
Bring early-stage attack intelligence into your MISP workflows.
ELLIO delivers real-time intelligence on active internet-wide scanning and mass exploitation activity, improving signal quality and accelerating SOC investigations and response without manual OSINT effort.

Disrupt attacks at their earliest stages.
Turn global reconnaissance into early attacker intent signals to prevent escalation, reduce operational cost, and stay ahead of evolving threats
Detect Active Exploitation Activity Before a CVE is Known.
Surface exploitation patterns in the wild, even before vulnerabilities are officially tracked, enabling earlier awareness of emerging attack activity and systematic risks.
Identify Early Warning Signals of Mass Exploitation Campaigns
Detect spikes in scanning and exploitation activity tied to emerging vulnerabilities or coordinated campaigns before they turn into widespread incidents.
Prioritize Vulnerabilities Based on Real Exploitation
See which vulnerabilities are actively scanned or exploited in the wild. Focus remediation on what is truly being weaponized, reducing exposure and unnecessary patching effort.
Expose Ongoing Mass Exploitation Activity in MISP
Add real attacker scanning and exploitation context to MISP indicators, showing how IPs, services, and vulnerabilities are being actively targeted across the internet to reduce real-world risk before escalation.
Separate Global Internet Noise from Relevant Attack Activity
Distinguish mass internet scanning from meaningful targeting and exploitation signals relevant to analysis. Reduce investigation effort spent on low-value or non-actionable activity.
Understand Attack Infrastructure and Tooling in Real Time
Track scanners, botnets, and exploitation frameworks operating at scale to identify infrastructure reuse, attacker tooling patterns, and campaign relationships across events.
Detect Active Compromise on Your Network Edge
Identify inbound scanning and exploitation attempts against exposed services to understand whether infrastructure is part of broader active attack activity or mass targeting campaigns.
Enable National-Level Reconnaissance Prioritization
Aggregate global reconnaissance signals to identify which services, sectors, and exposed technologies are being systematically probed across regions, supporting early warning and coordinated defensive guidance.
Built in Europe. Trusted by security teams worldwide.
ELLIO is a European threat intelligence provider based in Prague, delivering reconnaissance and mass exploitation intelligence powered by its own global deception network and real-time analytics. It provides an independent European alternative to US-based threat intelligence platforms for organizations seeking sovereignty in threat intelligence.
AI-ready cyber defense requires ground truth data.
Extend your intelligence stack with live, contextualized data from global reconnaissance activity across the internet, enabling faster correlation of weak signals, earlier detection of emerging threats, and proactive identification of evolving risk.
{
"ip": "210.187.49.191",
"classification": "malicious",
"first_seen": "2025-12-20",
"last_seen": "2025-12-31",
"spoofable": false,
"src": {
"geo": {
"country": {
"name": "Malaysia",
"code": "MY"
},
"continent": {
"name": "Asia",
"code": "AS"
}
}
},
"dst": {
"geo": [
{
"country": {
"name": "Australia",
"code": "AU"
},
"continent": {
"name": "Oceania",
"code": "OC"
}
},
{
"country": {
"name": "France",
"code": "FR"
},
"continent": {
"name": "Europe",
"code": "EU"
}
},
{
"country": {
"name": "Singapore",
"code": "SG"
},
"continent": {
"name": "Asia",
"code": "AS"
}
},
{
"country": {
"name": "United Arab Emirates",
"code": "AE"
},
"continent": {
"name": "Asia",
"code": "AS"
}
},
{
"country": {
"name": "Hong Kong",
"code": "HK"
},
"continent": {
"name": "Asia",
"code": "AS"
}
},
{
"country": {
"name": "Czechia",
"code": "CZ"
},
"continent": {
"name": "Europe",
"code": "EU"
}
},
{
"country": {
"name": "Germany",
"code": "DE"
},
"continent": {
"name": "Europe",
"code": "EU"
}
},
{
"country": {
"name": "Sweden",
"code": "SE"
},
"continent": {
"name": "Europe",
"code": "EU"
}
},
{
"country": {
"name": "Japan",
"code": "JP"
},
"continent": {
"name": "Asia",
"code": "AS"
}
},
{
"country": {
"name": "United Kingdom",
"code": "GB"
},
"continent": {
"name": "Europe",
"code": "EU"
}
},
{
"country": {
"name": "South Korea",
"code": "KR"
},
"continent": {
"name": "Asia",
"code": "AS"
}
},
{
"country": {
"name": "United States",
"code": "US"
},
"continent": {
"name": "North America",
"code": "NA"
}
},
{
"country": {
"name": "India",
"code": "IN"
},
"continent": {
"name": "Asia",
"code": "AS"
}
},
{
"country": {
"name": "Ireland",
"code": "IE"
},
"continent": {
"name": "Europe",
"code": "EU"
}
},
{
"country": {
"name": "Indonesia",
"code": "ID"
},
"continent": {
"name": "Asia",
"code": "AS"
}
},
{
"country": {
"name": "Austria",
"code": "AT"
},
"continent": {
"name": "Europe",
"code": "EU"
}
},
{
"country": {
"name": "Greece",
"code": "GR"
},
"continent": {
"name": "Europe",
"code": "EU"
}
},
{
"country": {
"name": "New Zealand",
"code": "NZ"
},
"continent": {
"name": "Oceania",
"code": "OC"
}
},
{
"country": {
"name": "Israel",
"code": "IL"
},
"continent": {
"name": "Asia",
"code": "AS"
}
},
{
"country": {
"name": "Poland",
"code": "PL"
},
"continent": {
"name": "Europe",
"code": "EU"
}
},
{
"country": {
"name": "Latvia",
"code": "LV"
},
"continent": {
"name": "Europe",
"code": "EU"
}
}
]
},
"network": {
"port": [
22,
23,
80,
443,
2222,
2375
],
"spoofable_port": [
23
],
"non_spoofable_port": [
22,
80,
443,
2222,
2375
]
},
"fingerprints": {
"ja3": [
"7041540a5e44ce9a1d4200c4214355aa"
],
"ja4": [
"t13i170900_5b57614c22b0_78e6aca7449b"
],
"muonfp": [
"65535:::",
"42340:2-4-8-1-3:1460:11"
]
},
"http": {
"path": [
"/",
"/V2/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
"/admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
"/api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
"/app/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
"/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
"/containers/json",
"/index.php",
"/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
"/public/index.php",
"/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"
],
"user_agent": [
"Go-http-client/1.1",
"NTRIP NtripClient/1.0",
"Hello-world"
]
},
"tag": [
"PHPUnit RCE Detector",
"ThinkPHP RCE Detector",
"Docker API Scanner",
"Apache Path Traversal",
"Laravel Detector",
"Targets GCP",
"Targets AWS",
"Fast Scanner (i.e. Masscan / ZMap)"
],
"mitre_attack": {
"tactics": [
"Reconnaissance",
"Initial Access"
],
"techniques": [
"T1595.002 - Vulnerability Scanning",
"T1190 - Exploit Public-Facing Application",
"T1592.002 - Gather Victim Software Info"
],
"sub_techniques": [
"T1595.002",
"T1592.002"
]
},
"cve": [
"CVE-2017-9841",
"CVE-2018-20062",
"CVE-2022-47945",
"CVE-2021-41773",
"CVE-2021-42013"
],
"ssh": {
"auth": [
{
"username": "root",
"password": "root"
},
{
"username": "root",
"password": "123456"
},
{
"username": "root",
"password": "admin"
},
{
"username": "admin",
"password": "admin"
},
{
"username": "admin",
"password": "1234"
},
{
"username": "ubuntu",
"password": "ubuntu"
},
{
"username": "pi",
"password": "raspberry"
},
{
"username": "oracle",
"password": "oracle"
}
]
}
}
wp2shell in the Wild: From Patch to Mass Exploitation in Under 48 hours
The ELLIO Deception Network recorded more than 11,500 sessions across 700 sensors as traffic moved from probing to attempted database extraction, administrator creation, and a web-shell write. The first probe arrived the morning after WordPress published its fix.
Sanctioned, Seized, Still Scanning: Inside a Russian Bulletproof Hosting Network Targeting the EU
On 18 May 2026, Dutch investigators seized more than 800 servers and broke up a hosting operation that prosecutors say powered Russian cyberattacks across the EU. We had spent the previous year watching the same network from the other side. After the seizure, the scanning did not stop.
New Integrations for Microsoft Sentinel and MISP
ELLIO is expanding its threat intelligence ecosystem with two new integrations designed for SOC, detection engineering, and threat intelligence workflows: Microsoft Sentinel via TAXII 2.1 and a native MISP integration.
See how ELLIO works for you.
Start Free TrialHow does ELLIO integrate with MISP?
ELLIO integrates with MISP through standard threat intelligence feed mechanisms and API-based enrichment. It can be consumed as external intelligence feeds or used to enrich existing MISP events and indicators with reconnaissance and mass exploitation context.
What type of intelligence does ELLIO add to MISP?
ELLIO adds live reconnaissance and mass exploitation intelligence, including internet-wide scanning activity, probing behavior, and early attacker targeting signals. This provides pre-attack context for existing MISP indicators and events.
How is ELLIO different from traditional threat intelligence feeds in MISP?
Unlike static IOC feeds, ELLIO focuses on real-time reconnaissance and active targeting activity. It enriches indicators with behavioral and contextual data rather than only known malicious IPs, domains, or CVEs.
Can ELLIO help prioritize threats inside MISP?
Yes. ELLIO provides context on whether infrastructure, services, or vulnerabilities are actively being targeted in the wild. This helps prioritize investigation and response based on real attacker activity rather than isolated indicators.
Does ELLIO require changes to existing MISP workflows?
No. ELLIO is designed to integrate into existing MISP setups as an enrichment or feed source. It enhances current workflows by adding external reconnaissance intelligence without requiring changes to event handling or taxonomy structures.
Where does ELLIO get its data from?
ELLIO collects intelligence from its own global deception network and real-time internet-wide reconnaissance monitoring infrastructure. This captures live scanning, probing, and exploitation-related activity as it happens across the internet, providing ground-truth context on attacker behavior.