Skip to content
 
 

Repository files navigation

🛡️ Cyber Threat Intelligence (CTI) Sharing Platform

A lightweight, real-time Cyber Threat Intelligence Platform designed to monitor live network traffic, detect malicious behavior, enrich data using threat intelligence feeds, and classify risks to support faster SOC decision-making.


📌 Project Information

  • Project Track: Cyber Security
  • Problem Statement: Cyber Threat Intelligence (CTI) Sharing Platform
  • Team Name: CYBERTRONS

👨‍💻 Team Members

  • Team Leader: Asuri Karthik

  • Team Mates:

    • Konda Sridhar
    • Pavan Sai SK
    • Malla Gangadhar
  • Institute: Parul Institute of Engineering & Technology


🚨 Problem Overview

Modern SOC operations face several challenges:

  • Threat intelligence is fragmented across multiple tools and feeds
  • Lack of correlation prevents early detection of coordinated attacks
  • Manual analysis increases response time and risk
  • Actionable intelligence is hard to extract from raw data like:
    • Indicators of Compromise (IOCs)
    • Tactics, Techniques & Procedures (TTPs)
    • Network logs

⚙️ Dependencies & Challenges

  • Real-time ingestion of high-volume network traffic
  • Accurate correlation with low false positives
  • Maintaining data accuracy and performance

💡 Our Solution

🔍 Cyber Threat Intelligence Platform

Our platform continuously monitors live network traffic and provides actionable intelligence through the following modules:

📡 Traffic Capture

  • Collects live network traffic from endpoints, servers, and network interfaces in real time.

📊 Packet Analysis

  • Inspects packets to detect:
    • Suspicious behavior
    • Network anomalies
    • Malicious patterns

🌍 Threat Intelligence & GeoIP Detection

  • Enriches traffic data using:
    • GeoIP intelligence
    • Threat intelligence feeds
  • Identifies malicious IP sources and geographic threats.

⚠️ Risk Classification

  • Classifies network activity into:
    • LOW
    • MEDIUM
    • HIGH
  • Uses predefined rules and behavior analysis.

📈 Dashboard & Reporting

  • Interactive real-time web dashboard with visualisation
  • Downloadable security reports
  • Improved visibility for SOC teams

🧠 Key Features

  • ⚡ Lightweight & Fast
  • 🔎 Real-time Threat Intelligence
  • 🧩 Customizable threat detection logic
  • 🚀 Easy to deploy and beginner-friendly
  • 🔄 Modular & extensible architecture

🛠️ Technology Stack

Frontend

  • React
  • CSS
  • javascript

Backend

  • Python (Flask)
  • Scapy
  • GeoIP2

Tools

  • Kali Linux
  • Wireshark
  • VS Code

🌐 Real-World Applications

  • Monitoring & Alerting with visualisation
  • Network security analysis
  • Educational & research use
  • Lightweight alternative to enterprise SIEM solutions

🚀 Innovation & Future Scope

  • Cost-effective compared to expensive SIEM platforms
  • Real-time network visibility using live traffic analysis
  • Flexible architecture for:
    • Future integrations
    • Performance scaling
    • Advanced threat intelligence feeds

PRE-REQUIREMENTS

-install npm modules

-Flask

-flask-cors

-scapy

-geoip2

-shodan

-feedparser

-requests

📢 Conclusion

This Cyber Threat Intelligence Platform enhances security visibility by combining live traffic monitoring, threat intelligence enrichment, and risk-based classification — enabling faster incident response and smarter security decisions.


Built with security, scalability, and simplicity in mind.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages