IntelGraph correlates threat indicators from 5 intelligence sources, eliminates false positives, and generates a step-by-step evidence chain for every alert — so analysts know exactly why something triggered.
Five-stage pipeline from raw feed data to actionable, explainable intelligence.
Pull IOCs automatically from URLhaus, OTX, CISA KEV, Shodan, and VirusTotal.
Parse IPs, domains, URLs, hashes, and CVEs from raw feed data.
Build a knowledge graph — deduplicate entities and map relationships across sources.
Score threats, detect anomalies, and fire alerts with full evidence chains.
Share findings as STIX 2.1 bundles or trigger playbooks via webhook.
Each source contributes a different signal — IntelGraph resolves conflicts between them automatically.
Open source, extensible, and designed around the questions analysts actually ask.
Every alert comes with a step-by-step explanation of why it fired — not just a score.
D3.js force-directed graph visualizes relationships between IPs, domains, CVEs, and hashes.
Automatically flags when two sources disagree on the same indicator.
Standards-compliant export for Splunk, Microsoft Sentinel, MISP, and OpenCTI.
Rule-based automation: C2 IP detection, ransomware CVE response, malware domain workflows.
Webhook, email, and Slack notifications as threats are detected.
Role-based access control, 2FA, OAuth2, and API key rotation built in.
Scheduled threat reports in PDF-ready format via Jinja2 templates.
Request a live demo, open an issue, or just browse the code.
berkayaltintas@intelgraph.io · contact@intelgraph.io