Novasky Labs / Cyber threat intelligence

Keep watch through the night.

Every day, infostealer malware copies passwords, cookies and session tokens off infected machines, and the logs turn up in Telegram channels and underground forums. Novasky Labs is building the watch over those places, so you hear about a stolen login before someone signs in with it.

Infostealer logs Leaked credentials Stolen sessions

Watchman, what of the night?

Isaiah 21:11 KJV

01 / The thief already has a key

The quietest breaches start with a valid login.

But know this, that if the goodman of the house had known in what watch the thief would come, he would have watched, and would not have suffered his house to be broken up.

Matthew 24:43 KJV

An infostealer doesn't have to break anything. It runs for a few seconds on a laptop, often someone's personal machine, and copies whatever the browser saved: passwords, autofill, cookies, session tokens.

The logs get bundled and passed around in Telegram channels and forums. Some are sold, many are given away as samples. A live session cookie lets an attacker skip the password and the MFA prompt entirely, because as far as the application can tell, they're already signed in.

Inside your network it looks like an employee doing their job. The early warning lives where the logs are traded, so that's where we keep watch.

02 / How the watch works

Glean, thresh, discern, witness, sound.

Every part of the platform is named for what it does. The names come from Scripture. The work is plain CTI tradecraft.

  1. 01

    Glean

    Gleaner · collection

    We collect what has been scattered in the open: public channels, underground and onion forums, leak sites and paste sites. We never buy the harvest.

    Ruth 2:3
  2. 02

    Thresh

    Threshing Floor · parsing

    Archives are opened on an isolated, offline floor. Credentials, cookies and host details are kept as text. Everything else is thrown out unopened, and nothing collected ever runs.

    Matthew 3:12
  3. 03

    Discern

    Discern · grading

    Each dump is checked against everything already seen. Fresh stealer logs are told apart from recycled combo lists and fake "breaches", and every source carries a reliability grade.

    1 John 4:1
  4. 04

    Witness

    Witness · provenance

    Every finding keeps its testimony: where it came from, when it was first seen, the post around it, and how confident we are.

    2 Corinthians 13:1
  5. 05

    Sound

    Shofar · alerts

    When a match lands on a domain you've proven you own, the alarm goes to the people who can act on it, by email, Slack, webhook or straight into your SIEM.

    Ezekiel 33:3

03 / Agentic by design

Analysts that don't sleep.

Volume is the hard part. Thousands of posts a day, in a dozen languages, most of it reposts and noise. Our Watchmen are AI analysts that read the collection as it lands. They triage, translate, pull out who and what is exposed, flag new sources worth watching, and draft the brief a human analyst would write.

They work inside hard limits, and the limits live in code at the boundary instead of in a prompt.

I have set watchmen upon thy walls, O Jerusalem, which shall never hold their peace day nor night.

Isaiah 62:6 KJV

04 / MSP-first

Leave the ninety and nine.

Luke 15:4

If you look after a hundred clients, the job is finding the one account that has been taken. Novasky is built around that kind of work, and this part is already running in the portal.

  • One console across every client organization, with per-client roles.
  • Nothing is shown for a domain until DNS proves it belongs to you.
  • A findings workflow your techs already know: new, acknowledged, resolved, false positive.
  • Scoped, expiring API tokens for your SIEM, PSA or reporting.
  • Sign-in that practices what we preach: passkeys, SSO, no SMS codes.

Live In the portal today

05 / What we believe

A creed for the watch.

Read the full creed
I

Glean, never buy.

Collection is passive. Paying criminals for logs funds the next round of infections.

II

Test every spirit.

Fake and recycled breaches are everywhere, so everything we ingest gets graded before anyone is alerted.

III

Witnesses, not rumors.

Provenance and a confidence grade on every record. We show our sources.

IV

A light for all.

Intelligence priced for MSPs and small teams, and research published in the open.

06 / Early access

The watch has begun.

We're bringing on a small group of MSPs and security teams as design partners. If you want early access, or want a say in what gets built, get in touch.