Network security · Estonia

Network defence you can measure.

SciScope is a specialist network-security company. We build and tune network security monitoring, train the analysts who run it, design capture-the-flag exercises, and handle packet capture at exercise scale — and we publish the SciScope Scanner Feed — curated IP threat intelligence built from our own sensors.

IDS / NSM consulting — design, deployment and tuning
TRAINING network monitoring, taught on real traffic
EXERCISES CTF design, delivery and exercise-scale packet capture
THREAT INTEL Scanner Feed — curated first-party IP intel
01 / services

Four practices. One obsession: the wire.

Everything we do comes back to seeing network traffic clearly — building the monitoring, teaching the people, exercising the teams, and handling the data. Small company, senior work, no hand-offs.

CONSULTING

IDS / NSM consulting

Design, deployment and tuning of intrusion detection and network security monitoring: sensor placement, rule and alert tuning, triage workflows — making an NSM stack earn its keep instead of drowning your analysts.

IDS tuningsensor placement open-source NSM stacksalert triage
TRAINING

Network-monitoring training

Hands-on courses for SOC and Blue Team analysts — reading real traffic, not slideware. From protocol fundamentals to hunting across flow records, DNS telemetry and IDS alerts.

packet analysisthreat hunting Blue Team skillshands-on labs
EXERCISES

Capture-the-flag exercises

Design and delivery of technical CTF and defence exercises — realistic scenarios, scoring that rewards understanding over guesswork, and infrastructure that survives contact with the players.

scenario designscoring systems exercise infrastructure
EXERCISE DATA

Packet capture at exercise scale

Full-lifecycle packet-capture services for large international cyber defence exercises: capture design and sizing beforehand, integrity monitoring during play, and post-exercise processing into clean, per-team datasets.

capture architecturePCAP processing per-team datasets

Product · Scanner Feed

A threat feed that doesn't block the good guys.

The SciScope Scanner Feed is our curated IP-reputation feed, built from a distributed network of passive sensors. We score the real scanners and attackers hitting the internet — and refuse to flag the search crawlers, public DNS resolvers and security scanners that popular blocklists quietly sweep up.

3.7% of a widely-used abuse-report feed's top 100k is legitimate infrastructure it flags at high confidence
296 search-engine crawler IPs wrongly listed on one popular community blocklist
0 of those false positives reach the SciScope feed
Explore the Scanner Feed the evidence, the guarantee and the pricing — on the product site
02 / about

Measure first. Then claim.

SciScope OÜ is a small, senior network-security company based in Estonia, with years of hands-on work in the engine rooms of large international cyber defence exercises and production monitoring networks. We stay small on purpose: the person you talk to is the person doing the work.

FIRST-PARTY

Our own sensors, our own data

We run our own sensor network and collect our own measurements. When we publish a number, we measured it — nothing is resold from a black box.

EVIDENCE

Every claim shows its work

Scores ship with breakdowns, findings ship with timestamps, and reports say what was observed — not what would sound impressive.

LAWFUL BY DESIGN

GDPR-aware from the start

IP addresses are personal data. Our collection and processing is built on the network-security legitimate interest: data minimisation, retention limits, defensive use only.

Tell us about your network. You'll get an engineer, not a funnel.

No forms, no qualification calls with sales. Email what you're trying to do — monitoring that needs tuning, a team that needs training, an exercise that needs building or capturing — and you'll hear back from the person who would actually do the work.

Email hello@sciscope.ee interested in the feed instead? feed.sciscope.ee