A non-profit project dedicated to enhancing digital resilience through OSINT aggregation and promoting open access to threat intelligence.
CSIRT-CA is an independent, non-profit initiative established to identify, aggregate, and disclose vulnerabilities, data leaks, and malicious C&C servers across Central Asia. By promoting openness in Threat Intelligence, we aim to assist organizations and National CERTs in proactively defending their infrastructure.
The project does not conduct active scanning of networks, ports, or systems. All information is gathered passively from open sources (OSINT) in strict compliance with the cybersecurity legislation and criminal codes of the region.
While our social media channels serve as a tool to notify stakeholders about threats, we reserve the right and prioritize contacting organizations privately and directly whenever possible, provided the threat information has not been previously disclosed to the public.
We strictly prohibit the publication of citizens' personally identifiable information (PII) from data leaks. However, we may indicate the source or origin of a leak if the disclosing party has explicitly made this information publicly available.
When threats remain unpatched or unaddressed, information is published on our public channels completely anonymized, detailing only the ASN or general nature of the vulnerability to raise regional situational awareness.
As part of our commitment to transparency and community defense, CSIRT-CA will regularly publish depersonalized analytics and Indicators of Compromise (IoC) to our public repository.
View Repository on GitHubIf you wish to report a security incident, request an embargo extension, or share sensitive intelligence (logs, memory dumps), please use our secure channels.
Email Address
info@csirt-ca.orgWe strictly require the use of PGP encryption when transmitting sensitive data to ensure confidentiality.
Download our Public PGP Key