Article
Ninja Signal — AI-Augmented Threat Intelligence Graph
What it is: A production cybersecurity platform that combines a Neo4j knowledge graph (~162K nodes, 200K+ edges) with 17 purpose-built ML models to deliver actionable threat intelligence. Live at ninjasignal.ninja.
The graph: Ingests from 8 threat feeds (NVD, MITRE ATT&CK, CISA KEV, AlienVault OTX, OpenCTI) into a unified knowledge graph connecting threat actors, techniques, vulnerabilities, software, campaigns, indicators, infrastructure, and mitigations.
What the ML does:
┌──────────────────────────────────────┬────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐
│ Model │ Business Value │
├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Risk Propagation │ Ranks every entity by proximity to active exploits — tells you what to worry about first │
├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Community Detection │ Reveals coordinated threat ecosystems — actors, tools, and infrastructure operating as a unit │
├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Link Prediction (Adamic-Adar + Katz) │ Predicts undocumented relationships before feeds confirm them — verified prediction tracking proves accuracy │
├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ KEV Exploitation Predictor │ GradientBoosting classifier trained on 10 graph-derived features predicts which CVEs will be exploited in the wild │
├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ CVE Priority Queue │ 6-signal composite scoring replaces CVSS-only triage — patch by real-world threat context, not severity alone │
├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Attack Path Analysis │ Risk-weighted shortest paths map kill chains and identify shared chokepoints for defensive prioritisation │
├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ "What If" Simulator │ Remove a technique or deploy a mitigation and see exactly how much risk drops across the graph │
├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Actor Attribution Clustering │ Weighted Jaccard + DBSCAN groups actors by behavioural DNA — finds shared operators and supply chains │
├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Graph Neural Network │ 2-layer GCN for semi-supervised node classification reveals risk patterns rule-based scoring misses │
├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Activity Forecast │ Hawkes process temporal model predicts when each actor is likely to strike next │
├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Changepoint Detection │ Z-score analysis against rolling baselines flags statistical surges and unexpected quiet periods │
├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ MetaPath Embeddings │ Typed random walks + SVD capture relation-aware similarity that standard methods miss │
└──────────────────────────────────────┴────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘
Where Claude fits: The platform already generates AI reports for community drill-downs and has a conversational threat analyst. Claude API integration would enable:
1. Natural language threat briefings — "What's changed in the Russia-nexus cluster this week?" answered from live graph context
2. Automated incident narratives — Claude correlates SIEM alerts with graph topology to write analyst-ready incident reports
3. Conversational graph exploration — analysts query the threat graph in plain English instead of Cypher
4. Cross-model synthesis — Claude reads outputs from all 17 models and produces a unified daily intelligence summary
5. Detection rule generation — Claude writes KQL/Sigma rules from graph-derived attack paths
Scale: 245 threat actors, 1,200 techniques, 1,900 vulnerabilities, 89K indicators, 48K software entries. All ML models run in under 3 seconds with 15-minute caching. Production server on Hetzner, Cloudflare CDN, Docker Compose stack.
Sister platform: ANTOS (antos.ninja.ing) — an AI-orchestrated DevSecOps pipeline where Claude coordinates 16 security tools across 8 pipeline stages, from threat modelling at design time through to runtime monitoring.
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·