Reading burden
Analysts spend hours scanning PDFs, blogs, news feeds, and OSINT sources to pull out entities that should already be machine-readable.
AI threat intelligence platform
Turn unstructured threat reports into SOC-ready intelligence.
ThreatIQ ingests reports, OSINT, feeds, STIX, and MISP content, extracts entities and relationships, builds a verified knowledge graph, and delivers analyst-ready answers with source evidence.
PDF, RSS, GDELT, web, MISP, STIX, XML, and JSON.
Actors, malware, CVEs, TTPs, indicators, and campaigns.
Relationships, confidence, provenance, and evidence.
Natural-language query, analyst workflow, and MISP export.
Problem
Feeds provide indicators. Search finds documents. CTI platforms add depth or scale. SOC analysts still need a connected, explainable operating layer that answers what the threat means and what to do now.
Analysts spend hours scanning PDFs, blogs, news feeds, and OSINT sources to pull out entities that should already be machine-readable.
Actor-to-malware-to-CVE relationships are buried in prose, scattered across sources, and lost when teams search by keyword only.
Turning a report into MISP events, tickets, enrichment data, or hunt hypotheses still requires custom scripts and manual review.
Evaluation
The evaluation compared ThreatIQ against LLM-only responses and measured entity accuracy, faithfulness, routing quality, and latency.
Versus a 54% LLM-only baseline.
Cosine similarity against ground truth.
Correct RAG, graph, or combined path.
Query to answer with gpt-4o-mini.
Platform
LangGraph routes questions to RAG, graph queries, or both. ChromaDB preserves document context, while the knowledge graph stores relationships, confidence, and source provenance.
Document loaders, web scraping, RSS/GDELT collection, MISP connector, STIX parser, and OCR.
Staged LLM extraction, NER, relation models, confidence scoring, and ontology mapping.
React dashboard, FastAPI endpoints, WebSocket jobs, MISP export, and approval workflows.
Capabilities
MISP, RSS, GDELT, Common Crawl, PDF/TXT, web scraping, STIX 2.x, JSON, and XML in one pipeline.
Evidence-bearing entities, directional relationships, confidence scores, and Neo4j fallback.
Analysts ask direct questions and receive grounded answers with citations per response.
Approval-based draft queue for scoring, approving, and pushing structured events.
Run chunk size, RAG, and temperature experiments from the browser with live results.
Extract entities, query graph relationships, and search reports through desktop AI tools.
Graph-derived digest for CVEs, actor links, malware, IoCs, sectors, and MISP-ready items.
Golden queries, entity accuracy, faithfulness metrics, routing checks, and experiment polling.
Security and integrations
ThreatIQ is designed for private SOC workflows, safe ingestion, authenticated APIs, and controlled export into existing CTI operations.
Pricing
Pricing scales from lightweight evaluation to team workspaces and dedicated enterprise infrastructure.
Per analyst seat
Up to 10 seats
Private on-prem or cloud
Private pilot
Deploy ThreatIQ as a static landing page today, then connect the product demo, API, and MISP workflow behind it when ready.