Skip to content

The spine

What we are watching, and where it comes from

Global vendors see Kenya as a region. We see it as the dataset. These figures are read live from the platform — the same numbers our analysts work from.

141,196Vulnerabilities cataloguedMatched against the technologies each client actually runs.
1,682CISA known-exploitedFlagged where exploitation has been observed in the wild.
176Threat actors profiledMapped to MITRE ATT&CK techniques and tooling.
What we do not hold

Breach and infostealer monitoring runs behind a strict redaction boundary. Recovered credential values are read only to set an exposure flag and are never written to our systems — only field names survive ingestion. If your security team wants to walk that boundary with us, we will show you the code path.

Regional briefs

What is landing in Kenyan inboxes

Written by the analysts, from what our clients' own people report catching.

The first brief is being written

A monthly regional threat brief starts here. If you would rather not wait, an assessment gets you the same picture of your own estate now.

Commission an assessment

A brief tells you what is circulating. An assessment tells you what would work against you specifically, which is the question that decides a budget.

Or have it feed your simulations

On Seraph CTI, what appears in a brief becomes a simulation template the same week — so your people are tested on the lure that is actually being sent.