PRODUCT BY GANASEC

Threat intelligence your team can deploy.

DetectHQ monitors 60+ sources, validates indicators, tracks actor and vendor exposure, scans software supply-chain risk, and generates detection logic your team can ship into real workflows.

detecthq.in / intelligence loop
feed.monitor --sources 60+
indexed: 4,800+ intel items
actors: 367+ MITRE-mapped groups
vendors: 437 ranked by real-world exposure
ioc.validate --sources vt, abuseipdb, otx, mb, threatfox, pulsedive, greynoise
rules.generate --formats yara,sigma,kql,python
push: slack, webhook, splunk, sentinel, elastic, api, mcp
Threat feeds monitored
60+
Intel items indexed
4,800+
Vendors ranked
437
Connected modules
7
WHY IT EXISTS

Signals become actions.

Most small SOC, AppSec, MSSP, SaaS, and fintech teams do not need another pile of reports. They need fast answers: which indicator is real, which vendor affects us, which package is risky, and what detection can we deploy now.

01Collect

DetectHQ watches threat feeds, vendor risk, package signals, indicators, and public exposure.

02Verify

Indicators are cross-checked, scored, deduplicated, and mapped to sources your team can review.

03Generate

Validated intelligence becomes YARA, Sigma, KQL, Python, STIX, CSV, or API-ready output.

04Push

Intel lands in Slack, webhooks, SIEMs, terminals, MCP clients, or your existing workflow.

MODULES

Seven modules. One intelligence loop.

DetectHQ connects feed triage, discovery, OSINT, vendor tracking, supply-chain checks, attack-surface monitoring, fraud intelligence, and integrations in one workflow.

0160+ feeds monitored

Threat Dashboard

Live intel volume, severity trends, active sources, and a rolling timeline in one command center.

02367+ actors tracked

Discovery

Search actors, CVEs, vendors, and risk categories without jumping across disconnected tools.

037+ ecosystems

Supply Chain Security

Typosquat checks, dependency-confusion detection, SBOM upload, and SCA enrichment.

04Sub-second lookups

IOC Validate

Cross-check IPs, domains, hashes, URLs, and emails against seven trusted OSINT sources.

05Public exposure only

Attack Surface

Track public domains and IPs, detect changes, and see which assets are affected by new risk.

06Built to plug in

Integrations

CLI, MCP server, REST API, SIEM push, Slack/webhook alerts, and exportable intelligence.

07Fintech-ready

BIN Monitoring

Fraud and carding intelligence for fintech, payment, issuer, and risk teams.

WHO IT HELPS

Built for teams without a full-time intel desk.

Lean SOC and security teams replacing manual feed triage.
MSSPs that need repeatable external intelligence workflows across clients.
AppSec teams watching packages, SBOMs, dependencies, and vendor exposure.
Fintech and payment teams monitoring BIN ranges, fraud signals, and carding exposure.
PLANS

Start small, then scale the intelligence loop.

DetectHQ is designed so teams can test real output first, then move into Pro, Team, or Enterprise when the workflow proves itself.

Free
$0
Test the output before committing

Trial, light API access, watchlist items, and view-only detection rules.

Team
$150/mo
Built for a small SOC

More seats, higher limits, watchlists, and attack-surface scope for team workflows.

Enterprise
Custom
Full scale and custom controls

Unlimited attack-surface workflows, SIEM push, TAXII, email OSINT, SLA, SSO, and on-prem options.

DETECTHQ.IN

See DetectHQ against your own indicators, vendors, or repositories.

Bring a live IOC, public GitHub repository, vendor list, or issued BIN range. The best demo is your real workflow, not a rehearsed dashboard tour.