GNSAC
Platform · GNSAC VIGIL
GNSAC VIGIL — External Threat Intelligence and Digital Risk Protection

Contextual intelligence for risks beyond the perimeter.

Vigil correlates credential exposure, underground activity, phishing infrastructure and externally observable technology risk with the domains, identities, brands and third parties relevant to your organisation. Deploy it as an on-premises appliance or use it as a managed SaaS service.

On-premises OVF/OVA applianceSaaS managed cloud optionIsolated customer-specific database
vigil — command dashboard LIVE
GNSAC Vigil command dashboard
8.7B+Corporate credential records
11M+New records / day
1.53BUnderground leak records
2,270++Monitored intelligence sources
806Threat actors tracked
Production datasetcontinuous collection~11M/day new records (7M credentials1.8M underground leaks0.5M threat intel1.7M hashes)snapshot 2026-08-21Definitions & limitations
Modules

Seven intelligence modules. One correlation engine.

Each module addresses a distinct external-risk domain while using a shared correlation, investigation and reporting workflow.

8.7B+ corporate credentials
search@example-corp.com8.7B · 0.8s
[email protected]cookies
[email protected]stealer
[email protected]combolist
[email protected]2019 dump
8.7B+corporate records
1.7B+password hashes
7Mnew / day
01

Credential Intelligence

Stealer logs, combolists and breach dumps matched to authorised identities, with exposure relationships and a timeline.

Explore
1,700+ monitored channels
messaging · access market
RDP access · TR logistics · 2,000 hosts
CRITICAL
forum · underground
database dump · example-corp · 41K rows
HIGH
leak site · qilin
logistics-partner.com listed
MEDIUM
1.53Bleak records
1,700+messaging ch.
500+leak sites
02

Dark Web & Underground

Selected forums, marketplaces, lawfully accessible messaging communities and ransomware leak sites monitored for relevant organisational references.

Explore
3.1M phishing URLs
example-corp-login.comlive · 97%
examp1e-corp.comcert · 91%
example-corp.supportparked · 74%
exarnple-corp.netnew · 68%
CT LOGLOGIN FORMEVIDENCE PACK
3.1Mphishing URL
CTcert watch
7.5MIoCs
03

Phishing & Brand

Look-alike domains, phishing infrastructure and fake pages — with evidence to support investigation and abuse reporting.

Explore
130+ analysis modules
example-corp.comphase 9 / 12
discover · assets318
correlate · leaks41
prioritise · attack paths6
130+modules
12phases
MITREATT&CK
04

External Risk Assessment

Structured checks across authorised domains, with evidence-backed findings, relevant MITRE ATT&CK references and prioritised remediation guidance.

Explore
806 actors tracked
logistics-partner.comleak site
payroll-vendor.iocredential leak
msp-provider.netCVE · KEV
CFO · LinkedIn exposureVIP
806actors tracked
500+leak sites
12risk categories
05

Supply Chain & VIP

Vendor breach records, ransomware victim lists, mentions of your suppliers in monitored underground sources and executive exposure provide current evidence for third-party review.

Explore
101K+ vulnerability records
CVE-2026-2149 · VPN applianceKEV
CVE-2026-1187 · web server9.8
response → Jira · Teamsrouted
101K+CVE
KEVflags
SIEMSOAR · Jira
06

Vulnerability Intelligence & Response Workflows

Vulnerability records with KEV context are matched to observed technologies; supported workflows route findings to SIEM, SOAR, Jira or Teams.

Explore
4,700+ YARA rules
PE32+SHA-256YARA · 2 matches
invoice_0922.exe · 1.2 MBstatic analysis
MAL_Stealer_Generic0x4a20
MID 3472 · terminal 8811watched
4,700+YARA rules
0files executed
BINMID · TID watch
07

Malware & Payment Security

Suspicious files are read and checked against YARA rules on your instance, never executed or retained; merchant, terminal and BIN identifiers are watched across monitored sources.

Explore
Platform

From external signal to prioritised security action.

A unified workspace for monitoring, investigation, evidence review and reporting. Analyst-level evidence and executive-level reporting are produced from the same underlying findings.

vigil — dashboardLIVE
Operational overview
130+CTI modules
12analysis phases
5–10 minfirst assessment
Request a Demo
Automated CTI Scan

A structured assessment of externally observable risk.

Vigil evaluates a customer-authorised domain through phased discovery and intelligence checks. Results are normalised, correlated and prioritised to support technical remediation and management reporting.

  1. 01
    Discover
    Assets and attack surface
  2. 02
    Correlate
    Leak, brand and threat data
  3. 03
    Prioritise
    CVE, MITRE ATT&CK, attack paths
  4. 04
    Act
    Risk score, plan and report
130+OSINT & CTI modules
500–2,000checks depending on domain structure
5–10 mintypical initial analysis time
12analysis phases
CTI Scan live run
Technical Assessment Report
Evidence-backed findings · affected assets · source context · relevant MITRE ATT&CK references · prioritised remediation guidance
Executive Risk Brief
Material exposures · business relevance · ownership · recommended management actions
See a sample scan
After detection

Alerts, response and reporting on the same platform.

A finding is not the end of the work. Vigil carries it through notification, takedown, prioritisation and the report your management or auditor will read.

24alert categories

Alerts you configure

For each category you set whether it notifies, the minimum severity and the e-mail preference. Critical and high findings appear in the in-product alert stream; the monitor checks new records every 30 seconds.

Credentials · 3Brand · 7Assets · 2VIP · 1Payments · 1Dark web · 1Platform · 1Supply chain · 8
6ready-made playbooks

Response and takedown

Takedown Center keeps the case, the notice, the reply and the evidence in one process. Notices are sent from your own SMTP server; a notice counts as sent only when the mail server accepts it. Removal remains the provider’s decision.

Case and contactApproved noticeReply and escalationEvidenced closure
6report types · TR / EN

Reports for each audience

Executive, technical, compliance, VIP, vendor and brand reports are produced as PDF in Turkish and English. Delivery by download, e-mail or schedule; each report fixes its period so the next one can be compared against it.

ExecutiveTechnicalComplianceVIPVendorBrand
8supplier signals

Supply-chain monitoring

Add a supplier by name and domain. The monitor compares against the previous state every 30 minutes and routes new changes and new exposure to the related alert category.

Ransomware recordBreach recordInfostealer findingLook-alike domainDNS changeCertificate changeE-mail spoofing riskSupplier vulnerability
4assessment dimensions

Vulnerability prioritisation

A vulnerability is assessed by its technical score together with exploitation likelihood, active exploitation in the CISA catalogue and whether a public exploit exists. Records that name a monitored supplier enter the alert stream.

CVSSEPSSKEVPublic exploit
6country intelligence modules

Threat graph and regional context

The threat graph links credentials, leaks, actors, domains, IOCs and campaigns so a finding can be followed to its relationships. Regional modules follow national sources and the groups active in each region.

TürkiyeUnited StatesUnited KingdomCanadaAustraliaRussia
Architecture

A deployment model designed for operational control.

In an on-premises deployment, curated intelligence is synchronised to the customer appliance through a documented channel. Matching against monitored assets and identities occurs within the customer-controlled environment.

01
GNSAC intelligence repository
8.7B+ corporate credentials · 2,270+ sources · 1,700+ messaging channels · 130+ modules
02
CentralSync →
documented intelligence synchronisation channel
YOUR PERIMETER03
Your perimeter
OVF/OVA appliance · isolated PostgreSQL · 2FA + RBAC · audit trail
04
Your tools
SIEM · SOAR · Jira · ServiceNow · Teams · Slack · REST API
OVF / OVAdeploy on your own hypervisor
Isolated databaseyour findings and assets kept separate
2FA + RBACadmin / analyst / viewer
Auditable activityrelevant administrative and user events
On-prem for regulated sectors Connectivity and data flows are documented for security review.
Integrations

Integrate external intelligence into existing security operations.

SplunkIBM QRadarMicrosoft SentinelWazuhSOAR webhookSTIX 2.1 / TAXII 2.1JiraServiceNowMicrosoft TeamsSlackSMTPREST APICSV / JSON export

Deliver validated findings and alerts to SIEM, SOAR, case-management and collaboration platforms through supported connectors, webhooks and REST APIs. Vigil complements existing SOC processes without requiring analysts to replace their primary operational tools.

On-premises · OVF/OVACustomer-isolated database2FA + RBACAuditable user activityREST APIData-governance supportSIEM · SOAR · Jira · Teams
FAQ

Questions buyers ask before a demo.

What sources does Vigil monitor?+

Vigil monitors selected underground forums and marketplaces, lawfully accessible messaging communities, stealer log collections, breach datasets, paste services, exposed code repositories, phishing and certificate-transparency sources, ransomware leak sites and vulnerability intelligence. Coverage changes as sources become available, relevant or inaccessible.

How fast are we alerted?+

Collection and matching are continuous. Depending on source availability and processing status, high-priority alerts can be generated within minutes of ingestion and routed according to customer-defined rules.

Does Vigil replace our SOC?+

No. Vigil is the external intelligence and exposure layer. Your SOC continues to monitor internal telemetry; Vigil routes relevant externally observed findings into the tools your SOC already uses.

Where is customer data stored?+

For on-premises deployments, monitored assets, findings and user activity are stored in a customer-isolated database within the customer-controlled environment. Connectivity and data-flow requirements are documented during security review. SaaS data-location and retention requirements are agreed during scoping.

How long does deployment take?+

A standard on-premises implementation is generally completed within four weeks, subject to infrastructure readiness, security approvals and integration scope.

How is it licensed?+

Vigil is licensed per organisation in three tiers. Monitored scope, users, scans, reports, deployment model and Enterprise limits are confirmed in the applicable quote and order form.

Get started

Evaluate Vigil against your external risk profile.

Review the platform, an anonymised assessment report and the deployment model with a GNSAC security specialist.

External Threat Intelligence & Digital Risk Protection | GNSAC Vigil