Network security · Estonia
SciScope is a specialist network-security company. We build and tune network security monitoring, train the analysts who run it, instrument large-scale cybersecurity exercises, and run distributed packet capture at tens of gigabits per second — and we publish the SciScope Scanner Feed — curated IP threat intelligence built from our own sensors. Founder-led, with a PhD in cybersecurity and 18 years of hands-on network defence.
Everything we do comes back to seeing network traffic clearly — building the monitoring, teaching the people, exercising the teams, and handling the data. Small company, senior work, no hand-offs.
Design, deployment and tuning of intrusion detection and network security monitoring: sensor placement, rule and alert tuning, triage workflows — making an NSM stack earn its keep instead of drowning your analysts. Advice backed by 25+ peer-reviewed publications on intrusion detection and monitoring.
Hands-on courses for SOC and Blue Team analysts — reading real traffic, not slideware. From protocol fundamentals to hunting across flow records, DNS telemetry and IDS alerts. Taught by an instructor with a decade of university-level teaching in cyber defence monitoring.
Instrumentation and delivery for technical cyber defence exercises — realistic scenarios, scoring that rewards understanding over guesswork, and infrastructure that survives contact with the players. Built on nine years helping run some of the world's largest international cyber defence exercises.
Full-lifecycle packet-capture services: capture architecture and sizing up front, integrity monitoring while capture runs, and post-capture processing into clean, analysis-ready datasets. Experience with both physical and virtual capture links.
Product · Scanner Feed
The SciScope Scanner Feed is our curated IP-reputation feed, built from a distributed network of passive sensors. We score the real scanners and attackers hitting the internet — and refuse to flag the search crawlers, public DNS resolvers and security scanners that popular blocklists quietly sweep up.
SciScope OÜ is a small, senior network-security company based in Estonia, with years of hands-on work in the engine rooms of large international cyber defence exercises and production monitoring networks. We stay small on purpose: the person you talk to is the person doing the work.
We run our own sensor network and collect our own measurements. When we publish a number, we measured it — nothing is resold from a black box.
Scores ship with breakdowns, findings ship with timestamps, and reports say what was observed — not what would sound impressive.
IP addresses are personal data. Our collection and processing is built on the network-security legitimate interest: data minimisation, retention limits, defensive use only.
SciScope is founder-led, and the founder's entire career has been on the defensive side of network security — starting in data-centre operations and large-scale infrastructure monitoring, and still active in threat-intelligence research today.
Also on the shelf: Red Hat engineering and security certifications, GIAC continuous monitoring, and a standing role advising on cybersecurity at national-academy level.
No forms, no qualification calls with sales. Email what you're trying to do — monitoring that needs tuning, a team that needs training, an exercise that needs building or capturing — and you'll hear back from the person who would actually do the work.