some of the world's largest international cyber defence exercises, every year since 2014.

scenario designscoring systems exercise infrastructure
PACKET CAPTURE

Distributed packet capture at tens of Gbit/s

Full-lifecycle packet-capture services: capture architecture and sizing up front, integrity monitoring while capture runs, and post-capture processing into clean, analysis-ready datasets. Experience with both physical and virtual capture links.

capture infrastructure consultingintegrity monitoring PCAP processingphysical & virtual links

Product · Scanner Feed

A threat feed that doesn't block the good guys.

The SciScope Scanner Feed is our curated IP-reputation feed, built from a distributed network of passive sensors. We score the real scanners and attackers hitting the internet, and refuse to flag the search crawlers, public DNS resolvers and security scanners that popular blocklists quietly sweep up.

3.7% of a widely-used abuse-report feed's top 100k is legitimate infrastructure it flags at high confidence
296 search-engine crawler IPs wrongly listed on one popular community blocklist
0 of those false positives reach the SciScope feed
Explore the Scanner Feed the evidence, the guarantee and the pricing, all on the product site
02 / about

Measure first. Then claim.

SciScope OÜ is a specialist network-security company based in Estonia, built on years of hands-on work in the engine rooms of large international cyber defence exercises and production monitoring networks. There is no account layer here: you deal directly with whoever is doing the work, from the first email to delivery.

FIRST-PARTY

Our own sensors, our own data

We run our own sensor network and collect our own measurements. When we publish a number, we measured it. Nothing is resold from a black box.

EVIDENCE

Every claim shows its work

Scores ship with breakdowns, findings ship with timestamps, and reports say what was observed, not what would sound impressive.

LAWFUL BY DESIGN

GDPR-aware from the start

IP addresses are personal data. Our collection and processing is built on the network-security legitimate interest: data minimisation, retention limits, defensive use only.

03 / track record
What stands behind the work Doctoral research, 25+ publications and exercise engineering every year since 2014. Expand for the record.

SciScope's practice comes entirely from the defensive side of network security: data-centre operations and large-scale infrastructure monitoring first, then research, exercise engineering and teaching, and active threat-intelligence research to this day.

PhD in cybersecurity: doctoral research on automating cyber defences; MSc in cyber security, cum laude
25+ peer-reviewed publications on intrusion detection, security monitoring and defence automation
SINCE 2014 engineering cyber defence exercises at an international research centre, among the largest run anywhere, every year since
A DECADE co-teaching a university course on cyber defence monitoring solutions

Also in the cabinet: Red Hat engineering and security certifications, GIAC continuous monitoring, and a standing role advising on cybersecurity at national-academy level.

Tell us about your network. You'll get an engineer, not a funnel.

No forms, no qualification calls with sales. Email what you're trying to do (monitoring that needs tuning, a team that needs training, an exercise that needs building or capturing) and you'll hear back from an engineer who would work on it, not a sales qualifier.

Email hello@sciscope.ee interested in the feed instead? feed.sciscope.ee