Network security · Estonia

Network defence you can measure.

SciScope is a specialist network-security company. We build and tune network security monitoring, train the analysts who run it, instrument large-scale cybersecurity exercises, and run distributed packet capture at tens of gigabits per second — and we publish the SciScope Scanner Feed — curated IP threat intelligence built from our own sensors. Founder-led, with a PhD in cybersecurity and 18 years of hands-on network defence.

IDS / NSM consulting — design, deployment and tuning
TRAINING network monitoring, taught on real traffic
EXERCISES cybersecurity exercise instrumentation and packet capture at tens of Gbit/s
THREAT INTEL Scanner Feed — curated first-party IP intel
01 / services

Four practices. One obsession: the network.

Everything we do comes back to seeing network traffic clearly — building the monitoring, teaching the people, exercising the teams, and handling the data. Small company, senior work, no hand-offs.

CONSULTING

IDS / NSM consulting

Design, deployment and tuning of intrusion detection and network security monitoring: sensor placement, rule and alert tuning, triage workflows — making an NSM stack earn its keep instead of drowning your analysts. Advice backed by 25+ peer-reviewed publications on intrusion detection and monitoring.

IDS tuningsensor placement open-source NSM stacksalert triage
TRAINING

Network-monitoring training

Hands-on courses for SOC and Blue Team analysts — reading real traffic, not slideware. From protocol fundamentals to hunting across flow records, DNS telemetry and IDS alerts. Taught by an instructor with a decade of university-level teaching in cyber defence monitoring.

packet analysisthreat hunting Blue Team skillshands-on labs
EXERCISES

Cybersecurity exercises

Instrumentation and delivery for technical cyber defence exercises — realistic scenarios, scoring that rewards understanding over guesswork, and infrastructure that survives contact with the players. Built on nine years helping run some of the world's largest international cyber defence exercises.

scenario designscoring systems exercise infrastructure
PACKET CAPTURE

Distributed packet capture at tens of Gbit/s

Full-lifecycle packet-capture services: capture architecture and sizing up front, integrity monitoring while capture runs, and post-capture processing into clean, analysis-ready datasets. Experience with both physical and virtual capture links.

capture infrastructure consultingintegrity monitoring PCAP processingphysical & virtual links

Product · Scanner Feed

A threat feed that doesn't block the good guys.

The SciScope Scanner Feed is our curated IP-reputation feed, built from a distributed network of passive sensors. We score the real scanners and attackers hitting the internet — and refuse to flag the search crawlers, public DNS resolvers and security scanners that popular blocklists quietly sweep up.

3.7% of a widely-used abuse-report feed's top 100k is legitimate infrastructure it flags at high confidence
296 search-engine crawler IPs wrongly listed on one popular community blocklist
0 of those false positives reach the SciScope feed
Explore the Scanner Feed the evidence, the guarantee and the pricing — on the product site
02 / about

Measure first. Then claim.

SciScope OÜ is a small, senior network-security company based in Estonia, with years of hands-on work in the engine rooms of large international cyber defence exercises and production monitoring networks. We stay small on purpose: the person you talk to is the person doing the work.

FIRST-PARTY

Our own sensors, our own data

We run our own sensor network and collect our own measurements. When we publish a number, we measured it — nothing is resold from a black box.

EVIDENCE

Every claim shows its work

Scores ship with breakdowns, findings ship with timestamps, and reports say what was observed — not what would sound impressive.

LAWFUL BY DESIGN

GDPR-aware from the start

IP addresses are personal data. Our collection and processing is built on the network-security legitimate interest: data minimisation, retention limits, defensive use only.

03 / founder
Who's behind SciScope? A PhD and 18 years of defending networks — expand for the record.

SciScope is founder-led, and the founder's entire career has been on the defensive side of network security — starting in data-centre operations and large-scale infrastructure monitoring, and still active in threat-intelligence research today.

PhD in cybersecurity — doctoral research on automating cyber defences; MSc in cyber security, cum laude
25+ peer-reviewed publications on intrusion detection, security monitoring and defence automation
9 YRS researching cyber defence at an international research centre — helping build some of the world's largest defence exercises
A DECADE co-teaching a university course on cyber defence monitoring solutions

Also on the shelf: Red Hat engineering and security certifications, GIAC continuous monitoring, and a standing role advising on cybersecurity at national-academy level.

Tell us about your network. You'll get an engineer, not a funnel.

No forms, no qualification calls with sales. Email what you're trying to do — monitoring that needs tuning, a team that needs training, an exercise that needs building or capturing — and you'll hear back from the person who would actually do the work.

Email hello@sciscope.ee interested in the feed instead? feed.sciscope.ee