LIVE FEED
MeshSec claimed defacement of ba•.edu.az May 20//Hunter Bajwa claimed defacement of hg••••.az Mar 30//Unkn0wn Gunm4n claimed DDoS attack on pa••••.az Apr 07//Mr. BDKR28 claimed defacement of z2•.az Jul 01//CRED 20,000+ .az credentials ingested · last 7d//Trenggalek Cyber Army claimed defacement of pr••••.az Jun 29//Red Wolf Team claimed DDoS attack on ce••.gov.az Oct 12//𝐅 ~ INTELLIGENCE / OSINT claimed DDoS attack on pa••••.az Mar 29//CoupDeGrace claimed defacement of fo••••.az Jun 30//DARKWEB 80+ dark-web sources with .az activity monitored//HEZI RASH claimed DDoS attack on ci••••.az Oct 16//Simsimi claimed defacement of el••••.az Jul 01//cyberbannews_en claimed DDoS attack on my•.gov.az Aug 20//Nullsec Philippines claimed DDoS attack on tr••••.az Oct 10//INTEL 200+ DDoS + 1,000+ defacement events on .az tracked//Python Squad claimed DDoS attack on ad•.az Aug 20//Armenian code claimed DDoS attack on az••••.az May 06//maw3six claimed defacement of bi•.edu.az Jul 14//VandaTheGod claimed defacement of mg••••.az Apr 06//CRED 1,100,000+ credentials under continuous monitoring//Antonkill claimed defacement of he••.az Jul 01//siyahi claimed defacement of my••••.az May 18//Phantom01Cyber claimed DDoS attack on ca••••.gov.az Jun 13//Cyberbannews Ir claimed DDoS attack on my•.gov.az Aug 20//ARABIAN GHOSTS claimed DDoS attack on ra••••.az Mar 07//magelang6etar claimed defacement of sa••••.az Jul 01//Nullsechackers claimed DDoS attack on ed••••.az Oct 10//0xV01D claimed defacement of la••••.az Apr 16//TEAM FEARLESS claimed DDoS attack on gr••••.edu.az Aug 13//civilian claimed defacement of vi••••.az Apr 29//MeshSec claimed defacement of ba•.edu.az May 20//Hunter Bajwa claimed defacement of hg••••.az Mar 30//Unkn0wn Gunm4n claimed DDoS attack on pa••••.az Apr 07//Mr. BDKR28 claimed defacement of z2•.az Jul 01//CRED 20,000+ .az credentials ingested · last 7d//Trenggalek Cyber Army claimed defacement of pr••••.az Jun 29//Red Wolf Team claimed DDoS attack on ce••.gov.az Oct 12//𝐅 ~ INTELLIGENCE / OSINT claimed DDoS attack on pa••••.az Mar 29//CoupDeGrace claimed defacement of fo••••.az Jun 30//DARKWEB 80+ dark-web sources with .az activity monitored//HEZI RASH claimed DDoS attack on ci••••.az Oct 16//Simsimi claimed defacement of el••••.az Jul 01//cyberbannews_en claimed DDoS attack on my•.gov.az Aug 20//Nullsec Philippines claimed DDoS attack on tr••••.az Oct 10//INTEL 200+ DDoS + 1,000+ defacement events on .az tracked//Python Squad claimed DDoS attack on ad•.az Aug 20//Armenian code claimed DDoS attack on az••••.az May 06//maw3six claimed defacement of bi•.edu.az Jul 14//VandaTheGod claimed defacement of mg••••.az Apr 06//CRED 1,100,000+ credentials under continuous monitoring//Antonkill claimed defacement of he••.az Jul 01//siyahi claimed defacement of my••••.az May 18//Phantom01Cyber claimed DDoS attack on ca••••.gov.az Jun 13//Cyberbannews Ir claimed DDoS attack on my•.gov.az Aug 20//ARABIAN GHOSTS claimed DDoS attack on ra••••.az Mar 07//magelang6etar claimed defacement of sa••••.az Jul 01//Nullsechackers claimed DDoS attack on ed••••.az Oct 10//0xV01D claimed defacement of la••••.az Apr 16//TEAM FEARLESS claimed DDoS attack on gr••••.edu.az Aug 13//civilian claimed defacement of vi••••.az Apr 29//
National Threat Intelligence · Azerbaijan

See cyber threats before they reach you.

Caspint tracks who's coming after Azerbaijani companies — compromised accounts, data for sale, defaced sites and infrastructure under attack — collected from breach dumps, cybercrime forums and closed Telegram channels, and delivered to you in time. Free for local companies.

caspint · national threat dashboard
The mission

Cyber threat intelligence built for Azerbaijan.

Most companies in Azerbaijan cannot afford the high cost of premium cyber threat intelligence (CTI) services. Caspint was built precisely for that need.

We track attacks aimed at Azerbaijani companies and identify who is targeting them, how, and when — collecting leaked credentials, databases for sale, defaced websites and compromised systems from the surface, deep and dark web, and thousands of closed Telegram channels, and delivering them to you.

In doing so, we make world-class cyber threat intelligence accessible to Azerbaijani companies and help raise the country's overall cyber resilience.

9,000,000+Telegram messages
575,000+compromised accounts
570,000+attacks on web resources
680,000+threat indicators · IOC
28,000+ransomware attacks
13,300+Telegram DDoS attacks
1,000+Telegram channels monitored
1,550+threat groups tracked
The platform

Five disciplines. One national picture.

Caspint is organized the way a security team works: five intelligence disciplines and fourteen focused modules, each scoped to Azerbaijan and to your organization.

Analyst Tools

Workbench

Everything a SOC analyst uses day to day, in one place.

Five disciplines.
One platform. Free for Azerbaijan.

For any organization defending Azerbaijan, no license, no procurement.

Request access
Inside the platform

Built for the work analysts actually do.

National Threat Dashboard

Key information on one screen.

Security teams have little time and too many threats. The dashboard brings the whole picture onto one screen, so every day you see where you stand — how much of your data is exposed, what changed, and what needs attention — on a single screen.

caspint · dashboard
Credential Intelligence

Know when your organization's accounts are exposed online.

Leaked employee passwords are the easiest way in for attackers — no vulnerability to exploit, they simply log in. Caspint shows you which of your accounts have been compromised, so you can reset the passwords before anyone uses them.

credentials · scope: your org
Leaked employee credentials exposed in breaches, monitored by Caspint
Threat Group Profiles

Threat groups active against the region.

You can't prepare for every threat the same way. Knowing which groups actually threaten you, how they operate and who they target lets you build defenses around real threats, not generic ones. Ready-made profiles of the groups targeting the region and your sector do that research for you — who, why and how is already known.

threat-actors · target: AZ
Attack Surface Intelligence

Monitoring your external attack surface.

Attackers scan your internet-facing systems for weak points before they ever reach you. Caspint shows your organization exactly the way they see it — which servers, subdomains and services are exposed and what weaknesses they carry. Most importantly, findings are ranked by real risk, so instead of drowning in thousands of alerts you fix what truly matters first.

attack-surface · host map
TG Intelligence

Search closed Telegram channels.

The trade in your data and the plans against your organization often happen in closed Telegram channels you can't get into. Caspint monitors hundreds of them and alerts you the moment your name, brand or domains come up. You find out while it's being prepared, not after the fact — and even if the message is later deleted, the evidence stays with you.

telegram · tg-intel
Dark Web

Tracking dark-web forums and markets.

Your leaked data and access to your systems are bought and sold on dark-web forums and markets. Caspint watches these sources for you and alerts you whenever something tied to your organization appears — a leak, an access for sale, or a combolist. Every finding is verified by our analysts.

darkweb · monitoring
IOC Intelligence

Download ready-to-use IOCs in one click.

We collect threat indicators — malicious IPs, domains and file hashes — for you and update them daily. Download all of them in one click as TXT, CSV, JSON or STIX 2.1 and integrate them straight into your SIEM, firewall and other security systems.

ioc · lookup
Indicator of compromise (IOC) intelligence feed in Caspint
Brand & Executive Protection

Brand and digital-risk monitoring.

Most fraud and cyberattacks are prepared before they strike — look-alike domains are registered, fake profiles impersonating you and your executives are created, your documents and keys are leaked. Caspint tracks this preparation stage across the open and closed web — including detecting fake profiles on social media — so you can stop a threat before it reaches its first victim — your customer or your employee. Solving the problem before it starts is always cheaper than restoring a reputation.

brand · protection
Brand protection monitoring for look-alike domains and impersonation
Threat News

Regional cyber-threat news.

Global news feeds are often generic, leaving you to figure out whether something applies to Azerbaijan. Caspint gives you only curated news relevant to the region and your organization, so you stay informed of the latest developments in your sector.

news · regional
Cybersecurity threat news feed relevant to Azerbaijan
Statistics & Trends

Statistics.

Track how your data exposure and threat landscape change over time with charts.

statistics · trends
Analyst Workbench

Analyst Workbench.

Everything a SOC analyst uses day to day, in one place. From domain analysis to email verification, a range of functions can be run right here.

workbench · case
Common questions

Why was Caspint created?

Caspint is an independent cybersecurity initiative, and its core mission is to raise the overall level of cyber defense in Azerbaijan. We believe effective security shouldn't be reachable only by organizations with large budgets. That's why Caspint is open to selected organizations with no license fee or procurement process.

Who can get access?

Organizations operating in Azerbaijan can apply for access. Registration is done with a corporate email address, and every application is reviewed by our team. Access is granted only to organizations found eligible.

What happens after applying?

Your application is reviewed by our team. Once approved, intelligence is automatically tailored to your organization and access to the platform is granted.

Do we have to give access to our internal systems?

No. Using Caspint does not require access to your VPN, API, Active Directory, email or any other internal systems. The platform works purely on cyber-intelligence gathered from external sources and delivers the data relevant to your organization.

Where does the data come from?

Caspint collects data from breach databases, stealer logs, cybercrime markets and ransomware sites, as well as hundreds of closed channels operating on social media and the dark web.

How current is the data?

Data collection runs 24/7 without interruption and the platform is updated daily. You can track new leaks, compromised accounts and other security changes discovered about your organization within the last 24 hours.

Be warned in time about what cybercriminals already know about you.

If your organization operates in Azerbaijan, you can apply to register for Caspint.

Caspint
Mission Intelligence FAQ Azərbaycanca → Request access →