Multi-source threat actor intelligence for everyone. Generate analyst-grade dossiers from MITRE ATT&CK, Malpedia, OTX, SigmaHQ, ThreatFox, CISA, and vendor research blogs.
Every dossier opens with an LLM-synthesized executive overview. Export to whatever your workflow needs.
Each source feeds into a common schema. The deduplicator merges everything and assigns confidence scores. Nothing downstream knows which source the data came from.
| Source | Key | Auth | Cache |
|---|---|---|---|
| MITRE ATT&CK | mitre | none | 7 days |
| CISA Advisories + KEV | cisa | none | per request |
| Malpedia | malpedia | none | per request |
| AlienVault OTX | otx | OTX_API_KEY | per request |
| SigmaHQ detection rules | sigma | none | 7 days |
| ThreatFox IOCs | threatfox | none | 24 hours |
| Vendor intel synthesis | vendor | LLM API key | 7 days |
Python 3.11+, a virtual environment, and one free API key. That's it.