🎉 Exciting news! Coalition has acquired Wirespeed to accelerate cybersecurity for all.
Skip To Main Content

Coalition Signals Intelligence

Global internet exposure intelligence at scale

Coalition Signals Intelligence delivers real-time visibility into open ports and exposed services across the public IP address space, enabling better attack surface management, threat intelligence enrichment, and vulnerability prioritization1

Screenshot 2025-10-14 at 10.40.54

Why Coalition Signals Intelligence

Comprehensive coverage

Coalition scans the entire IPv4 space and regularly scans over 300 million public IPv6 addresses to provide industry-leading breadth.

Global perspective

Scans are captured from multiple countries and vantage points so exposures visible from different regions are detected and surfaced.

Actionable context

Over 40 modules extract application- specific details (not just open ports) — e.g., web server and SSL details, remote access services, email and DB servers, IoT and VPN devices — enabling faster, more accurate remediation.

Easy ingestion

Data is available in JSON lines format and retrieved via secure API; documentation and sample pipelines are provided for fast integration with SIEMs, SOARs, and data platforms.

Use-case ready

Designed to support attack surface management, threat intelligence enrichment, vulnerability prioritization and network forensics.

Enterprise-ready

Unlimited access options, global scanning and regular updates make this dataset suitable for threat intelligence, large-scale analytics, and security operations.

Data fields & formats

Data is designed to integrate with asset management and analytics platforms and is delivered with documentation and example pipelines for fast adoption.

Key fields
  • IP Address (IPv4 or IPv6)

  • Timestamp of scan

  • Open ports and protocols

  • Detected service & application details

  • Geolocation and ASN

  • Scan source region

Delivery formats & integrations
  • JSON lines via secure API

  • Sample ingestion pipelines for SIEM/SOAR

  • Exports for data science platforms

Use cases

Attack Surface Management

Discover exposed assets and open ports across corporate or third-party infrastructure using real-world scan data.

Threat Intelligence

Enrich IOCs with live port/service context to improve correlation and detection accuracy.

Vulnerability Management

Prioritize remediation based on observed exposure and public internet visibility.

Integrations

Delivered via API and designed for rapid ingestion:

  • JSON lines formatted

  • Incorporate into SIEM & SOAR pipelines

  • Compliment Asset management tools

Sample pipelines, secure API access and integration guidance are provided to accelerate deployment

Get started

Request a demo, data sample and pricing from the Coalition Data Sales Team.

Successfully submitted

Please read our Privacy Policy explaining how Coalition processes personal information.

Looking for BinaryEdge? Please see this FAQ regarding the shutdown of BinaryEdge:
Coalition Signals Intelligence is provided by Coalition Incident Response, Inc. dba Coalition Security®, a wholly owned affiliate of Coalition, Inc. It is based on regular scans of public IP addresses, and its completeness or accuracy cannot be guaranteed. Coalition Signals Intelligence is intended for general, informational purposes only, and not as legal, professional, or consulting advice; use of Coalition Signals Intelligence is solely at your own risk. Coalition disclaims all warranties, express or implied. Coalition Signals Intelligence results may vary or fluctuate based on factors outside of Coalition's control. Limitations and Exclusions apply.

Copyright © 2025 Coalition, Inc. All rights reserved.