layer7 threat intelligence

We watch the attack surface.

Passive collection across DDoS communities — booter channels, operator chatter, attack claims and proof-of-downtime reports. Everything below is live from the archive. Look up a Telegram handle to see what we hold on them.

try:

Messages

312

Attack claims

90

Target domains

46

Methods seen

46

Channels

1

Days of capture

190

Capture volume

last 90 days

Attack methods

From the archive

redacted attack claims · newest first
AttackSep 1 · 01:16 UTC
hxxp://check-host[.]net/check-report/498cece6kb85
hxxp://check-host[.]net/check-report/498cf1c0k329

TCP Socket vs OVH
AttackAug 31 · 17:13 UTC
hxxp://check-host[.]net/check-report/4981c49dk2a7
hxxp://check-host[.]net/check-report/4981c64fk12d

7x flooder
AttackAug 31 · 14:34 UTC
1x flooder
AttackAug 31 · 11:03 UTC
5x http2-flooder
AttackAug 31 · 11:01 UTC
3x http2-flooder
Indicators are shown defanged (hxxp://, example[.]com) and IP addresses partially masked. Intelligence is collected passively — we join, read and archive. No posting, no DMs, no interaction with operators.