Built by Security Engineers
for Security Teams

We know what it's like to be on the other side of the screen at 2am triaging alerts. We built Speculus because we needed it ourselves.

Who We Are

Industry experts.

We are a small, focused team of security engineers, threat researchers, and data scientists. People who have spent years at some of the top companies in the industry responding to incidents and building the kind of infrastructure, detections, automations, and ML models that keep us all safe.

We know what it is like to stare down thousands of alerts with no clear signal. We know the pain of stitching together five different tools just to get a complete picture of a single IP. That frustration is exactly what pushed us to build Speculus.

We are not a big vendor with a bloated platform and a sales team chasing you. We are engineers who care deeply about the quality of the intelligence we ship and we hold ourselves to a standard we would want on our own SOC.

Our Mission

Fixing a broken
intelligence market.

The "Network Threat Intelligence" space has some real problems. Stale data, vague descriptions and vendors selling the same recycled feeds dressed up in different packaging. Most products tell you an IP is risky or malicious without ever explaining the "why". This doesn't solve the problem it wastes your security teams time.

Our approach is different. We aggregate data from a massive number of sources and layer on top of that a network of monitoring nodes that watch emerging threats in real time. When a new botnet spins up, a Tor exit shifts, or a datacenter starts hosting malicious actors, we see it.

The goal is simple: give security teams the clearest, most actionable IP intelligence available so they can make faster decisions and spend less time chasing noise.

What makes us different

The first AI-Native Network Threat Intelligence Feed.

Most threat intelligence feeds are rule-based lookups against static blocklists. Speculus is built differently. We built the first AI-native network threat intelligence data feed, combining massive source aggregation with custom trained ML models and LLMs to understand network behavior at a level that static rules simply cannot reach.

Our models are trained on real network traffic patterns, known threat actor infrastructure, and behavioral signals that emerge long before an IP ever shows up on a blocklist. That means you are getting intelligence that is ahead of the curve, not behind it.

Want to work with us?

We're always interested in talking to sharp engineers and researchers who care about the threat intelligence space.

Get in Touch