LIVE PLATFORM — ALL DATA IS REAL-TIME

From Raw Honeypot Data to
Published Intelligence Dossiers

A fully autonomous threat intelligence platform that collects SSH attack data, enriches it through 14+ OSINT sources, links it via graph analysis into 288,000+ intelligence edges, detects campaigns, clusters actors, and produces publishable dossiers that have predicted real-world attacks before they happened.

Loading live intelligence…
⚡ AUTONOMOUS PIPELINE

Six-Stage Intelligence Pipeline

Every 15 minutes, raw honeypot events become actionable intelligence. No human intervention required — the system collects, enriches, links, attributes, and publishes continuously.

🍯
Collection
Cowrie SSH honeypot captures every login, credential, command, and malware download
Real-time streaming
🔬
Enrichment
14+ OSINT sources: Shodan, AbuseIPDB, RDAP, GreyNoise, DShield, Cymru, Spamhaus, Tor, Censys, VirusTotal, OTX, IPInfo, URLhaus, Pulsedive
Hourly passive + 6×/day active recon
🎯
Active Recon
Nmap port scans, service fingerprinting, HTTP probing, and Nuclei vulnerability checks via Tor
6×/day · 15 targets/run
🧠
Intel Linking
20 graph strategies: HASSH, credentials, commands, SSH keys, malware, BGP, RDAP, OTX, DNS, temporal
Every 2h · 288K+ edges
🎭
Attribution
Campaign detection, actor clustering, behavioral classification, infrastructure correlation
Continuous analysis
📡
Sharing
Machine-readable feeds, API endpoints, publishable dossiers, STIX/TAXII-ready export
Every 15 min
💎 DIFFERENTIATORS

What Makes This Platform Unique

Not another SIEM dashboard. This is a complete intelligence production facility — from sensor to published report.

🔄

Fully Autonomous Pipeline

Zero human intervention from data collection to intelligence output. The system enriches, links, detects campaigns, and publishes dossiers on its own schedule. Analysts review — not operate.

🕸️

Graph-Based Intel Linking

288,000+ entity edges connecting IPs through shared HASSH fingerprints, credentials, commands, network prefixes, and ASN relationships. Not flat IOC lists — a living intelligence graph.

🎯

Predictive Campaign Detection

Published dossiers have correlated with real attacks that were later confirmed. The latest campaign (TI-2026-013) was documented before the infrastructure was publicly attributed.

🤖

80%+ Offline Dossier Generation

AI agents with 299 MCP tools (54 honeypot-specific) query the intelligence graph, correlate enrichment data, and produce publication-quality dossiers — entirely offline using self-hosted LLMs. No cloud AI dependency.

📈

Constantly Improving Data Quality

Every pipeline run improves coverage. Bad data is automatically re-enriched. New OSINT sources plug in without architecture changes. Intelligence quality compounds over time.

🏗️

Self-Hosted Data Sovereignty

Entire platform runs on-premise on a single server. No cloud dependencies, no vendor lock-in, no data leaves the perimeter until intentionally shared. Full GDPR/sovereignty compliance.

📦

Portable & Replicable

Kubernetes-native architecture (K3S). Every component is containerized with versioned manifests. Deploy a full instance on any hardware — from a single workstation to a multi-node cluster.

Horizontal Scalability

Add honeypot sensors, enrichment workers, or compute nodes without redesign. The pipeline scales per-stage independently. Built to handle 10× current volume without architecture changes.

📊

Full Pipeline Observability

Every step logged to PostgreSQL: source-level success rates, timing, error classification, coverage gaps. Structured telemetry enables data quality auditing and automated remediation.

🔴 REAL-WORLD IMPACT

Intelligence That Predicted Real Attacks

This isn't theoretical. Published dossiers from this platform have correlated with confirmed attack campaigns.

🔴 ACTIVE CAMPAIGN — CONFIRMED

TI-2026-013: The Krane Botnet — Bulletproof Infrastructure Ecosystem

32
Confirmed IPs
16
Countries
20
Autonomous Systems
8,854
Login Attempts
303
Successful Auths
55+
Days Active

A coordinated multi-actor campaign combining a Mirai-family Go SSH scanner (Krane), the mdrfckr persistent backdoor, and a Scaleway-hosted libssh scanner fleet — operating through a bulletproof hosting ecosystem anchored on WHITELABEL-MNT. Our intelligence graph identified 3 distinct actor clusters, traced infrastructure to newly registered ASNs, and documented the C2 staging across FranTech and xTom Germany — before public attribution existed.

The latest attack against our infrastructure was directly correlated with two existing dossiers (TI-2026-012 and TI-2026-013), validating the predictive capability of the platform.

Read the full dossier →

🤖 AI-NATIVE INTELLIGENCE

Autonomous Dossier Generation — 80%+ Offline

Self-hosted AI agents consume the intelligence graph through 299 MCP tools (54 honeypot-specific) and produce publication-quality threat reports without any cloud dependency.

🧠 How It Works

An AI agent receives a target (IP, ASN, campaign, or pattern) and autonomously:

  • Queries the honeypot API for sessions, credentials, commands
  • Pulls enrichment data from all 14+ OSINT sources via structured endpoints
  • Traverses the intelligence graph (288K+ edges) to find related actors
  • Correlates HASSH fingerprints, credential patterns, and C2 infrastructure
  • Cross-references campaigns, IOC databases, and known threat groups
  • Generates a complete dossier with executive summary, IOCs, TTPs, and attribution

Result: Publication-quality intelligence reports generated in minutes, not days — with full source attribution and confidence scoring.

⚡ The MCP Advantage

299
Total MCP Tools
54
Honeypot Intel Tools
47
Local LLMs
0
Cloud Dependencies

The entire AI stack runs on local hardware via Ollama (~435 GB model storage). Models range from fast 7B for classification to 70B+ for complex reasoning and dossier writing.

54 honeypot-specific tools cover: IP dossiers, session analysis, credential intelligence, command parsing, campaign detection, actor clustering, entity graph traversal, ASN/network analysis, STIX/MISP export, IOC feeds, blocklists, deep enrichment status, and timeline visualization.

Additional 245 infrastructure tools: Kubernetes, Docker, Mikrotik routing, CrowdSec, monitoring, Ollama model management, database, filesystem, network diagnostics, and more — enabling full-stack autonomous operation.

📈 Continuous improvement: Data quality improves with every pipeline run — new enrichment sources, better linking algorithms, and re-enrichment of stale data happen automatically. Each dossier generated today is better than one generated last week, because the underlying intelligence graph is richer. There is still significant room to grow: more honeypot sensor types (HTTP, SMB, RDP), additional premium OSINT integrations, predictive ML models for attack forecasting, and automated STIX bundle generation are all architecture-ready.

📦 OUTPUTS

Intelligence Products

The platform produces multiple intelligence formats for different consumers — from machine-readable feeds to human-readable dossiers.

📋

Published Dossiers

Complete threat intelligence reports with executive summaries, IOCs, TTPs, infrastructure analysis, and actor attribution. Shareable, citable, actionable.

HTML · PDF · SHAREABLE
🔌

REST API

Full programmatic access: IP lookup, enrichment data, campaign queries, graph traversal, bulk export. 40+ endpoints with structured JSON responses.

JSON · AUTHENTICATED · RATE-LIMITED
📡

Threat Intel Feed

Machine-readable export: actor clusters, IOCs, campaigns, hostile networks, attack tools. CC BY-SA 4.0 licensed. Updated every 15 minutes.

JSON · CC BY-SA 4.0 · AUTO-UPDATED
🖥️

Web Intelligence UI

Full-featured analyst interface: IP dossiers, network visualization, campaign timelines, enrichment status, inter-linked intelligence views.

REACT-LIKE SPA · REAL-TIME
🤖

MCP Agent Tools (299)

AI agents autonomously query IPs, traverse the intelligence graph, pull enrichment data, detect patterns, and generate publication-quality dossiers — 80%+ of analyst quality, completely offline.

MCP · 299 TOOLS · 54 HONEYPOT · OFFLINE LLMs · AUTONOMOUS
📊

Pipeline Telemetry

Complete observability: per-source success rates, enrichment coverage, timing metrics, error classification. Queryable via API for operational dashboards.

POSTGRES · STRUCTURED LOGS
LIVE DATA

Real-Time Intelligence — Right Now

Everything below is live production data, auto-refreshed every 15 minutes. This is not a demo.

Loading live intelligence panels…
🏗️ ARCHITECTURE

Technical Foundation

Enterprise-grade infrastructure running on bare metal. No cloud dependencies. Complete data sovereignty.

Compute
Dell Precision 7910
Xeon E5-2699 v4
88 threads · 503 GiB RAM
NVIDIA RTX 4060 Ti
Orchestration
K3S Kubernetes
51 namespaces · 115+ pods
Helm + custom manifests
Rolling deployments
Data Layer
PostgreSQL
Threat Intel DB
Structured enrichment logs
Graph entity storage
AI / ML
Ollama (47 models)
~435 GB model storage
MCP Protocol (299 tools)
Autonomous dossier gen
Collection
Cowrie SSH Honeypot
Real-time event stream
Malware capture
Session replay
OSINT Sources
14+ integrations
Shodan · AbuseIPDB · VT
Censys · GreyNoise · OTX
Pulsedive · IPInfo · RDAP
🚀 SCALABILITY

Built to Scale, Ready to Deploy

From a single workstation to a distributed sensor network. The architecture is designed for growth without redesign.

📦

Container-Native Portability

Every component is a versioned container image with declarative Kubernetes manifests. Clone the repo, run kubectl apply, and the entire platform deploys — anywhere K3S or K8S runs. From a laptop lab to a NATO-grade datacenter.

🌐

Multi-Sensor Federation

Add SSH, HTTP, SMB, or RDP honeypot sensors anywhere on any network. Each sensor streams events to the central intelligence pipeline. Geographic distribution improves coverage and enables regional threat landscape analysis.

Per-Stage Horizontal Scaling

Enrichment workers, deep OSINT workers, and linker jobs scale independently. Rate limits are per-worker. Add 10× enrichment capacity by simply scaling the worker pool — the architecture handles it natively.

🔌

Plugin-Ready OSINT Architecture

New intelligence sources plug in as Python modules with a standard interface. No core changes needed. The platform currently integrates 14+ sources — adding more is a configuration change, not a development project.

🗺️ Growth Roadmap — Architecture-Ready

Sensor Expansion
HTTP/HTTPS honeypot · SMB/RDP traps · DNS sinkholes · Cloud decoys (AWS/Azure/GCP canaries)
ML & Prediction
Attack forecasting · Behavioral fingerprinting · Anomaly detection · Automated IOC scoring
Integration & Export
STIX/TAXII bundles · MISP feed · Splunk/QRadar connectors · Automated CERT notifications
Multi-Tenant
Isolated instances per organization · Federated intelligence sharing · Role-based access control

Access the Intelligence

Download the threat intelligence feed, explore the published dossiers, or discuss enterprise deployment and collaboration opportunities.

📋 Read Latest Dossier 🍯 Honeypot Report

Interested in deployment, replication, or partnership? lisneanucristian@gmail.com · LinkedIn