Network security · Estonia
SciScope is a specialist network-security company. We build and tune network security monitoring, train the analysts who run it, instrument large-scale cybersecurity exercises, and run distributed packet capture at tens of gigabits per second. We also publish the SciScope Scanner Feed, curated IP threat intelligence built from our own sensors. Built on 18 years of hands-on network defence: production monitoring networks, international cyber defence exercises, and analyst training since 2014.
Everything we do comes back to seeing network traffic clearly: building the monitoring, teaching the people, exercising the teams, and handling the data. One discipline, taken to depth. The same practice that designs your monitoring trains your analysts and instruments your exercises. Senior work, no hand-offs.
Design, deployment and tuning of intrusion detection and network security monitoring: sensor placement, rule and alert tuning, triage workflows, making an NSM stack earn its keep instead of drowning your analysts. Grounded in 25+ peer-reviewed publications on intrusion detection and security monitoring.
Hands-on courses for SOC and Blue Team analysts: reading real traffic, not slideware. From protocol fundamentals to hunting across flow records, DNS telemetry and IDS alerts. We have developed and delivered hands-on classroom training since 2014, and some of that course material is public. Modules, formats and prerequisites, or contact us at trainings@sciscope.ee about a course developed to order.
Instrumentation and delivery for technical cyber defence exercises: realistic scenarios, scoring that rewards understanding over guesswork, and infrastructure that survives contact with the players. Built on hands-on work in some of the world's largest international cyber defence exercises, every year since 2014.
Full-lifecycle packet-capture services: capture architecture and sizing up front, integrity monitoring while capture runs, and post-capture processing into clean, analysis-ready datasets. Experience with both physical and virtual capture links.
Product · Scanner Feed
The SciScope Scanner Feed is our curated IP-reputation feed, built from a distributed network of passive sensors. We score the real scanners and attackers hitting the internet, and refuse to flag the search crawlers, public DNS resolvers and security scanners that popular blocklists quietly sweep up.
SciScope OÜ is a specialist network-security company based in Estonia, built on years of hands-on work in the engine rooms of large international cyber defence exercises and production monitoring networks. There is no account layer here: you deal directly with whoever is doing the work, from the first email to delivery.
We run our own sensor network and collect our own measurements. When we publish a number, we measured it. Nothing is resold from a black box.
Scores ship with breakdowns, findings ship with timestamps, and reports say what was observed, not what would sound impressive.
IP addresses are personal data. Our collection and processing is built on the network-security legitimate interest: data minimisation, retention limits, defensive use only.
SciScope's practice comes entirely from the defensive side of network security: data-centre operations and large-scale infrastructure monitoring first, then research, exercise engineering and teaching, and active threat-intelligence research to this day.
Also in the cabinet: Red Hat engineering and security certifications, GIAC continuous monitoring, and a standing role advising on cybersecurity at national-academy level.
No forms, no qualification calls with sales. Email what you're trying to do (monitoring that needs tuning, a team that needs training, an exercise that needs building or capturing) and you'll hear back from an engineer who would work on it, not a sales qualifier.