Authorized Distributor · Middle East & Africa

Criminal IP Threat Intelligence & Attack Surface Management for the Middle East & Africa.

Uncover threats before they strike your region.

reconn is the authorized Criminal IP distributor for the Middle East and Africa. We license, deploy and support Criminal IP TI and Criminal IP ASM for MSSPs, channel partners, SOC teams, threat analysts and government security operations across the GCC, the Levant, North Africa and Sub-Saharan Africa.

Authorized Middle East & Africa DistributorMSSP & Channel Program4.29B IPs Scanned100+ OSINT SourcesMITRE ATT&CK AlignedOn-Premise & Air-GappedSIEM / SOAR / XDR ReadyDark Web Monitoring

Two products, one intelligence layer: Criminal IP TI for IP intelligence, domain intelligence and threat actor tracking, Criminal IP ASM for attack surface management across everything you own and did not know you owned. Regional licensing, procurement and support handled by reconn as distributor.

4.29 billion
Global public IP addresses scanned in approximately 3 days, continuously. Live infrastructure, not a historical database.
100+ sources
Proprietary global scanners, a distributed honeypot network and 100+ OSINT feeds correlated into one record per asset.
Surface to dark web
Exposure detection across the surface web, deep web and dark web, including leaked credentials tied to your organization.
Risk Scoring
5 severity tiers, inbound and outbound
Asset Discovery
2–3 days from one domain to full inventory
Access Methods
4 search engine, API, on-prem DB, feeds
Monitoring
Daily continuous re-scan of every discovered asset
In short

reconn is the authorized Criminal IP distributor for the Middle East and Africa. Criminal IP is a cyber threat intelligence search engine and attack surface management platform built by AI SPERA. reconn holds regional distribution, which means licensing, procurement, deployment, integration, partner enablement and support all happen in-region, in your time zone, under contracts your finance team can actually process.

The region needs that combination. Organizations here run hybrid cloud estates across multiple jurisdictions, under regulators that do not share a rulebook, while state-aligned and criminal actors work through the same critical infrastructure, financial and government networks year after year. Global tooling rarely reflects that picture, and global vendors rarely answer the phone at the right hour.

Criminal IP scans the entire public IPv4 space continuously, runs its own honeypot network, and folds in more than a hundred OSINT sources plus dark web collection. The output is not a pile of raw indicators. It is a decision-ready record for an IP, a domain or a threat actor, with the context an analyst needs to triage, hunt, attribute and contain without leaving the tool.

This page covers both halves of the platform: Criminal IP TI for IP intelligence, domain intelligence and threat actor tracking, and Criminal IP ASM for attack surface management across everything your organization exposes to the internet. It also covers how we work with MSSPs and channel partners across the region.

Distribution

Authorized Criminal IP distributor for the Middle East and Africa.

Channel

MSSPs, resellers, system integrators and consultancies, with deal registration.

Coverage

GCC, Levant, North Africa and Sub-Saharan Africa.

Support

Regional pre-sales, deployment, integration and escalation.

Regional Demand

Why Demand for Criminal IP Intelligence Is Growing in Dubai, Abu Dhabi & Riyadh.

Three cities are driving most of the threat intelligence and attack surface management spend in the region, for three different reasons. If you run a security team, an MSSP, or a channel business in any of them, the pattern below will be familiar.

United Arab Emirates

Dubai

The regional headquarters city. Financial services, aviation, logistics, hospitality and the largest concentration of MSSPs, integrators and security distributors in the Middle East. Dubai government entities work to the Dubai Electronic Security Center's Information Security Regulation, DIFC firms sit under their own data protection regime, and federal entities under the UAE Information Assurance Regulation.

The practical effect is that a Dubai security team is usually answering to more than one framework at once, across an estate spread over free zones, multiple clouds and a long tail of third parties. That is an attack surface problem before it is a threat intelligence problem, and most teams discover it in that order.

DESC ISRUAE IA RegulationDIFC DP LawMSSP density
United Arab Emirates

Abu Dhabi

Critical national infrastructure and sovereign capital. Energy, utilities, aviation, healthcare and government sit here, alongside ADGM as a financial free zone and ADHICS as a sector-specific standard for healthcare. The exposure profile skews heavily toward operational technology, industrial systems and long-lived infrastructure that was never designed to be internet-reachable.

Two consequences follow. Exposed OT and IoT assets need to be found continuously rather than audited annually, and deployment often has to be on-premise or air-gapped because the data cannot leave the environment. Both are buying requirements before they are feature preferences.

ADHICSADGMCNI & OTAir-gapped
Saudi Arabia

Riyadh

The fastest-growing security market in the region, and the most prescriptive. The National Cybersecurity Authority's Essential Cybersecurity Controls apply to government and critical national infrastructure, with separate cloud and critical systems controls layered on. SAMA's framework governs financial services, the Personal Data Protection Law is administered by SDAIA, and CITC covers telecom and ICT.

On top of that sits Vision 2030. Giga-projects and rapid cloud migration are creating new external attack surface faster than any manual inventory can track it, and much of it is greenfield infrastructure standing up in months rather than years. Local presence and data residency expectations also make in-region distribution and on-premise deployment close to mandatory.

NCA ECCSAMA CSFPDPLVision 2030

What Is Driving It

01

Regulation names it explicitly

Continuous monitoring, threat intelligence and asset inventory are no longer implied by regional control catalogues. They are line items an auditor asks you to evidence.

02

Attack surface is outgrowing the inventory

Cloud migration, giga-projects, acquisitions and shadow IT add external assets faster than a spreadsheet-based inventory can absorb them. Nobody knows the real number.

03

The region is specifically targeted

State-aligned espionage against energy, government and finance, plus hacktivism that spikes with regional events. Generic global feeds under-represent both.

04

Analyst supply is the bottleneck

Hiring cannot keep pace with alert volume anywhere in the region. Decision-ready intelligence beats a raw indicator feed when there is nobody free to enrich it.

05

Sovereignty pushes deployment local

Data residency expectations in Saudi Arabia and the UAE make on-premise and air-gapped options a requirement, and make an in-region distributor the practical route to buy.

06

The MSSP market is scaling fast

Regional SOCs are being built at pace. Every one of them needs an intelligence layer it can license, automate against and resell inside its own managed service.

For MSSPs and channel partners in Dubai, Abu Dhabi and Riyadh: this demand is landing in your pipeline as questions you already get asked. What is exposed on our perimeter, who is targeting us, is this indicator worth escalating, and can you prove it. Criminal IP answers all four with evidence, and it attaches to services you already sell rather than requiring a new one. reconn handles the licensing, enablement and pre-sales so your team can lead with the outcome. See the partner program.

Criminal IP TI

IP Intelligence & Domain Intelligence, Decision-Ready.

Criminal IP TI brings IP intelligence, domain intelligence and emerging threat data into a single platform. Rather than aggregating raw indicators, it surfaces the context analysts across the Middle East and Africa actually need to triage alerts, hunt threats, investigate incidents and decide, without switching tools or sources.

IP Intelligence

Scanned and indexed through proprietary global infrastructure, a distributed honeypot network and 100+ OSINT sources.

  • AI risk scoring across 5 severity tiers, inbound and outbound
  • Open ports, service banners and application fingerprinting on every port
  • CVE and CWE mapping with ExploitDB and GitHub PoC references
  • VPN, Proxy, Tor, Anonymous VPN, Hosting, CDN and Mobile classification
  • C2 server identification across major attack frameworks
  • Scanner IP detection with targeted ports and activity history
  • Abuse records, threat actor attribution and SSL certificate data
  • Domain history mapped to the IP and categorized by threat type

Domain Intelligence

Real-time domain and URL scanning returns structured domain intelligence across every key risk dimension.

  • Phishing detection and malicious domain classification
  • SSL/TLS configuration scanning for misconfigurations and vulnerabilities
  • CVE and CWE mapping with exploit and PoC references
  • Sub-domain enumeration and discovery
  • Domain risk scoring with contextual severity
  • Redirection chain analysis across countries, ASNs and domains
  • Exposed configuration file detection: Git, Firebase, phpinfo, WordPress
  • JARM hashing, tech stack vulnerability mapping and packet log analysis

Threat Actor Monitoring

Deep insight into advanced persistent threats and the infrastructure they operate against this region.

  • IOCs, IOAs, TTPs and CVEs linked to named threat actors
  • Attack indicators mapped across the kill chain, from reconnaissance to exfiltration
  • Attacker-controlled resource identification
  • Techniques mapped to the MITRE ATT&CK framework
  • Geographic targeting, including Middle East and Africa campaigns
  • Compromised asset discovery: C2 servers and exfiltration nodes

Coverage

What Criminal IP Tracks

  • Hacking groups and APTs — threat actor infrastructure and live campaigns
  • Command and control — active C2 server detection and tracking
  • Malware and abuse records — historical breach data and malicious activity
  • CVE/CWE intelligence — vulnerability exposure and exploit readiness
  • Anonymization services — VPN, Proxy, Tor and Anonymous VPN detection

And What Most Tools Miss

  • Real IP detection — unmasking the true source behind Cloudflare and similar services
  • Domain reputation — category-based classification of every scanned domain
  • OSINT data — public intelligence from continuous internet-wide scans
  • Policy violations — misconfigured, exposed and non-compliant hosting infrastructure
  • Breach history — accumulated IDS, malware, phishing and ransomware activity per asset

Access Methods

For Engineering

REST API

Structured JSON responses for direct integration into SIEM, SOAR, XDR and custom security workflows. Documented, versioned and built for automation at volume.

  • Full-featured RESTful endpoints
  • Dedicated integrations including Splunk and Cisco
  • Custom integration support
For Classified Environments

On-Premise Database

Self-hosted threat intelligence for instant, scalable investigation with no external calls. Built for air-gapped, classified and high-performance requirements common across regional government and defense.

  • No outbound dependency
  • Scales to high query volume
  • Data residency friendly

Threat intelligence feeds. Continuously updated feeds on malicious IPs, domains and infrastructure, formatted for direct ingestion into firewalls, proxies and orchestration tooling. Customizable to the indicator types and confidence thresholds your team actually acts on. Ask about feed formats.

Criminal IP ASM

Attack Surface Management for the Middle East & Africa.

Traditional attack surface management tools hand you an asset list. Criminal IP ASM enriches every discovered asset with live threat intelligence, so the output is not an inventory to work through but a ranked set of things that actually matter. Deployed and supported across the region by reconn.

Continuous Discovery

One domain or IP is enough to start. Everything connected to it is found, classified and kept current.

  • Auto-discovery from a single domain or IP entry
  • New assets identified and classified as they appear
  • Domains, certificates, cloud infrastructure, IoT devices and exposed services
  • Categorized by geography, cloud provider, ASN and application type

Superior IP & Domain Intelligence

The same intelligence layer behind Criminal IP TI assesses every asset ASM finds.

  • Advanced domain scanning and IP analysis on discovered assets
  • Instant visibility into malicious activity and compromised assets
  • Emerging threat detection across the whole attack surface
  • Real-time enrichment with threat context, not just a status flag

AI-Automated Vulnerability Validation

Beyond CVE discovery. Risk is prioritized from context, not from a severity score alone.

  • Automatic vulnerability mapping for every discovered asset
  • Dangerous and critical port identification on registered IPs
  • Connected application analysis across all detected ports
  • Automated correlation with emerging exploits and attack patterns

OSINT-Powered Exposure Detection

Hidden and exposed assets, surfaced from three layers of the web rather than one.

  • Google Hacking detection for exposed configuration files
  • Leaked API keys and exposed documents on the surface web
  • Hidden assets and sensitive data across the deep web
  • Dark web monitoring for leaked accounts and credentials

Certificate Monitoring

SSL/TLS lifecycle tracked automatically, so an expiry never becomes an incident.

  • Automated certificate discovery and monitoring
  • Expiration tracking with alerting ahead of the date
  • Self-signed and invalid certificate identification
  • TLS configuration scanning for misconfigurations

Risks Beyond CVEs

Most of what compromises an organization is not sitting in a vulnerability database.

  • C2 servers and command injection points on your own estate
  • Anonymization services: VPNs, proxies and Tor nodes
  • Policy violations, abuse records and threat actor infrastructure
  • Real IP detection behind proxies and CDNs, plus phishing and fraud domains

Real-Time Alerts & Updates

Daily continuous monitoring, with alerts that arrive already carrying their context.

  • New asset discovered, or a new exposure on an existing one
  • Certificate expiring or already expired
  • Credential leak detected on dark web sources
  • Threat context changed, for example an asset now linked to malicious activity

Risk Prioritization

Automated High, Medium and Low tiering driven by threat intelligence, not by CVSS in isolation.

  • AI-driven correlation of vulnerabilities, exploits and threat data
  • Intelligent scoring that surfaces the most critical threats first
  • Less time spent on non-critical findings
  • Pressing exposures addressed before cosmetic ones

Collaboration & Integration

Findings move into the workflow your team already runs, with a record of what was decided.

  • Built-in comments and team coordination on each finding
  • Clear documentation of risk analysis and mitigation steps
  • API-first design with REST endpoints and structured JSON
  • SIEM, SOAR, XDR and vulnerability management integration

Three Layers of Exposure

Surface Web — OSINT

Google Hacking results, public databases, exposed documents, leaked API keys and configuration files that any search engine can already reach.

Deep Web

Hidden assets and sensitive data behind authentication, forms and unindexed paths, routinely missed by conventional ASM tooling.

Dark Web

Continuous monitoring of dark web sources for leaked accounts and credentials tied to your organization, so exposure is caught before it is used.

Manual or automatic. Manual Asset Registration ASM scans the IP ranges and domains you register. Automatic Asset Detection ASM takes a single domain or IP and discovers every related IP and subdomain within two to three days, then keeps finding new ones. Most organizations start automatic and add manual entries after an acquisition or for a subsidiary audit. Ask which fits your estate.

Distribution & Channel

reconn is the Criminal IP Distributor for the Middle East & Africa.

Criminal IP is built by AI SPERA. reconn holds authorized distribution for the Middle East and Africa, which means every commercial and technical step happens in-region: licensing, procurement, deployment, integration, enablement and escalation.

What distribution actually means here

  • Regional contracting so procurement is not chasing a vendor entity in another hemisphere
  • Local invoicing and currency handling, with the documentation finance teams need to raise a PO
  • Pre-sales engineering from people who have deployed the platform, not a shared inbox
  • Deployment and integration into your SIEM, SOAR or XDR, including on-premise and air-gapped builds
  • Escalation into AI SPERA when a case needs the vendor, managed by us rather than by you
  • Time zone overlap for the working day you actually operate in

Who we work with

  • MSSPs and MDR providers embedding threat intelligence into a managed SOC service
  • Resellers and value-added resellers selling into enterprise and government accounts
  • System integrators delivering SOC build-outs and security transformation programs
  • Consultancies and advisory firms running threat exposure and attack surface assessments
  • Government and defense integrators requiring on-premise and air-gapped deployment
  • Telcos and cloud providers building security services on top of their own infrastructure

Partner Program

01

Deal Registration

Register an opportunity and it is protected. Margin is predictable, and you are not competing against the vendor or against another partner on the same account.

02

Demo & NFR Access

Not-for-resale access so your team can learn the platform properly, plus demo reports on a prospect's real attack surface to open the conversation with evidence.

03

Pre-Sales Engineering

We join your calls. Scoping, architecture, proof of concept and technical objection handling, so a smaller channel team can still sell a technical product.

04

Technical Enablement

Training for your analysts and engineers on Criminal IP TI and ASM, delivered on-site or online, so delivery does not depend on one person who read the docs.

05

Co-Marketing

Joint campaigns, regional events, webinars and content built around your accounts rather than a generic vendor template.

06

Service Design Support

For MSSPs building a productized offering, help shaping what the service includes, how it is priced per client, and how the API automation is structured.

Regional Coverage

GCC

United Arab Emirates, Saudi Arabia, Qatar, Kuwait, Bahrain and Oman. Our home market and the densest concentration of regulated SOC and critical infrastructure work.

Levant & Wider Middle East

Jordan, Lebanon, Iraq and neighboring markets, typically through in-country partners with existing enterprise and government relationships.

North Africa

Egypt, Morocco, Algeria, Tunisia and Libya, where financial services and telecom security programs are moving quickly.

Sub-Saharan Africa

Nigeria, Kenya, Ghana, South Africa, Ethiopia, Tanzania and beyond, largely through MSSPs and integrators building regional SOC capability.

Already selling security in the region? Threat intelligence and attack surface management attach cleanly to almost every security service, from managed detection to compliance assessments, because the output is evidence rather than another dashboard your client has to learn. Open a partner conversation and we will map it to what you already sell.

What Changes

Five Things Your Team Stops Doing By Hand.

These hold for TI and ASM alike, because both run on the same intelligence layer. The difference is only whether you are pointing it at someone else's infrastructure or your own.

01

Uncover Hidden Threats

Comprehensive visibility powered by real-time IP intelligence, domain scanning, and OSINT plus dark web monitoring. You see what single-source tooling structurally cannot.

02

Eliminate Alert Fatigue

Intelligent risk scoring surfaces the threats that need attention now, so analyst hours go to the queue that matters instead of the one that is longest.

03

Accelerate Response

Mean time to respond drops when complete threat context and remediation guidance are already attached to the indicator rather than assembled during the incident.

04

Maintain Asset Visibility

Continuous discovery identifies and classifies new assets as the estate expands, so the inventory does not quietly go stale between audits.

05

Strengthen Your Security Posture

Real-time domain and IP intelligence exposes weaknesses while they are still weaknesses. Decisions get made against what is live on your perimeter today, not against a quarterly report describing what was live when it was written.

Security Operations

Six Workflows Your Team Already Runs.

Criminal IP is not a new process to adopt. It slots into the six things a SOC does every day and removes the part where an analyst opens six browser tabs to build context by hand.

Workflow 01

Alert Triage

Analysts use threat scoring, abuse history and behavioral signals to enrich alerts from existing tooling, prioritize high-risk indicators and cut investigation noise.

Criminal IP valueInstant threat context removes the blind spots in conventional alert enrichment.
Workflow 02

Threat Hunting

Pivot from a single IP or domain to related infrastructure: connected IPs, subdomains, shared services and shared hosting that reveal the wider campaign.

Criminal IP valueFiltered search and pivoting expose complete attack infrastructure in minutes.
Workflow 03

Incident Response

During an incident, infrastructure intelligence and historical context explain attacker behavior, support containment decisions and track attacker-controlled assets.

Criminal IP valueThreat actor tracking and C2 detection accelerate containment and forensics.
Workflow 04

Phishing & Malicious Domain Analysis

Analyze domains and URLs for phishing behavior, suspicious redirect chains and exposed content, so a report can be validated or dismissed quickly.

Criminal IP valuePhishing detection and URL analysis validate a domain without manual inspection.
Workflow 05

Infrastructure Attribution

Correlate IPs, domains and hosting data to identify patterns, link infrastructure to threat actors and track campaign activity over time.

Criminal IP valueMITRE ATT&CK mapping ties observed infrastructure to known actors.
Workflow 06

Exposure & Risk Identification

Use scan data and vulnerability insight to find exposed services, misconfigurations and viable attack vectors across your own infrastructure.

Criminal IP valueAutomated discovery and prioritization end the manual asset inventory.

Built For

Built for MSSPs, SOC Teams & Security Leaders Across the Middle East & Africa.

Managed Security Service Providers

Deliver more value to your clients

Criminal IP TI and ASM give your SOC decision-ready intelligence to detect threats faster, reduce alert fatigue and hand clients richer incident context. The differentiator is scale: global threat actor tracking, real-time OSINT and dark web monitoring across every account you manage.

  • Threat hunting across client infrastructure
  • White-label reporting inside your existing workflows
  • API-driven automation across multiple client environments
  • Continuous monitoring for the whole managed portfolio
Enterprise SOC Teams

Uncover what traditional tools miss

Integration with your existing SIEM and SOAR brings threat intelligence into the workflows analysts already live in. Detect compromised assets, investigate events with full infrastructure context and make containment calls faster.

  • Enrichment for alert triage and incident response
  • Threat actor infrastructure tracking scoped to your organization
  • Attack surface monitoring tied to internal vulnerability data
  • Tool consolidation onto one intelligence layer
Threat Analysts & IR Teams

Investigate faster, decide with confidence

Search-powered threat hunting, dark web monitoring and threat actor tracking put detailed context in one place, so an investigation stops being an exercise in context switching.

  • Threat hunting search engine with advanced filters
  • Attacker infrastructure correlation and mapping
  • Credential leak detection and exposure monitoring
  • Real-time incident context and historical trend analysis
CSOs & Security Leaders

Visibility into your external attack surface

Automated asset discovery and risk prioritization reduce blind spots and make sure the vulnerabilities that matter get the attention, with reporting that survives a board conversation.

  • Automated attack surface discovery and monitoring
  • Risk-driven dashboard showing high-impact exposures
  • Compliance and regulatory reporting capabilities
  • Board-ready risk metrics and trend analysis
Regional & Government Security Operations

Specialized intelligence for the Middle East & Africa

Track threat actors targeting the region, follow infrastructure linked to regional campaigns and stay ahead of emerging threats, with a deployment model that works inside classified environments.

  • Region-specific threat actor tracking
  • Infrastructure linked to campaigns targeting the Middle East and Africa
  • On-premise deployment for data residency requirements
  • Support for regional CISO and national security initiatives

Feature Matrix

Criminal IP TI & ASM, Feature by Feature.

CapabilityWhat you get
IP IntelligenceGlobal scanning, honeypot network and 100+ OSINT sources. AI-based 5-tier risk scoring, open ports and service banners, CVE/CWE mapping, VPN/Proxy/Tor/C2 detection, abuse records, SSL certificates and domain history.
Domain IntelligenceReal-time scanning across every risk dimension: phishing detection, SSL/TLS configuration scanning, CVE mapping, sub-domain enumeration, risk scoring, redirection analysis, exposed config detection, JARM hashing and network packet analysis.
Threat Actor MonitoringIOCs, IOAs, TTPs and CVEs. Kill chain indicators, MITRE ATT&CK mapping, geographic targeting and compromised asset discovery.
Search EngineInteractive threat hunting with advanced filters, pivoting across related infrastructure, historical data access and flexible analysis.
API AccessRESTful API with structured JSON responses, custom integration and air-gapped environment support.
On-Premise DatabaseSelf-hosted intelligence, scalable investigations, no external calls and classified environment support.
Threat FeedsContinuously updated IOC feeds, malicious IP and domain lists, infrastructure data and straightforward integration.
Data FreshnessReal-time continuous updates. 4.29 billion IPs scanned in approximately 3 days, with continuous feed delivery.

Criminal IP TI and Criminal IP ASM share one intelligence layer. Organizations that run TI and ASM together get the same enrichment on an external indicator and on their own exposed asset, which is what makes attribution work in both directions.

Why Criminal IP

Eight Reasons Middle East & Africa Teams Choose Criminal IP.

01

Real-Time Global Intelligence

Continuously scanned data rather than a historical database. The context competitors report is often already stale.

02

Decision-Ready, Not Raw

Context-rich records built for analysts, not IOC dumps that need manual enrichment before anyone can use them.

03

Deep Threat Actor Tracking

Monitor actors targeting the Middle East and Africa, with MITRE ATT&CK mapping and infrastructure correlation.

04

Integrated ASM

Attack surface management powered by threat intelligence, not asset discovery with a vulnerability scan bolted on.

05

Seamless Integration

API-first design that fits the SIEM, SOAR, XDR and vulnerability management stack you already operate.

06

OSINT to Dark Web

Detection across surface, deep and dark web in one platform, instead of three subscriptions and a spreadsheet.

07

Scales Across the Org

On-premise for air-gapped environments, API for automation, search engine for the humans doing the hunting.

08

Regionally Supported

Procurement, deployment, integration and support handled in-region by reconn, in your time zone.

Trust Indicators

4.29B

Global public IP addresses scanned approximately every 3 days, 24/7, by proprietary infrastructure.

100+

OSINT sources correlated alongside a proprietary honeypot network and global scanners.

5 tiers

Risk scoring with no reported data reliability issues when blocking on Dangerous or Critical ratings.

Real IP detection unmasks sources behind Cloudflare, VPNs and mobile proxies. Threat actor tracking is aligned to MITRE ATT&CK. Breach history is collected through C-TAS, CTI feeds and Criminal IP's own honeypot operations.

Questions

Criminal IP, Frequently Asked.

What is Criminal IP Threat Intelligence?

A threat intelligence platform providing real-time, decision-ready intelligence on IP addresses, domains, threat actors and emerging threats. It combines global IP scanning, honeypot networks, 100+ OSINT sources and dark web monitoring in a single platform, covering alert triage, threat hunting, incident response and infrastructure attribution.

How does it differ from other threat intelligence products?

Criminal IP updates its intelligence by continuously scanning global IPs, monitoring ports and operating honeypot servers to detect active threats and C2 infrastructure. Rather than serving history-based data, it scans 4.29 billion IP addresses in approximately 3 days on a continuous cycle, so the record you read reflects what is live now.

What data do I get on an IP address?

AI-based 5-tier risk scoring for inbound and outbound traffic, open ports with service banners and application fingerprinting, CVE and CWE mapping with exploit references, VPN/Proxy/Tor/Anonymous VPN/Hosting/CDN/Mobile classification, C2 server identification, scanner IP detection, abuse records with threat actor attribution, SSL certificate data and domain history mapped to the IP.

What domain intelligence is available?

Phishing detection, SSL/TLS configuration analysis, CVE and CWE mapping, sub-domain enumeration, domain risk scoring, connected IP reputation, redirection chain analysis, exposed configuration file detection, JARM hashing with tech stack vulnerability mapping, and network packet log analysis on URL access.

How often is the data updated?

Collection runs continuously in real time. All 4.29 billion global public IP addresses are scanned approximately every 3 days, with continuous updates pushed to the platform between full sweeps.

Can it integrate with our existing security tools?

Yes. Criminal IP TI integrates with leading SIEM, SOAR and XDR platforms through a full-featured RESTful API with structured JSON responses, dedicated integrations with platforms including Splunk and Cisco, customizable threat intelligence feeds, and custom integration support where a specific requirement is not covered. Ask us to scope the integration.

How reliable is the risk scoring?

Criminal IP's 5-level risk scoring has no reported errors or data reliability issues when organizations block IPs rated Dangerous or Critical. The continuous scanning methodology is what supports that validity, and it is why customers are comfortable wiring the scores directly into firewall systems.

Can it detect the real IP behind Cloudflare?

Yes. Criminal IP can track and identify the real source IP of malicious users hidden behind Cloudflare and similar services, and it detects IP addresses masked by VPNs, mobile proxies and other anonymization services.

What is breach history data?

Accumulated malicious activity information for an asset, including activity detected by IDS, malware, phishing and ransomware. It is collected through C-TAS (Criminal IP's Threat Advisory System), cyber threat intelligence feeds, and Criminal IP's own honeypot operations.

Is the platform customizable for our requirements?

Universally applicable features are developed on the product roadmap. For customer-specific requirements, custom development is available, with additional cost for the customization and implementation work. Enterprise B2B contract customers also get access to Criminal IP TI training, delivered on-site or online.

What access methods are available?

Four: the interactive search engine for threat hunting, the RESTful API for integration and automation, an on-premise database for self-hosted and air-gapped environments, and customizable threat intelligence feeds for ingestion into existing tools.

How do we buy it in the region?

Through reconn. We handle regional licensing, procurement paperwork, deployment and ongoing support, so you are not managing a vendor relationship across time zones. Open a comms channel and we will size it against your environment.

Open a comms channel

Get Started With Criminal IP in the Middle East & Africa.

Two routes in. If you are securing your own organization, we will size Criminal IP against your environment and show you what it finds before you commit to anything. If you sell security in Dubai, Abu Dhabi, Riyadh or anywhere across the region, we will map the partner program to what you already sell. Either way you are talking to the authorized distributor, not a reseller of a reseller.

Scanners live · 4.29B IPsMiddle East & Africa coverageChannel program open

Direct Lines

Criminal IP is built by AI SPERA. reconn is the authorized distributor for the Middle East and Africa, handling licensing, procurement, deployment, integration, partner enablement and support in-region. A demo report on your own attack surface is the fastest way to see whether this is worth your time.