{"repo":"THREATRADAR-Pipeline/ThreatRadar","free":true,"listed":false,"github":"https://github.com/THREATRADAR-Pipeline/ThreatRadar","clone":"git clone https://github.com/THREATRADAR-Pipeline/ThreatRadar.git","description":"ThreatRadar is an open-source Threat Intelligence pipeline for SOC and threat intelligence teams that ingests, enriches, scores, and validates IOCs from multiple feeds using AI-driven anomaly detection to identify potential feed poisoning before pushing trusted intelligence to MISP.","language":"Python","stars":20,"topics":["cortex","elasticsearch","misp","scoring","soc","ai","cybersecurity","llm","machine-learning","osint"],"license":"MIT","category":"security-tools","readme_excerpt":"An end-to-end Threat Intelligence pipeline with AI-powered feed poisoning detection, Cortex-driven IOC scoring, and MISP integration. --- Table of Contents - Overview - Pipeline Architecture - Features - Technology Stack - Prerequisites - Full Installation Guide - Configuration - Environment Variables - Cortex Analyzer - Threat Intelligence Feeds - ML Poisoning Detection - MISP Integration - Running ThreatRadar - Docker Deployment - Kibana Dashboards - Troubleshooting - Contributing - License and Credits --- Overview ThreatRadar is an open-source Threat Intelligence pipeline designed for Security Operations Centers and threat intelligence teams. It aggregates IOCs from multiple sources, enriches and scores them through Cortex analyzers, and detects statistical anomalies and semantic contradictions in feed data using an LLM and IsolationForest model before results reach analyst queues. A core design goal is addressing feed poisoning : the injection of false or misleading IOCs into threat intelligence feeds to manipulate defender decisions. ThreatRadar handles this at the pipeline level through AI detection and closed-loop feedback from analyst sightings in MISP. What ThreatRadar does: - Ingests IOCs from multiple open and commercial feeds - Normalizes and classifies IOCs into seven typed Elasticsearch indices - Enriches each IOC with MITRE ATT&CK mappings, CVSS scores, and actor attribution - Scores IOCs via Cortex analyzers (VirusTotal, AbuseIPDB, Maltiverse, IPinfo, Urlscan,","default_branch":null,"files":null,"tree":[],"storefront":"/r/THREATRADAR-Pipeline","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/THREATRADAR-Pipeline/ThreatRadar/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}