Wallhacks by Windsor Security

Threat intelligence you can check.

Wallhacks clusters indicators from public intelligence feeds and publishes what it finds — with the corpus, the sources, and the methodology in the open. No unverifiable claims. No anonymous case studies.

What the engine is watching

as of August 5, 2026
132,167
Indicators in the corpus
803,451
Records in the feed index
5
Public feeds, indexed daily

Sources, named

Every feed is public and auditable. Nothing proprietary or undisclosed contributes to these figures.

  • phishing-db
    Reported phishing domains
    391,606
  • blocklist.de
    Hosts observed attacking public infrastructure
    374,251
  • Tor exit nodes
    Current Tor egress addresses
    22,050
  • abuse.ch URLhaus
    Malware distribution URLs
    15,537
  • abuse.ch Feodotracker
    Botnet command-and-control IPs
    7
  • abuse.ch SSLBL
    Botnet C2 SSL certificates — retired upstream
    retired

How it works

Four steps, and the last one is the one most tools skip.

01

Ingest

Public feeds are pulled on a daily schedule and filtered by indicator type, recency window, and TLD risk before anything enters the corpus.

02

Enrich

Each indicator is enriched against multiple providers, then normalised into a single scoring schema so signals from different sources stay comparable.

03

Cluster

Indicators and public threat reporting are embedded into a vector space and grouped without supervision, surfacing structure no analyst defined in advance.

04

Review

Nothing publishes automatically. Every finding is checked by a human against primary sources first.

Latest verified finding

Published one at a time, as each is checked against primary sources.

CVE-2025-59718CISA KEV · December 16, 2025

FortiCloud SSO authentication bypass

On 7 January 2026 the clustering run grouped four CISA-sourced advisory documents into a single coherent cluster centred on this vulnerability, with no analyst defining the campaign, the vendor, or the CVE in advance. The grouping formed roughly three weeks after the vulnerability entered CISA's Known Exploited Vulnerabilities catalogue.

Read the full finding and methodology →

Run your own indicators through it

The same engine behind the findings above is open for you to query.

Enrichment

Submit a domain, IP, hash, or URL and get normalised context from multiple intelligence sources in one response.

Correlation

See which other indicators share infrastructure or behaviour, so a single alert resolves into the wider picture.

Risk scoring

A 0–10 score with an explicit confidence level, built to support a triage decision rather than replace it.

Free to try, no account required

Paste in an indicator and see what comes back.