Independent Cybersecurity Monitoring Initiative for Central Asia

A non-profit project dedicated to enhancing digital resilience through OSINT aggregation and promoting open access to threat intelligence.

About Us

CSIRT-CA is an independent, non-profit initiative established to identify, aggregate, and disclose vulnerabilities, data leaks, and malicious C&C servers across Central Asia. By promoting openness in Threat Intelligence, we aim to assist organizations and National CERTs in proactively defending their infrastructure.

Monitoring Constituency

πŸ‡°πŸ‡Ώ Kazakhstan
πŸ‡°πŸ‡¬ Kyrgyzstan
πŸ‡ΉπŸ‡― Tajikistan
πŸ‡ΉπŸ‡² Turkmenistan
πŸ‡ΊπŸ‡Ώ Uzbekistan

Core Operating Principles

Zero Active Reconnaissance

The project does not conduct active scanning of networks, ports, or systems. All information is gathered passively from open sources (OSINT) in strict compliance with the cybersecurity legislation and criminal codes of the region.

1

Prioritizing Private Notification

While our social media channels serve as a tool to notify stakeholders about threats, we reserve the right and prioritize contacting organizations privately and directly whenever possible, provided the threat information has not been previously disclosed to the public.

2

Data Leak Policy

We strictly prohibit the publication of citizens' personally identifiable information (PII) from data leaks. However, we may indicate the source or origin of a leak if the disclosing party has explicitly made this information publicly available.

3

Depersonalized Public Disclosure

When threats remain unpatched or unaddressed, information is published on our public channels completely anonymized, detailing only the ASN or general nature of the vulnerability to raise regional situational awareness.

Open Data & Threat Feeds

As part of our commitment to transparency and community defense, CSIRT-CA will regularly publish depersonalized analytics and Indicators of Compromise (IoC) to our public repository.

View Repository on GitHub

Contact & Secure Communication

If you wish to report a security incident, request an embargo extension, or share sensitive intelligence (logs, memory dumps), please use our secure channels.

Email Address

info@csirt-ca.org

We strictly require the use of PGP encryption when transmitting sensitive data to ensure confidentiality.

Download our Public PGP Key