Coalition Signals Intelligence
Global internet exposure intelligence at scale
Coalition Signals Intelligence delivers real-time visibility into open ports and exposed services across the public IP address space, enabling better attack surface management, threat intelligence enrichment, and vulnerability prioritization1

Why Coalition Signals Intelligence
Comprehensive coverage
Coalition scans the entire IPv4 space and regularly scans over 300 million public IPv6 addresses to provide industry-leading breadth.
Global perspective
Scans are captured from multiple countries and vantage points so exposures visible from different regions are detected and surfaced.
Actionable context
Over 40 modules extract application- specific details (not just open ports) — e.g., web server and SSL details, remote access services, email and DB servers, IoT and VPN devices — enabling faster, more accurate remediation.
Easy ingestion
Data is available in JSON lines format and retrieved via secure API; documentation and sample pipelines are provided for fast integration with SIEMs, SOARs, and data platforms.
Use-case ready
Designed to support attack surface management, threat intelligence enrichment, vulnerability prioritization and network forensics.
Enterprise-ready
Unlimited access options, global scanning and regular updates make this dataset suitable for threat intelligence, large-scale analytics, and security operations.
Data fields & formats
Data is designed to integrate with asset management and analytics platforms and is delivered with documentation and example pipelines for fast adoption.
Key fields
IP Address (IPv4 or IPv6)
Timestamp of scan
Open ports and protocols
Detected service & application details
Geolocation and ASN
Scan source region
Delivery formats & integrations
JSON lines via secure API
Sample ingestion pipelines for SIEM/SOAR
Exports for data science platforms
Use cases
Attack Surface Management
Discover exposed assets and open ports across corporate or third-party infrastructure using real-world scan data.
Threat Intelligence
Enrich IOCs with live port/service context to improve correlation and detection accuracy.
Vulnerability Management
Prioritize remediation based on observed exposure and public internet visibility.
Integrations
Delivered via API and designed for rapid ingestion:
JSON lines formatted
Incorporate into SIEM & SOAR pipelines
Compliment Asset management tools