STARTER

Catfish view

Custom Pricing

contact sales
Best seller
PRO

Sealion View

Custom Pricing

contact sales
entreprise

Shark View

Custom Pricing

contact sales

Compare plans

Catfish view

(starter)

Sealion View

(pro)

Shark View

(entreprise)

Results/month *

1,000,000 *

10,000,000 *

100,000,000 *

Historical data

7 DAYS

14 DAYS

30 DAYS

ASM categories

CTISCAN category

CTIURL category

OQLv2

* All ONYPHE Views are subject to a rate limit of an average of 1 request per second, contact us for Unrated API option.

Trusted by Governments and Security Teams

For organisations that take their Internet exposure seriously

Slide Image
Slide Image
Slide Image
Slide Image
Slide Image
Slide Image
Slide Image
Slide Image
Slide Image
Slide Image
Slide Image

Keep the storm away

ONYPHE scans the entire Internet weekly from three global vantage points. Use our data to find adversary infrastructure, track it across campaigns, and connect indicators before they reach you.

Hunt Threats. Track Infrastructure. Follow the Evidence.

Deep Internet mapping and Passive DNS built for analysts who need to find adversary infrastructure and follow it wherever it leads.

feature

No easy hiding places

Full URL scanning with redirect chain traversal, deep TCP and UDP port scanning across the IPv4 space, and hundreds of millions of IPv6 hosts scanned weekly. Adversary infrastructure has fewer places to hide than you might think.

feature

12 months of Passive DNS

Domain infrastructure changes constantly. ONYPHE's 12-month Passive DNS database lets analysts reconstruct how adversary infrastructure evolved over time, connecting current indicators to historical patterns and past campaigns.

feature

Track. Pivot. Attribute.

Adversary infrastructure doesn't stay still, but it leaves traces. ONYPHE's deep Internet mapping lets analysts pivot across IPs, domains, and hosting patterns to track infrastructure across campaigns and connect current activity to past behaviour.

Frequently Asked Questions

About ONYPHE's CTI Dataset

What analysts and security teams ask most about ONYPHE's Cyber Threat Intelligence data.

Onyphe takes a unique approach by scanning the entire Internet and Dark Web in a net-neutral manner since 2017. Unlike competitors that only show you what they choose to display, we scan every exposed asset—including ones you didn't know existed. Our domain-name-based approach is more effective than traditional IP-only methods, helping you discover hidden risks before cybercriminals do.

Our solution is specifically designed to cut ransomware exposure up-front by identifying the initial access vectors attackers use: exposed RDP/VNC services, vulnerable VPN servers, and critical exploits waiting to be leveraged. By continuously monitoring your digital footprint in real-time, we alert you to vulnerabilities before they can be exploited—saving you from the millions of euros typically spent on breach recovery.

We take ethical internet scanning seriously. Our founder and CTO presented our "10 Commandments for Ethical Internet Scanning" at the Cyber Threat Intelligence Summit 2022. We:

    Publish transparent web server explanations for all probes
    Provide opt-out email addresses for removal requests
    Use fixed IP addresses (not disposable ones)
    Scan slowly to avoid stressing networks
    Honor data removal requests promptly

We operate with full transparency and respect for network owners worldwide.

Yes! For organizations with specific requirements, we provide:

     Unrated API options for high-volume needs
     Customizable dashboards tailored to your team's workflows
     Dedicated account management and priority support
     Volume discounts for annual commitments
     White-label solutions for service providers