Glean, never buy.
Collection is passive. Paying criminals for logs funds the next round of infections.
Novasky Labs / Cyber threat intelligence
Every day, infostealer malware copies passwords, cookies and session tokens off infected machines, and the logs turn up in Telegram channels and underground forums. Novasky Labs is building the watch over those places, so you hear about a stolen login before someone signs in with it.
Infostealer logs Leaked credentials Stolen sessions
Watchman, what of the night?
01 / The thief already has a key
But know this, that if the goodman of the house had known in what watch the thief would come, he would have watched, and would not have suffered his house to be broken up.
An infostealer doesn't have to break anything. It runs for a few seconds on a laptop, often someone's personal machine, and copies whatever the browser saved: passwords, autofill, cookies, session tokens.
The logs get bundled and passed around in Telegram channels and forums. Some are sold, many are given away as samples. A live session cookie lets an attacker skip the password and the MFA prompt entirely, because as far as the application can tell, they're already signed in.
Inside your network it looks like an employee doing their job. The early warning lives where the logs are traded, so that's where we keep watch.
02 / How the watch works
Every part of the platform is named for what it does. The names come from Scripture. The work is plain CTI tradecraft.
We collect what has been scattered in the open: public channels, underground and onion forums, leak sites and paste sites. We never buy the harvest.
Ruth 2:3Archives are opened on an isolated, offline floor. Credentials, cookies and host details are kept as text. Everything else is thrown out unopened, and nothing collected ever runs.
Matthew 3:12Each dump is checked against everything already seen. Fresh stealer logs are told apart from recycled combo lists and fake "breaches", and every source carries a reliability grade.
1 John 4:1Every finding keeps its testimony: where it came from, when it was first seen, the post around it, and how confident we are.
2 Corinthians 13:1When a match lands on a domain you've proven you own, the alarm goes to the people who can act on it, by email, Slack, webhook or straight into your SIEM.
Ezekiel 33:303 / Agentic by design
Volume is the hard part. Thousands of posts a day, in a dozen languages, most of it reposts and noise. Our Watchmen are AI analysts that read the collection as it lands. They triage, translate, pull out who and what is exposed, flag new sources worth watching, and draft the brief a human analyst would write.
They work inside hard limits, and the limits live in code at the boundary instead of in a prompt.
I have set watchmen upon thy walls, O Jerusalem, which shall never hold their peace day nor night.
04 / MSP-first
Luke 15:4
If you look after a hundred clients, the job is finding the one account that has been taken. Novasky is built around that kind of work, and this part is already running in the portal.
Live In the portal today
05 / What we believe
Collection is passive. Paying criminals for logs funds the next round of infections.
Fake and recycled breaches are everywhere, so everything we ingest gets graded before anyone is alerted.
Provenance and a confidence grade on every record. We show our sources.
Intelligence priced for MSPs and small teams, and research published in the open.
06 / Early access
We're bringing on a small group of MSPs and security teams as design partners. If you want early access, or want a say in what gets built, get in touch.