PURE SIGNAL™ RECON // PROACTIVE THREAT HUNTING

Threat hunting
at internet scale.

Threat hunting tools built on observed internet telemetry, not scanned inference or recycled feeds.

Recon gives analysts direct access to how infrastructure actually behaves across the global internet. Query 40+ datasets, pivot from a single indicator to the full adversary estate, and reach victims and third-party exposure before the next stage lands.

Trusted by government agencies, national CSIRTs, and Fortune 500 hunting teams since 2005.

Accessible in Pure Signal™ Command
// RECON · PIVOT CHAIN LIVE
IOC203.0.113.84seed
ASNAS64500 · staging+14 hosts
X509sha1:4f2c…9ab+31 domains
PDNScdn-update[.]examplefirst seen 41d
FLOWobserved → 6 victimsthird party
40+ DATASETS · 90 DAYS RETAINED · ONE CONTINUOUS THREAD

// ILLUSTRATIVE PIVOT CHAIN · RESERVED DOCUMENTATION ADDRESS SPACE

By the Numbers

60

+

DATASETS QUERIED

90

d

TELEMETRY RETAINED

400

B+

DAILY CONNECTIONS OBSERVED

2,000

+

BEHAVIORAL TAGS

// THE HUNTING CEILING

Hunting stops where your telemetry stops.

Most hunting programs are bounded by the logs a team already collects. Adversary infrastructure is built outside that boundary on purpose. Recon removes the ceiling by giving analysts the same view of internet traffic that Team Cymru operates from, so a hunt can follow the adversary instead of stopping at the edge of the estate.

No Boundaries

Hunt past the edge of your own network

Discover threats forming outside your estate and block malicious infrastructure as it appears, rather than after it makes contact with something you own.

Accuracy

Trace a threat back to its origin

Improve investigations and attribution by pivoting across victims and third parties to map an adversary's full infrastructure, not the fragment that reached your perimeter.

Response

Insight within hours, not months

Expand the scope of compromise in real time to limit further impact from repeat attackers, instead of waiting on finished intelligence that arrives after the window closes.

// THE COST OF WAITING

Finished intelligence describes what already happened. By the time it lands, the infrastructure it describes has already moved.

// WHAT RECON PUTS IN AN ANALYST'S HANDS

Four capabilities that change how a hunt runs.

Each one removes a specific dependency: on a vendor's collection window, on a single data type, on a retention limit, or on manual repetition.

UNRIVALED DISCOVERY

Real-time granular insights, on demand

Stop depending on outdated finished intelligence. Query more than 40 datasets for complete IP and domain context, including NetFlow, passive DNS, x509 certificates, open ports, WHOIS, and fingerprints, and get answers while the answer still matters.

// DATASETS AVAILABLE TO A SINGLE QUERY
NetFlowPDNSx509OpenPortsWHOISFingerprintsBGPASNMalware40+ more

COMPREHENSIVE INTELLIGENCE

The world's largest internet telemetry set

Turn the largest daily view of global internet traffic into enriched, actionable intelligence. Observed movement, not sampled inference, gathered through trusted relationships with more than 1,000 network operators, ISPs, and CSIRTs.

// FOUNDATION
Daily connections observed400B+
Trusted data partnerships1,000+
Data types fused60+
Behavioral tags2,000+

UNMATCHED ARCHIVE

Retrospective analysis across 90 days

Reach back through up to 90 days of historical internet telemetry to build context around past incidents and connect them to current activity. The same infrastructure, seen across time, is often what turns an isolated alert into a campaign.

// RETENTION WINDOW
TODAY30d60d90d
Historical telemetry queried the same way as live telemetry. No separate archive, no export request.

AUTOMATION

Save time and prioritize what matters

Scheduled queries and full API integration let teams build workflows that run without an analyst present, so human attention goes to investigating indicators rather than re-running the same lookups every morning.

// AUTOMATION SURFACE
Scheduled queriesFull APIBulk lookupAlertingExport to TIPSIEM and SOAR
// FOR MSSPs AND MDR PROVIDERS

Build services on data
competitors cannot buy.

Add measurable value to customers and launch new services quickly, powered by the most trusted real-time threat intelligence available. Partners running Recon report higher margins, stronger customer retention, and lower operational cost per account.

Discuss an MSSP Partnership

// RECON INSIGHTS AND RESOURCES

Proof from the teams already hunting this way.

Practitioner research, live investigation write-ups, and case work you can lift techniques from.

Research

What analysts say about threat hunting

The annual practitioner survey on how hunting teams work, where their visibility ends, and what they would change about their tooling.

Investigation

FIN7 activity on hosting provider infrastructure

A worked investigation tracing FIN7 across hosting provider infrastructure, showing each pivot and the reasoning behind it.

Case Study

What elite threat hunters see that others cannot

How hunting teams use Pure Signal to map adversary infrastructure, surface staging activity, and run investigations conventional tooling misses entirely.

What your peers say about Recon.

★★★★★

Extremely useful tool and capability for threat intel teams. Analysts can quickly develop hunt queries across a global dataset to identify specific entities of interest.

Verified User

// ENTERPRISE, 1,000+ EMPLOYEES

★★★★★

A game changer in cyber intelligence. Defenders can take high ground against advanced adversaries, with actual data rather than an opinion, which extends our comprehension.

CEO

// IT SECURITY AND RISK MANAGEMENT

// Next Step

Put Recon on a hunt you are already running.

Bring an indicator your team is working now. An analyst will run it through Recon alongside you and show you what the pivot chain returns on live telemetry, not on a canned dataset.

  • Live session with a Team Cymru threat analyst
  • Your own indicator, pivoted across 40+ datasets
  • Retrospective lookback across the 90 day window
  • No preparation required from your team
// ONE POINT OF ACCESS

Pure Signal™ Command is how analysts access Radar, Recon, and Scout, and the same ground truth underneath all three. A finding in one becomes an investigation in the next without a context switch or a second login.

See How Access Works in Command
PURE SIGNAL™ RECON · PROACTIVE THREAT HUNTING TOOLS
BUILT INTO THE INTERNET. TRUSTED BY THOSE WHO DEFEND IT.