AI threat intelligence platform

ThreatIQ

Turn unstructured threat reports into SOC-ready intelligence.

ThreatIQ ingests reports, OSINT, feeds, STIX, and MISP content, extracts entities and relationships, builds a verified knowledge graph, and delivers analyst-ready answers with source evidence.

01 Ingest

PDF, RSS, GDELT, web, MISP, STIX, XML, and JSON.

02 Extract

Actors, malware, CVEs, TTPs, indicators, and campaigns.

03 Graph

Relationships, confidence, provenance, and evidence.

04 Operate

Natural-language query, analyst workflow, and MISP export.

Problem

Threat intelligence is still too manual and too fragmented.

Feeds provide indicators. Search finds documents. CTI platforms add depth or scale. SOC analysts still need a connected, explainable operating layer that answers what the threat means and what to do now.

01

Reading burden

Analysts spend hours scanning PDFs, blogs, news feeds, and OSINT sources to pull out entities that should already be machine-readable.

02

Hidden context

Actor-to-malware-to-CVE relationships are buried in prose, scattered across sources, and lost when teams search by keyword only.

03

Export friction

Turning a report into MISP events, tickets, enrichment data, or hunt hypotheses still requires custom scripts and manual review.

Evaluation

Validated across 30 golden queries in 9 CTI task categories.

The evaluation compared ThreatIQ against LLM-only responses and measured entity accuracy, faithfulness, routing quality, and latency.

81% Entity accuracy

Versus a 54% LLM-only baseline.

0.74 Faithfulness

Cosine similarity against ground truth.

87% Routing accuracy

Correct RAG, graph, or combined path.

3.2s Mean latency

Query to answer with gpt-4o-mini.

Platform

Evidence-preserving architecture for operational CTI.

LangGraph routes questions to RAG, graph queries, or both. ChromaDB preserves document context, while the knowledge graph stores relationships, confidence, and source provenance.

LangGraph RAG Knowledge Graph MISP Export FastAPI ChromaDB
1

Data collection

Document loaders, web scraping, RSS/GDELT collection, MISP connector, STIX parser, and OCR.

2

AI extraction

Staged LLM extraction, NER, relation models, confidence scoring, and ontology mapping.

3

Analyst output

React dashboard, FastAPI endpoints, WebSocket jobs, MISP export, and approval workflows.

ThreatIQ dashboard showing knowledge graph totals, entity distribution, and high-confidence threats
ThreatIQ dashboard Graph nodes, relationships, CVEs, campaigns, and reports

Capabilities

Every layer of the CTI workflow, covered.

IN

Multi-source ingestion

MISP, RSS, GDELT, Common Crawl, PDF/TXT, web scraping, STIX 2.x, JSON, and XML in one pipeline.

KG

Knowledge graph

Evidence-bearing entities, directional relationships, confidence scores, and Neo4j fallback.

NL

Natural-language query

Analysts ask direct questions and receive grounded answers with citations per response.

ME

MISP export workflow

Approval-based draft queue for scoring, approving, and pushing structured events.

AB

A/B experiments

Run chunk size, RAG, and temperature experiments from the browser with live results.

MC

MCP server

Extract entities, query graph relationships, and search reports through desktop AI tools.

AF

Analyst feed

Graph-derived digest for CVEs, actor links, malware, IoCs, sectors, and MISP-ready items.

EV

Evaluation framework

Golden queries, entity accuracy, faithfulness metrics, routing checks, and experiment polling.

Security and integrations

Enterprise guardrails with a first-class integration surface.

ThreatIQ is designed for private SOC workflows, safe ingestion, authenticated APIs, and controlled export into existing CTI operations.

Security guardrails

  • API key authentication on REST endpoints and WebSocket jobs.
  • SSRF prevention blocks private ranges, loopback, metadata IPs, and unsafe URL schemes.
  • Upload safety restricts file types and stores files in server-controlled paths.
  • Prompt injection scans and unsafe output checks protect analyst workflows.

Integration surface

  • REST APIs for ingest, query, graph, MISP, and evaluations.
  • MCP tools for entity extraction, graph lookup, and report search.
  • LangSmith tracing with per-query cost tracking.
  • Configurable model, chunk size, auth, CORS, MISP, and Neo4j settings.

Pricing

From analyst trial to private on-prem deployment.

Pricing scales from lightweight evaluation to team workspaces and dedicated enterprise infrastructure.

Pilot

$0Free
  • 5 AI queries per day
  • 3 ingestion sources
  • Basic NER extraction
  • Read-only graph view
  • MISP preview export
Start free

SOC Team

$149/month

Up to 10 seats

  • Everything in Pro
  • Team workspace and RBAC
  • Shared knowledge graph
  • Analyst approval flows
  • Audit log and provenance
Contact sales

Enterprise

Custom

Private on-prem or cloud

  • Air-gap and on-prem deploy
  • Custom fine-tuning
  • SLA and expert support
  • Dedicated infrastructure
  • Custom integrations
Plan deployment

Private pilot

Move from threat reports to SOC action.

Deploy ThreatIQ as a static landing page today, then connect the product demo, API, and MISP workflow behind it when ready.