A fully autonomous threat intelligence platform that collects SSH attack data, enriches it through 14+ OSINT sources, links it via graph analysis into 288,000+ intelligence edges, detects campaigns, clusters actors, and produces publishable dossiers that have predicted real-world attacks before they happened.
Every 15 minutes, raw honeypot events become actionable intelligence. No human intervention required — the system collects, enriches, links, attributes, and publishes continuously.
Not another SIEM dashboard. This is a complete intelligence production facility — from sensor to published report.
Zero human intervention from data collection to intelligence output. The system enriches, links, detects campaigns, and publishes dossiers on its own schedule. Analysts review — not operate.
288,000+ entity edges connecting IPs through shared HASSH fingerprints, credentials, commands, network prefixes, and ASN relationships. Not flat IOC lists — a living intelligence graph.
Published dossiers have correlated with real attacks that were later confirmed. The latest campaign (TI-2026-013) was documented before the infrastructure was publicly attributed.
AI agents with 299 MCP tools (54 honeypot-specific) query the intelligence graph, correlate enrichment data, and produce publication-quality dossiers — entirely offline using self-hosted LLMs. No cloud AI dependency.
Every pipeline run improves coverage. Bad data is automatically re-enriched. New OSINT sources plug in without architecture changes. Intelligence quality compounds over time.
Entire platform runs on-premise on a single server. No cloud dependencies, no vendor lock-in, no data leaves the perimeter until intentionally shared. Full GDPR/sovereignty compliance.
Kubernetes-native architecture (K3S). Every component is containerized with versioned manifests. Deploy a full instance on any hardware — from a single workstation to a multi-node cluster.
Add honeypot sensors, enrichment workers, or compute nodes without redesign. The pipeline scales per-stage independently. Built to handle 10× current volume without architecture changes.
Every step logged to PostgreSQL: source-level success rates, timing, error classification, coverage gaps. Structured telemetry enables data quality auditing and automated remediation.
This isn't theoretical. Published dossiers from this platform have correlated with confirmed attack campaigns.
A coordinated multi-actor campaign combining a Mirai-family Go SSH scanner (Krane), the mdrfckr persistent backdoor, and a Scaleway-hosted libssh scanner fleet — operating through a bulletproof hosting ecosystem anchored on WHITELABEL-MNT. Our intelligence graph identified 3 distinct actor clusters, traced infrastructure to newly registered ASNs, and documented the C2 staging across FranTech and xTom Germany — before public attribution existed.
The latest attack against our infrastructure was directly correlated with two existing dossiers (TI-2026-012 and TI-2026-013), validating the predictive capability of the platform.
Self-hosted AI agents consume the intelligence graph through 299 MCP tools (54 honeypot-specific) and produce publication-quality threat reports without any cloud dependency.
An AI agent receives a target (IP, ASN, campaign, or pattern) and autonomously:
Result: Publication-quality intelligence reports generated in minutes, not days — with full source attribution and confidence scoring.
The entire AI stack runs on local hardware via Ollama (~435 GB model storage). Models range from fast 7B for classification to 70B+ for complex reasoning and dossier writing.
54 honeypot-specific tools cover: IP dossiers, session analysis, credential intelligence, command parsing, campaign detection, actor clustering, entity graph traversal, ASN/network analysis, STIX/MISP export, IOC feeds, blocklists, deep enrichment status, and timeline visualization.
Additional 245 infrastructure tools: Kubernetes, Docker, Mikrotik routing, CrowdSec, monitoring, Ollama model management, database, filesystem, network diagnostics, and more — enabling full-stack autonomous operation.
📈 Continuous improvement: Data quality improves with every pipeline run — new enrichment sources, better linking algorithms, and re-enrichment of stale data happen automatically. Each dossier generated today is better than one generated last week, because the underlying intelligence graph is richer. There is still significant room to grow: more honeypot sensor types (HTTP, SMB, RDP), additional premium OSINT integrations, predictive ML models for attack forecasting, and automated STIX bundle generation are all architecture-ready.
The platform produces multiple intelligence formats for different consumers — from machine-readable feeds to human-readable dossiers.
Complete threat intelligence reports with executive summaries, IOCs, TTPs, infrastructure analysis, and actor attribution. Shareable, citable, actionable.
Full programmatic access: IP lookup, enrichment data, campaign queries, graph traversal, bulk export. 40+ endpoints with structured JSON responses.
Machine-readable export: actor clusters, IOCs, campaigns, hostile networks, attack tools. CC BY-SA 4.0 licensed. Updated every 15 minutes.
Full-featured analyst interface: IP dossiers, network visualization, campaign timelines, enrichment status, inter-linked intelligence views.
AI agents autonomously query IPs, traverse the intelligence graph, pull enrichment data, detect patterns, and generate publication-quality dossiers — 80%+ of analyst quality, completely offline.
Complete observability: per-source success rates, enrichment coverage, timing metrics, error classification. Queryable via API for operational dashboards.
Everything below is live production data, auto-refreshed every 15 minutes. This is not a demo.
Enterprise-grade infrastructure running on bare metal. No cloud dependencies. Complete data sovereignty.
From a single workstation to a distributed sensor network. The architecture is designed for growth without redesign.
Every component is a versioned container image with declarative Kubernetes manifests. Clone the repo, run kubectl apply, and the entire platform deploys — anywhere K3S or K8S runs. From a laptop lab to a NATO-grade datacenter.
Add SSH, HTTP, SMB, or RDP honeypot sensors anywhere on any network. Each sensor streams events to the central intelligence pipeline. Geographic distribution improves coverage and enables regional threat landscape analysis.
Enrichment workers, deep OSINT workers, and linker jobs scale independently. Rate limits are per-worker. Add 10× enrichment capacity by simply scaling the worker pool — the architecture handles it natively.
New intelligence sources plug in as Python modules with a standard interface. No core changes needed. The platform currently integrates 14+ sources — adding more is a configuration change, not a development project.
Download the threat intelligence feed, explore the published dossiers, or discuss enterprise deployment and collaboration opportunities.
Interested in deployment, replication, or partnership? lisneanucristian@gmail.com · LinkedIn