Skip to content
Modat Try Magnify
Modat Magnify

The Internet Intelligence Platform

Continuously scan and enrich internet infrastructure to uncover relationships and intent that would otherwise remain hidden. The goal is not to collect the most data, but to create the most useful intelligence for analysts and the agents they rely on.

Scanners stop at what exists. Magnify explains what is behind it.

Threat intelligence feeds stop at indicators. Scanners only inventory what exists. Magnify surfaces what is being prepared, before it is used.

Modat Magnify Datasheet

Get the global visibility you need

Modat Magnify is built for cybersecurity analysts, researchers, product managers and threat hunters inside security teams, governments and enterprises, alongside a growing community of thousands of security professionals. One intelligence workspace to search, pivot and model infrastructure behaviour across IP and Passive DNS, in place of spend spread across several separate tools.

How an investigation works

Start with context, not raw data

A single weak signal expands into a full infrastructure map. Related assets are already clustered, history is already preserved, and behaviour is already scored. What took hours of manual pivoting now takes minutes.

Search, pivot across relationships, and watch a campaign take shape before it goes operational.

Screen recording of Modat Magnify: an IP query, the single result with its ports and CVEs, then the host profile with its ASN, subnet, domain, banner hashes and TLS certificate history. The host's identifying fields are partly blurred.
magnify.modat.io

Inside the platform

Capabilities others cannot match

Device profiling

Identity, not just existence

Know what a device is, who operates it and how it changes over time, backed by AI-driven profiling.

Historical memory

Replay how it evolved

Continuous history reconstructs past environments and reveals the intent behind every change.

Graph pivoting

One signal to a full map

Expand a single indicator into a complete infrastructure map, with related assets already connected.

Behavioural clustering

Catch it before it launches

AI clustering surfaces infrastructure that belongs together before a campaign becomes operational.

IP and DNS integration

Hosts and names, one picture

IP and Passive DNS in the same investigation: what a name resolved to and when, alongside the host it points at, so a pivot crosses from one to the other without leaving the platform.

Agentic capabilities

Built for agents, not bolted on

Standards-based MCP access, so an agent reasons over the same structured context your analysts work from. Clean, current and machine-readable by design rather than scraped out of a UI.

Why security teams choose Modat Magnify

Find more, stay sovereign, move faster

Superior intelligence

Find more

  • A bespoke AI clustering model identifies and fingerprints known and unknown internet-connected devices, learns the infrastructure signatures of threat actors, and predicts maliciousness.
  • Device profiling against our own profile database identifies the world's most used products and groups them into categories such as OT, malicious and healthcare.
  • Passive DNS connects each IP address to the domain names it currently answers for.
Data sovereignty

Fully operated and hosted from the EU

  • European infrastructure, European jurisdiction, and no dependency on non-European providers for the data you investigate with.
  • Carrying the ECSO "Cybersecurity Made in Europe" label.
What the label means
Actionable insights

Move faster

  • A workspace built around the way investigations actually run: AI-assisted querying, grouping and tagging, pivoting, tracking, and complex queries you can store and rerun.
  • Historical context, with more than a year of service history to compare against.
  • A Threat Investigation Manager that keeps investigations, automatic pivoting and case management in one place.

Human + Agent

People decide, agents deliver

Teams and agents work together, on one context rather than two copies of it. Agents talk to Modat continuously, analysing, clustering and expanding infrastructure relationships across the internet, then hand a structured picture to the analyst.

Analysts stay responsible for judgement: is this malicious, is this a campaign, what action to take. Technology amplifies the decision, it never replaces it.

Access it your way

Built into the workflows you already run

Modat enriches the tools and agents you already use, rather than asking you to replace either.

Platform

Search, pivot and monitor in the Magnify web app, with guided investigation for every analyst.

API

Expose Internet Intelligence through APIs that fit naturally into your SIEM, SOAR and investigation tooling.

MCP for agents

Through standards-based MCP access, agents reason over the same trusted context your analysts work from.

Integrations

Enrichment inside the threat intelligence platform your team already runs, through integrations such as EclecticIQ and OpenCTI.

Ask us anything

Not sure it can see what you need?

Tell us what you are trying to find and we will tell you straight whether Magnify can find it.

Prefer to look first? Open Magnify and run a query, no conversation required.

Intent leaves a trace.

Start seeing what is being prepared