About the data

About the data

What is Stroople Signal?

Stroople Signal turns scattered public threat intelligence into one live dashboard, so your team spends less time hunting for signals and more time acting on them. Ransomware activity, actively exploited vulnerabilities, official security advisories, confirmed data breaches, regulatory sanctions, phishing infrastructure and active malware indicators are refreshed automatically and brought together in a single overview. Start with the full picture, or go straight to the topic that matters to you today.

Why each part matters?

Ransomware. Ransomware remains the attack that does the most damage in the least time. Tracking victims as they’re disclosed, by sector, country and threat group, helps you spot whether your industry or region is currently in the crosshairs, before it becomes your own incident.

Vulnerabilities. Not every vulnerability deserves the same urgency. This section separates what attackers are already exploiting today, via the CISA KEV catalog, from official advisories specific to industrial and OT systems, and adds an early warning layer, EPSS, flagging vulnerabilities likely to be weaponised soon, before they ever reach KEV. Each entry shows the affected vendor and product, its severity, whether it’s already linked to a ransomware campaign, and its exploitation probability score, so patching effort goes where it actually reduces risk instead of being spread thin across a backlog.

Data breaches. Every confirmed breach is a reminder that your suppliers, partners and service providers are part of your own attack surface. Knowing who was hit, and what kind of data was exposed, helps you ask the right questions before a partner’s incident becomes yours.

CNIL sanctions. Regulatory fines are a preview of what enforcement actually looks like in practice, not just in theory. Seeing which failures get sanctioned, and how often, turns GDPR compliance from an abstract obligation into a concrete, evidenced priority list.

Phishing. Phishing is still the most common way attackers get their first foothold. Visibility into active campaigns and the infrastructure behind them helps security teams and end users alike recognise the patterns before they click.

Malware infrastructure. Command and control servers, malware distribution points and the indicators tied to them are the backbone of active campaigns, sourced from abuse.ch’s non-profit tracking projects. This page shows which C2 servers are currently online by threat family, the freshest indicators of compromise with their associated malware and confidence level, and live distribution URLs still serving payloads. Knowing which infrastructure is active right now turns a generic “stay alert” reminder into something a SOC can actually check against its own logs and block lists.

The threat score, in plain terms

The score at the top of the dashboard gives you a single read on how intense the current threat landscape is, from Low to Critical, blending recent ransomware activity, critical vulnerability exposure and other live signals into one number. It’s designed as a quick temperature check, not a replacement for reading the detail behind it: two clicks away, every signal that feeds into it is there for you to explore on its own.

Where the data comes from?

Every source behind Stroople Signal is public or official: government agencies including CISA and ANSSI, established non-profit threat intelligence projects, and recognised industry databases.

Our approach to sourcing

The sources behind Stroople Signal do monitor leak sites and dark web activity to compile their data. What we control is what we choose to republish here.

We never publish sensitive victim data: confidential documents exposed on a leak site, or personal data that would normally be subject to secure, contractual notification to the individuals concerned. We also do not share the addresses of cybercriminal forums, Telegram channels, or leak site locations.

Only verifiable, publicly relevant facts, such as a victim’s name, sector, country and date, are shown. This keeps the tool safe to browse and share, while staying genuinely useful for tracking trends and patterns across the threat landscape.

Does this replace Stroople’s threat intelligence service?

No. Stroople Signal is a free awareness tool built on a handful of open sources. Our Managed Cyber Defense offering combines multiple proprietary and commercial intelligence sources rather than a single feed, which reduces bias and strengthens the reliability of every alert.

It also includes continuous external attack surface monitoring and threat exposure management, covering risks no public dashboard can detect: typosquatting domains, infostealer logs, and credential combolists circulating outside indexed sources.

For organizations that need continuous detection and response rather than a daily glance at a dashboard, our Managed SOC and CERT team operates on this intelligence around the clock.

Want a tailored assessment?

Contact our experts for a diagnostic of your organization’s exposure, built on multiple sources rather than a single public feed.

Contact us

Data is aggregated automatically from public sources. For informational purposes only. This product uses data from the NVD API but is not endorsed or certified by the NVD.

Proudly Powered by WordPress