# THREATMARKET — Threat Intel Data Marketplace Public catalog + paid archive of REAL threat intelligence harvested by the fleet. Customers browse sample data, pay sats/BTC via BTCPay, download auto-zipped intel packs. ## Business model - Fleet tools (OSINT Terminal 454 tools, Lynx, Argus, research engine, market-intel crawls) continuously enumerate REAL data: subdomains, exposed services, cert transparency, breach indicators, newly-registered domains, market/lead datasets. - Auto-pipeline (2x daily) packages a fresh intel pack from a RANDOM website/company and archives it as a zip: /opt/threatmarket/archive/-.zip - Each pack = structured JSON/CSV (not made-up data — only real findings from real scans) - Site lists archive metadata (domain, date, finding counts, categories) WITHOUT the payload. Buyer pays BTCPay -> webhook -> zip unlocked for browser download (one-time link). ## Stack - CT TBD "threatmarket" (Debian 12), Flask + nginx :80->app - BTCPay store + webhook (payment confirmed -> unlock zip) - Gitea repo, Umami beacon, BMAC footer, agent SEO (llms.txt) - Cron: 2x daily random-target intel pack generation ## Rules - ZERO fabricated data. Every finding must come from a real scan run by real fleet tools. - If a scan produces nothing, the pack says so. No filler, no example rows. - Public pages show counts/metadata only; payloads only after payment.