Cytectra

A CTI platform that collects, correlates, and visualises threat data from many sources in one workspace. Intelligence is exchanged over STIX 2.1 and TAXII 2.1, so findings go straight to work in the SIEM, SOAR, EDR, and network gear you already own.

  • STIX 2.1 and TAXII 2.1
  • MITRE ATT&CK mapping
  • AI assisted analysis
  • Self-hosted, your data
cytectra.local / dashboard
Cytectra threat intelligence dashboard
12

Intelligence modules

20+

Stealer malware families

75+

App platforms watched

14

Lookalike domain techniques

Why Cytectra

Built to connect, not to stand alone

One CTI workspace

Indicators, advisories, campaigns, and attack surface findings live in one place instead of scattered across many tools.

Standards based exchange

Built-in STIX 2.1 and TAXII 2.1 support lets intelligence flow both ways with partners and other security platforms.

AI assisted investigation

The AI assistant summarises reports, pulls out entities and IOCs, then maps them to MITRE ATT&CK techniques.

External risk visibility

Exposed assets, lookalike domains, and leaked credentials are found before anyone uses them against you.

Straight into your defences

Indicators are exported to IDS, SIEM, and firewalls through feeds that stay in sync on their own.

Full control over the data

Self-hosted deployment with Docker Compose. Data and infrastructure stay inside your own environment.

Core modules

Four modules SOC teams reach for most

Every module stands on the same data, so a finding in one place immediately enriches the context everywhere else.

MODULE 01

Dashboard

The command centre for every threat intelligence activity.

Threat score, indicator counts, critical and high priority findings, intrusion sets, malware, and campaigns all sit on one screen. Visual summaries and ranked lists help the team see what needs handling first.

  • Threat score
  • Ingestion trend
  • Severity spread
  • Top CVE
  • MITRE ATT&CK
dashboard / overview
Cytectra dashboard
MODULE 02

AI Threat Intelligence Assistant

Investigation and correlation that move faster.

The AI assistant brings CTI data, MITRE ATT&CK knowledge, IOC analysis, and threat context together in one interactive workspace. It supports several AI providers and models, so the rollout can follow your internal policy.

  • Multi model AI
  • IOC extraction
  • Automatic summaries
  • Contextual memory
ai assistant / analysis
AI Threat Intelligence Assistant
MODULE 03

Attack Surface Management

Continuous visibility over internet facing assets.

A layered scanning engine finds new assets, tests for vulnerabilities, validates exposure, then tracks remediation status over time. Smart validation keeps false positives down so the team does not burn hours chasing empty findings.

  • Subdomain enumeration
  • SSL/TLS and headers
  • REST, GraphQL, SOAP
  • Scan profiles
  • Remediation tracking
asm / external exposure
Attack Surface Management
MODULE 04

Dark Web Monitoring

Early signals from where stolen data is traded.

Underground forums, marketplaces, leak sites, and Telegram channels are watched through one central search. AI assisted classification and false positive filtering keep the alerts relevant to your team.

  • Clearnet and Tor
  • Keyword watchlist
  • Risk scoring
  • Real time alerts
dark web / monitoring
Dark Web Monitoring
Other modules

Eight more intelligence sources

STIX/TAXII 2.1

STIX/TAXII 2.1

An interactive relationship graph between malware, indicators, campaigns, threat actors, and ATT&CK techniques.

Exploit and Vulnerability Intelligence

Exploit and Vulnerability Intelligence

CVEs, the CISA KEV list, PoC availability, Metasploit modules, and EPSS scores for risk based prioritisation.

Malicious Package Monitoring

Malicious Package Monitoring

Malicious packages across npm, PyPI, RubyGems, Go, Maven, NuGet, and crates.io, sourced from the OSV database.

Stealer Intelligence

Stealer Intelligence

Compromised credentials, devices, and subdomains from info-stealer logs across 20 malware families.

Security Advisory CSAF 2.0

Security Advisory CSAF 2.0

Advisory authoring, validation, publishing, and synchronisation, complete with affected asset correlation.

Typosquatting

Typosquatting

Domain variant generation with 14 techniques, DNS analysis, and similarity scoring to hunt lookalike domains.

Domain Monitoring

Domain Monitoring

Certificate Transparency logs and newly registered domain feeds with fuzzy matching on brand keywords.

Rogue Mobile App

Rogue Mobile App

Fake and malware laden apps across more than 75 official and third party stores, each with a risk score.

Export to defences

Indicators that stop at the dashboard hold nobody back

The IDS and Firewall Export modules turn indicators into the detection and blocking formats your devices already speak. Feeds are generated automatically behind stable polling URLs, so the rules stay current without manual work.

  • Type and severity filters
  • Custom SID
  • Automatic blocklist
  • Stable feed URL
export / ids and firewall
Exporting indicators to IDS and firewalls
  • Snort
  • Suricata
  • Zeek
  • Palo Alto
  • FortiGate
  • Check Point
  • Cisco
  • Juniper
  • MikroTik
  • F5
  • pfSense
  • OPNsense
  • CSV
  • Plain text
System requirements

One Docker stack, no extra dependencies

Node.js, PostgreSQL, and Nginx already sit inside the official image. The host only needs Docker Engine and Compose.

MINIMUM

Lab and evaluation

Enough for one team with a few thousand indicators.

  • Operating systemLinux: Ubuntu 20.04+, Debian 11+, CentOS 8+, or any OS that runs Docker
  • CPU4 cores
  • RAM8 GB
  • Storage120 GB
  • DockerEngine 20.10+ with Compose v2
  • NetworkInternet access for feed synchronisation
RECOMMENDED

SOC operations, 100 thousand indicators and up

For several active connectors, dark web ingestion, weekly reports, and the AI assistant.

  • CPU16 cores or more
  • RAM36 GB or more
  • Storage1 TB and up, SSD recommended
  • PostgreSQL14+, already part of the deployment
  • RuntimeNode.js 20.x and Nginx Alpine inside the image
  • NoteAdd RAM and storage as the indicator corpus grows
SCHEDULE A DEMO

See Cytectra work against your own threat context

We walk you through the flow from ingestion and correlation to exporting indicators into your devices. The session runs about 45 minutes with our technical team.

  • Answer within one working day
  • NDA available
  • Self-hosted deployment
WHATSAPP