A lightweight, real-time Cyber Threat Intelligence Platform designed to monitor live network traffic, detect malicious behavior, enrich data using threat intelligence feeds, and classify risks to support faster SOC decision-making.
- Project Track: Cyber Security
- Problem Statement: Cyber Threat Intelligence (CTI) Sharing Platform
- Team Name: CYBERTRONS
-
Team Leader: Asuri Karthik
-
Team Mates:
- Konda Sridhar
- Pavan Sai SK
- Malla Gangadhar
-
Institute: Parul Institute of Engineering & Technology
Modern SOC operations face several challenges:
- Threat intelligence is fragmented across multiple tools and feeds
- Lack of correlation prevents early detection of coordinated attacks
- Manual analysis increases response time and risk
- Actionable intelligence is hard to extract from raw data like:
- Indicators of Compromise (IOCs)
- Tactics, Techniques & Procedures (TTPs)
- Network logs
- Real-time ingestion of high-volume network traffic
- Accurate correlation with low false positives
- Maintaining data accuracy and performance
Our platform continuously monitors live network traffic and provides actionable intelligence through the following modules:
- Collects live network traffic from endpoints, servers, and network interfaces in real time.
- Inspects packets to detect:
- Suspicious behavior
- Network anomalies
- Malicious patterns
- Enriches traffic data using:
- GeoIP intelligence
- Threat intelligence feeds
- Identifies malicious IP sources and geographic threats.
- Classifies network activity into:
- LOW
- MEDIUM
- HIGH
- Uses predefined rules and behavior analysis.
- Interactive real-time web dashboard with visualisation
- Downloadable security reports
- Improved visibility for SOC teams
- ⚡ Lightweight & Fast
- 🔎 Real-time Threat Intelligence
- 🧩 Customizable threat detection logic
- 🚀 Easy to deploy and beginner-friendly
- 🔄 Modular & extensible architecture
- React
- CSS
- javascript
- Python (Flask)
- Scapy
- GeoIP2
- Kali Linux
- Wireshark
- VS Code
- Monitoring & Alerting with visualisation
- Network security analysis
- Educational & research use
- Lightweight alternative to enterprise SIEM solutions
- Cost-effective compared to expensive SIEM platforms
- Real-time network visibility using live traffic analysis
- Flexible architecture for:
- Future integrations
- Performance scaling
- Advanced threat intelligence feeds
-install npm modules
-Flask
-flask-cors
-scapy
-geoip2
-shodan
-feedparser
-requests
This Cyber Threat Intelligence Platform enhances security visibility by combining live traffic monitoring, threat intelligence enrichment, and risk-based classification — enabling faster incident response and smarter security decisions.
⭐ Built with security, scalability, and simplicity in mind.