Home › Blog

Article

Ninja Signal — AI-Augmented Threat Intelligence Graph

What it is: A production cybersecurity platform that combines a Neo4j knowledge graph (~162K nodes, 200K+ edges) with 17 purpose-built ML models to deliver actionable threat intelligence. Live at ninjasignal.ninja.

The graph: Ingests from 8 threat feeds (NVD, MITRE ATT&CK, CISA KEV, AlienVault OTX, OpenCTI) into a unified knowledge graph connecting threat actors, techniques, vulnerabilities, software, campaigns, indicators, infrastructure, and mitigations.

What the ML does:

┌──────────────────────────────────────┬────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐

│ Model │ Business Value │

├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤

│ Risk Propagation │ Ranks every entity by proximity to active exploits — tells you what to worry about first │

├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤

│ Community Detection │ Reveals coordinated threat ecosystems — actors, tools, and infrastructure operating as a unit │

├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤

│ Link Prediction (Adamic-Adar + Katz) │ Predicts undocumented relationships before feeds confirm them — verified prediction tracking proves accuracy │

├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤

│ KEV Exploitation Predictor │ GradientBoosting classifier trained on 10 graph-derived features predicts which CVEs will be exploited in the wild │

├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤

│ CVE Priority Queue │ 6-signal composite scoring replaces CVSS-only triage — patch by real-world threat context, not severity alone │

├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤

│ Attack Path Analysis │ Risk-weighted shortest paths map kill chains and identify shared chokepoints for defensive prioritisation │

├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤

│ "What If" Simulator │ Remove a technique or deploy a mitigation and see exactly how much risk drops across the graph │

├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤

│ Actor Attribution Clustering │ Weighted Jaccard + DBSCAN groups actors by behavioural DNA — finds shared operators and supply chains │

├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤

│ Graph Neural Network │ 2-layer GCN for semi-supervised node classification reveals risk patterns rule-based scoring misses │

├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤

│ Activity Forecast │ Hawkes process temporal model predicts when each actor is likely to strike next │

├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤

│ Changepoint Detection │ Z-score analysis against rolling baselines flags statistical surges and unexpected quiet periods │

├──────────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤

│ MetaPath Embeddings │ Typed random walks + SVD capture relation-aware similarity that standard methods miss │

└──────────────────────────────────────┴────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘

Where Claude fits: The platform already generates AI reports for community drill-downs and has a conversational threat analyst. Claude API integration would enable:

1. Natural language threat briefings — "What's changed in the Russia-nexus cluster this week?" answered from live graph context

2. Automated incident narratives — Claude correlates SIEM alerts with graph topology to write analyst-ready incident reports

3. Conversational graph exploration — analysts query the threat graph in plain English instead of Cypher

4. Cross-model synthesis — Claude reads outputs from all 17 models and produces a unified daily intelligence summary

5. Detection rule generation — Claude writes KQL/Sigma rules from graph-derived attack paths

Scale: 245 threat actors, 1,200 techniques, 1,900 vulnerabilities, 89K indicators, 48K software entries. All ML models run in under 3 seconds with 15-minute caching. Production server on Hetzner, Cloudflare CDN, Docker Compose stack.

Sister platform: ANTOS (antos.ninja.ing) — an AI-orchestrated DevSecOps pipeline where Claude coordinates 16 security tools across 8 pipeline stages, from threat modelling at design time through to runtime monitoring.

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

Originally published on LinkedIn ↗

← All writing