FREE Specialized cyber threat intelligence — provided free to organizations operating in Azerbaijan.

Intelligence on the threats aimed at Azerbaijan.

Caspint is a specialized threat intelligence platform for the organizations that defend Azerbaijan. We watch the adversaries, leaks and underground operations targeting the region — scoped to your .az footprint, assessed by analysts, refreshed daily, and free for companies operating here.

caspint · national threat dashboard
Defending organizations across Banking Energy Government Telecom Critical Infrastructure
The mission

Helping raise the cyber defense baseline across Azerbaijan.

Adversaries treat Azerbaijan as a single battlespace — moving between its banks, ministries, energy operators and telecoms. The organizations defending it should have an intelligence picture that does the same.

Caspint is built to be that picture: a shared, specialized intelligence capability that watches the threats facing organizations across Azerbaijan, then delivers each one exactly the slice that concerns it. Not another global tool with Azerbaijan as a rounding error — an intelligence service built around the .az namespace and the actors who operate against the region.

Because resilience can't depend on who can afford a license, full access is free for every organization operating in Azerbaijan.

Intelligence-led, not alert noise

Raw signal is correlated and assessed, so what reaches you is relevant and actionable.

Early warning

The goal is to surface a threat while it is still being prepared — before it reaches its target.

Free for everyone

No license fee, no procurement — so every defender in Azerbaijan can see the same picture.

The platform

Every module, one national picture.

Eleven modules make up the platform — each a stream of intelligence collected, correlated and filtered to what is actually relevant to Azerbaijan and to your organization. A detailed look at each follows below.

01

National Threat Dashboard

Your whole threat picture on one screen — exposure score, what changed overnight, and the critical items that need attention today.

unified viewdaily deltadrill-down
02

Credential Intelligence

Every leaked login tied to your .az domains — from stealer logs, combolists and breaches — flagged for reuse and freshness.

auto .az scopingreuse flagsexport
03

Threat Actor Intelligence

Dossiers on the groups operating against the region, filtered to who actually targets Azerbaijan and your sector.

origin/target filterslive victimologylinked IOCs
04

Attack Surface Intelligence

Continuous discovery of everything you expose to the internet, prioritized by real-world exploitation, not theory.

discoveryexploit-awareTLS checks
05

Telegram & Dark Web

Hundreds of closed channels and markets collected and indexed, with an alert the moment you're named.

closed-sourcenamed alertsfull-text
06

IOC Intelligence

A living repository of malicious indicators — addresses, domains, hashes — enriched and tied back to the actors behind them.

enrichmentactivity trackingactor pivot
07

Credit Card Monitoring

Stolen payment-card data for Azerbaijani banks, tracked by issuing bank so fraud teams can act on what's theirs.

by issuing bankfreshnessfraud export
08

Brand & Executive Protection

Look-alike domains, exposed executives and leaked documents caught before they're weaponized.

look-alike domainsexec exposureleaked docs
09

Threat News

Curated regional threat reporting, correlated to the actors and indicators it concerns.

regionalactor-linkeddaily
10

Statistics & Trends

The national picture over time — sector pressure, actor escalation and where your exposure is trending.

trendstop targetsbriefing-ready
11

Analyst Workbench

One investigative surface to triage any indicator, run bulk lookups and pull every dataset into a single case.

triagebulk lookupscase view

Eleven modules.
One platform. Free for Azerbaijan.

For any organization defending an .az domain — no license, no procurement.

Request access
Inside the platform

Built for the work analysts actually do.

01 · National Threat Dashboard

Your command picture, the moment you log in.

The dashboard is the first screen every morning — a single command view that pulls together your current exposure score, everything that changed in the last 24 hours, the adversaries active against your sector, and the handful of critical items that genuinely need attention today. Nothing important waits buried in a report nobody opened.

  • One pane across every module — credentials, surface, actors and underground together.
  • A clear "what changed since yesterday" so you start with the delta, not the noise.
  • Drill from any tile straight into the underlying intelligence.
caspint · dashboard
02 · Credential Intelligence

Every leak, mapped to your organization.

Define your organization once. From then on, every information-stealer log and breach dump we ingest is automatically scoped to your domain and all of its subdomains. No manual filtering, no irrelevant noise — just the exposures that put your people and systems at risk, ranked so the urgent ones rise to the top.

  • Automatic .az scoping — your domain and every subdomain, captured without configuration.
  • Reuse & freshness flags highlight the accounts most likely to be exploited next.
  • Built for response — export the affected accounts straight into a reset workflow.
credentials · scope: *.az
03 · Threat Actor Intelligence

Understand the adversary, not just the alert.

Filter a database of thousands of tracked groups down to the ones operating against Azerbaijan and your sector. Each dossier brings together motivation, known tooling, targeting history and live victim counts — turning an abstract threat into a named adversary you can reason about and prepare for.

  • Filter by origin, target country & sector to isolate who matters to you.
  • Live victimology shows who each group is hitting right now.
  • Connected intelligence — indicators, news and underground mentions in one view.
threat-actors · target: AZ
04 · Attack Surface Intelligence

Your footprint, the way an attacker sees it.

Continuous scanning discovers your internet-facing hosts, fingerprints their services and certificates, and weighs each weakness by how likely it is to be exploited in the wild. Instead of a flat list of vulnerabilities, your team gets a prioritized picture of where an adversary would actually begin.

  • Exploit-aware prioritization puts the genuinely dangerous exposures first.
  • Certificate & TLS hygiene — expiry, validation and weak configurations.
  • Service fingerprinting down to software and version, refreshed continuously.
attack-surface · host map
05 · Telegram & Dark Web

The underground conversation, turned into warning.

We index every message across hundreds of threat-actor and leak channels, making the closed underground searchable. Look for your brand across all of it on demand — or let an alert reach you the instant your name surfaces in a market, a forum or a target list, with the original context preserved.

  • Closed-source collection from channels most teams never see.
  • Named-mention alerts the moment your organization appears.
  • Full context kept — the source and surrounding discussion, not just a keyword hit.
telegram · monitoring
06 · IOC Intelligence

From one indicator to the whole story.

Every malicious address, domain and file hash we hold lives in one searchable repository — automatically enriched with context and reputation, and kept current as its activity changes. Drop in a single indicator from an alert or a log and pivot straight to the actors, campaigns and related indicators behind it. The investigation starts where it used to end.

  • Addresses, domains & file hashes enriched with context and reputation automatically.
  • Tracked for ongoing activity, not frozen at first sighting.
  • One-click pivot from any indicator to the actors and cases it connects to.
ioc · lookup
07 · Credit Card Monitoring

Card fraud, caught at the source.

Stolen payment-card data for Azerbaijani banks surfaces constantly in carding channels and dumps. We collect it and organize exposure by issuing bank and BIN range, so a fraud team sees exactly the cards that belong to them — with volume and freshness signals to judge how urgent a batch is and move to reissue before losses mount.

  • Exposure organized by issuing bank and BIN range.
  • Volume & freshness signals to prioritize response.
  • Export ready for fraud, monitoring and reissue workflows.
credit-cards · by bank
08 · Brand & Executive Protection

Stop impersonation before it becomes an incident.

Most fraud and intrusion is staged in advance — a look-alike domain registered, an executive's details collected, a document leaked, a fake account stood up. We watch for those preparations across the open and closed web, so your team can take down or get ahead of an operation while it's still being assembled, not after the first victim.

  • Look-alike & typo-squatting domains flagged as they appear.
  • Exposed executives & leaked documents surfaced early.
  • Impersonation detection across social and messaging platforms.
brand · protection
09 · Threat News

Reporting that connects to your intelligence.

A continuously curated feed of threat news and regional reporting — but every item is correlated back to the platform. An article about a campaign links straight to the actor dossier, the indicators and the victims it concerns, so context isn't something an analyst has to reassemble by hand.

  • Regional & sector-relevant reporting, filtered for signal.
  • Stories linked to the actor dossiers and indicators they reference.
  • Updated daily, so the narrative keeps pace with the threat.
news · regional
10 · Statistics & Trends

The national threat picture, over time.

Point-in-time alerts tell you what's happening now; the statistics layer tells you where it's heading. See which sectors are under the most pressure, which actors are escalating, and how your own exposure is trending week over week — the view you put in front of leadership and use to justify where defense effort goes next.

  • Exposure & activity trends across the platform over time.
  • Top targeted sectors and most-exposed .az domains, ranked.
  • Briefing-ready views for reporting to leadership.
statistics · trends
11 · Analyst Workbench

One surface for the whole investigation.

The workbench is where it all comes together. Triage any indicator, run lookups at scale across the full dataset, and pull credentials, actors, surface and underground intelligence into a single case view — built for the tempo of a real operations team, so analysts spend their time deciding, not switching tabs.

  • Triage any IP, domain, email or hash on demand.
  • Bulk lookups & enrichment across the entire platform.
  • Every module cross-referenced into one working case.
workbench · case
Built around the nation

Intelligence shaped to the
sectors that hold the line.

The threats facing Azerbaijan don't fall evenly. Caspint is tuned to the institutions adversaries prioritize — and gives each of them the same national-grade visibility.

Banking & Finance

Credential exposure, financial-data leaks and ransomware pressure against the institutions that move the national economy.

Energy & Utilities

The sector nation-state actors prize most — monitored for exposure, targeting and the early signs of intrusion.

Government & Public Sector

.gov.az exposure, hacktivist target lists and leaked official documents surfaced early, before they spread.

Telecom & ISPs

Carrier-scale infrastructure exposure and subscriber-data leaks that ripple across the whole country.

Critical Infrastructure

Transport, water and industrial operators watched for the exposures attackers chain into real-world disruption.

Enterprises & SMEs

The same national-grade intelligence for every company defending an .az domain — regardless of size or budget.

0
Leaked credentials collected & searchable
0
Threat actors & ransomware groups tracked
0
Closed channels & forums under collection
How it works

From raw signal to early warning.

Caspint runs a continuous intelligence cycle focused on Azerbaijan — collecting broadly, analyzing centrally, and delivering each organization only what concerns it.

01 — COLLECTION

We watch the whole battlespace

Around the clock we collect breach dumps, criminal-market activity, ransomware leak sites and hundreds of closed channels — all centered on the .az namespace and the actors targeting the region.

02 — ANALYSIS

Signal becomes assessed intelligence

Raw data is enriched, de-duplicated and correlated against known adversaries, infrastructure and your own footprint — turning noise into a clear, prioritized national threat picture.

03 — WARNING

You act before it lands

What's relevant to you arrives as an alert. Your analysts triage it in the workbench, export for response, and move — often before an operation reaches its target.

Free for Azerbaijan

See what the adversary already sees.

If your organization operates an .az domain, you qualify for full, free access to Caspint. Request access and we'll scope the intelligence picture to your footprint.

no license fee · no procurement · free for .az organizations
Caspint
Mission Intelligence For Azerbaijan How it works Azərbaycanca → Request access →