Skip to content
BOLTERTechnologies · Islamabad
Menu
All work

Threat intelligence and adversary tracking platform

An automated threat intelligence platform that ingests 80+ global feeds, scores and correlates tens of thousands of indicators daily, and maps live campaigns onto MITRE ATT&CK.

Data analytics2025Delivered
SectorCybersecurity and defence(name withheld)
Duration8 months
Year2025
StatusDelivered
Stack
Python 3.12FastAPIPostgreSQLSQLAlchemyReact 19ViteTailwind CSSThree.jsWebGLSTIX/TAXIIDocker
[ Placeholder · Cover image ]1600x900 screenshot or architecture diagram. Drop the file into public/work/<slug>/ and set `cover:` in the frontmatter.

Outcome

80+OSINT, STIX/TAXII and commercial feeds ingested automatically
50,000+indicators of compromise normalised and scored every day
3Dgeospatial command centre for real-time adversary tracking
Outcome chart[ Placeholder ]

The problem

Enterprise security operations centres and threat hunting teams are inundated with disconnected feeds of IP addresses, domain names, file hashes and malware signatures. Manually pulling from dozens of open-source and proprietary threat lists leaves analysts drowning in false positives and stale data, with no automated way to connect an isolated malicious IP to an active threat actor campaign, a known malware family, or the MITRE ATT&CK techniques being leveraged. Correlating indicators across disjointed spreadsheets and threat portals wastes critical response time while high-risk threats slip through undetected.

Approach

We built a unified cyber threat intelligence platform with an automated ingestion and normalisation pipeline capable of processing over 80 global OSINT, STIX/TAXII and commercial intelligence feeds. The backend uses FastAPI and PostgreSQL with JSONB schema flexibility to continuously deduplicate, cross-reference and calculate composite risk scores across indicators based on feed reliability, threat recency and historical attribution.

The system automatically tags indicators with threat actor profiles — APT groups, malware strains — and maps observed behaviours directly onto the MITRE ATT&CK matrix. On the frontend, a React application drives an interactive 3D WebGL geospatial threat globe, real-time indicator filtering, and deep-dive entity correlation views that let an analyst pivot from a single IP to an entire adversary infrastructure in seconds.

Outcome

Raw, noisy threat feeds became an organised, actionable intelligence hub. Analysts replaced hours of manual indicator cross-referencing with automated risk scoring and instant campaign context, cutting triage time sharply. Security teams gain immediate visibility into global adversary activity, high-risk emerging indicators and relevant countermeasures from a single high-density command centre rather than a dozen browser tabs.

What the client said

[ Placeholder · Client testimonial ]
A real client quote goes here, kept short. Two sentences beats a paragraph, and a specific complaint that you fixed beats generic praise. This block is not rendered at all once placeholders are switched off and no testimonial has been added.
Client nameTheir role