Omega Threat ID shield mark Threat Intelligence

A bad-actor registry that grows itself.

Omega Threat ID is a community IP-reputation list built from many independent eyes, OSINT, dark-web signals, and member sensors, fused with cross-source corroboration. Join free for the feed, or run a sensor for a dollar and make the whole network, and your own protection, sharper.

The Flywheel

More sensors → better list → better protection

Every sensor reports what it sees. Threat ID fuses those observations with OSINT and dark-web signals, and a bad actor confirmed by more than one independent source is scored higher. That sharper list flows straight into the products that check IPs, Omega Guard, FraudTrax, Hatchet Trace, and SVT, plus the ODIN engine, so each new sensor protects every member.

1 · Observe

Sensors & sources

Member sensors, our own honeypots, HT OSINT sweeps, and Tor collection surface hostile IPs in the wild.

2 · Corroborate

Fuse & score

Observations are de-duplicated and cross-checked. A distinct corroborating source raises confidence; known-good hosts are never falsely escalated.

3 · Protect

Feed & verdicts

The scored registry powers the member feed and enriches every Omega Guard, FraudTrax, and Hatchet Trace verdict, catching threats a single source would miss.

Why it matters

From noise to a verified, reportable threat

The registry turns scattered signals into intelligence you can act on, and hand to the right authorities.

Identify

Surface

Hostile IPs and infrastructure from many independent eyes: sensors, OSINT, and dark-web collection.

Verify

Corroborate

Cross-source confirmation: acted on when more than one independent source agrees, not a single unproven hit.

Detect early

Warn

The flywheel flags emerging threats before any one feed would, feeding Omega Guard, FraudTrax, Hatchet Trace and SVT in real time.

Escalate

Report

Attributable, timestamped intelligence, ready to support an abuse, IC3, CISA, or law-enforcement report so verified threats reach the right desk faster.

IP reputation is corroborating evidence, not proof; findings support human review and lawful escalation.

Membership

Free to join. A dollar to contribute.

Community membership is free and gets you the feed. Sensors are a $1 one-time provision each, and they earn their keep by making your own verdicts and the shared list better.

Community

Free

Sign up and pull the community feed, an aged, corroborated subset of the registry, as a blocklist for your own tooling. Request sensors any time.

$0MembershipFeedAccess
Sensor add-on

$1 / sensor

Provision a lightweight sensor tied to your account. It reports telemetry back into Threat ID, boosting your own Omega Guard / FraudTrax enrichment and the shared registry. Revocable any time.

$1One-timeLiveTelemetry
Built safe by design

Thin sensor, fat server

A sensor runs on your machine, so we assume it can be opened up and inspected, and we designed it to hold nothing worth stealing. All correlation, scoring, and list logic stays server-side on sovereign infrastructure. Each sensor carries only a unique, rotating, revocable credential and can do exactly one thing: submit observations to a hardened, rate-limited, anomaly-checked endpoint. It cannot read the feed, reach other sensors, or breach anything, even fully cracked open.

Per-sensor rotating keys Server-side logic only Instantly revocable
The Sensor Line

A line of purpose-built sensors

Omega Threat ID ships not one sensor but a line of them, each a thin agent hardened for one job and named for an American patriot or warrior. Same safe design, same server-side brain, purpose-built fronts. Pick the sensor that matches the surface you need to defend; the flagship is Swamp Fox (Brig. Gen. Francis Marion, namesake of Marion County, IL).

Live
Class

Network-device

Reports hostile IPs from a watched host or device. A thin agent tails one log with a chosen profile. Deployable today.

Live / wire
Class

Web-cloud

Reports attacker IPs from web, edge, and WAF logs. Self-host is live; a Cloudflare pull is wired in.

Live
Class

Brand-domain

Reports hostile domains, typosquats, phishing, and dark-web infrastructure via Hatchet Trace. ht-tor already feeds the registry.

Roadmap
Class

Identity-social

Reports hostile accounts and impersonators, powered by Omega Lens and FraudTrax. Lands with the multi-entity registry.

Agent profiles

One thin agent, many jobs

A single hardened agent runs every network-device sensor. A profile selects the log source and detection pattern, so the same code guards very different surfaces. Every sighting is tagged with its callsign, unit, and host for provenance.

ssh-honeypot

SSH watch

Brute-force and invalid-user attempts against a decoy or a real production host. ssh-bruteforce

web-edge

Web probes

Traversal, SQLi, .env/.git grabs, and CMS scanners in web access logs. web-probe

firewall

Port scans

Port scanners and DROP/REJECT hits from ufw / iptables kernel logs. port-scan

mail

Mail gate

SMTP / IMAP authentication abuse against postfix and dovecot. smtp-abuse

router

Gateway

Home-LAN / OpenWrt router and gateway probes. router-scan

iot

Device

IoT and device brute-force, telnet/http, Mirai-style. iot-bruteforce

The fleet

Two named series

Every sensor carries a callsign. Series I honors legendary American commanders by their battlefield nicknames. Series II is named in tribute to Medal of Honor recipients of Iraq and Afghanistan.

Series I

Warriors

Legendary American commanders, by the nicknames their troops gave them.

  • Swamp FoxFlagshipBrig. Gen. Francis Marion · Revolutionary War
  • StonewallLt. Gen. Thomas J. Jackson · Civil War
  • Old Blood and GutsGen. George S. Patton · WWII
  • Old HickoryMaj. Gen. Andrew Jackson · War of 1812
  • BullFleet Adm. William F. Halsey · WWII
  • Stormin' NormanGen. H. Norman Schwarzkopf · Gulf War
  • ChestyLt. Gen. Lewis B. Puller · WWII / Korea
  • Black JackGen. of the Armies John J. Pershing · WWI
  • Howlin' MadGen. Holland M. Smith · WWII
  • Mad AnthonyMaj. Gen. Anthony Wayne · Revolutionary War
  • Light-Horse HarryMaj. Gen. Henry Lee III · Revolutionary War
  • Vinegar JoeGen. Joseph Stilwell · WWII
Series II

Medal of Honor, Iraq & Afghanistan

Named in tribute to Medal of Honor recipients of the Global War on Terror. A sensor named for a recipient stands watch and defends.

  • MonsoorMA2 Michael A. Monsoor, USN (SEAL) · Ramadi, Iraq 2006 (P)
  • SmithSFC Paul R. Smith, USA · Baghdad, Iraq 2003 (P)
  • BellaviaSSG David G. Bellavia, USA · Fallujah, Iraq 2004
  • PayneMSG Thomas P. Payne, USA · hostage rescue, Iraq 2015
  • GiuntaSSG Salvatore A. Giunta, USA · Korengal, Afghanistan 2007
  • MeyerSgt Dakota L. Meyer, USMC · Ganjgal, Afghanistan 2009
  • RomeshaSSG Clinton L. Romesha, USA · COP Keating, Afghanistan 2009
  • CarterSSG Ty M. Carter, USA · COP Keating, Afghanistan 2009
  • CarpenterCpl William K. Carpenter, USMC · Marjah, Afghanistan 2010
  • PetrySFC Leroy A. Petry, USA · Paktia, Afghanistan 2008
  • ByersCPO Edward C. Byers Jr., USN (SEAL) · hostage rescue, Afghanistan 2012
  • ChapmanTSgt John A. Chapman, USAF · Takur Ghar, Afghanistan 2002 (P)

(P) denotes a posthumous award. These names are used with respect, to honor the recipients' valor. A sensor bearing a recipient's callsign stands a quiet watch in their memory.

Public tip line

Report a threat or fraud

Seen a malicious IP, a scam or impostor account, or a fraudulent identity? Anyone can report it. Tips go to an analyst for review; verified indicators may be added to the registry after corroboration.

Reports are confidential and are not published. Submit only lawfully obtained information. Tips are corroborating leads, not proof.

Join the network.

Community membership and the feed are free. Request a sensor for a dollar and sharpen protection for everyone, including you. Launching now, request early access below.

Join Omega Threat ID Free →