VULONE
About us

Who we are

VULONE is a threat-intelligence outfit built around one idea: defenders should learn what leaked before attackers get to use it. We collect, correlate and index material from the criminal and grey corners of the internet (forums, private messages, ransomware operations, credential dumps) and turn it into something an analyst can act on: attribution with evidence, exposure with provenance.

VULONE began with the takedown of a sprawling credential operation: more than a hundred and twenty-five thousand environment files, hundreds of thousands of secrets, and the build, cloud and payment systems they unlocked. Rather than sit on it, we turned it into an index any developer can query in a second, and kept the evidence chain intact for the people whose job is to investigate it.

We work with incident-response teams, MSSPs, fraud units and law enforcement, and we are strict about what we publish: hashes and metadata, never live secrets. The evidence behind the index stays with the investigation. If you have a question about what you found, a correction, or a partnership in mind, we would like to hear from you.