Home › Blog

Just shipped 6 ML features for threat intelligence — no GPU, no cloud ML, just graph math.

Just shipped 6 ML features for threat intelligence — no GPU, no cloud ML, just graph math.

I've been building Ninja Signal, a threat intel platform and data science platform that turns CVEs, MITRE ATT&CK techniques, threat actors, and indicators into a live knowledge graph (160K+ nodes in Neo4j).

The latest release adds 6 graph ML capabilities, all running pure Python on CPU:

Phase 1 — Quick wins:
 - Community Mitigation Prioritization — "deploy these 3 controls to cover 87% of this threat cluster's attack surface"
 - Multi-hop Katz Link Prediction — traces 3-hop paths with temporal decay to predict connections before they're observed
 - Temporal Changepoint Detection — z-score anomaly detection on weekly activity buckets to flag technique surges and actor emergence

Phase 2 — Deeper analysis:
 - Threat Actor Attribution Clustering — weighted Jaccard + DBSCAN to surface actor aliases and rebrands by TTP overlap
 - MetaPath2Vec Embeddings — relation-aware random walks across TTP/exploit/infrastructure meta-paths, SVD to 64 dimensions
 - Hierarchical Community Detection — multi-resolution Louvain to reveal nested threat ecosystems

The whole ML layer runs on NetworkX + scipy with a 15-minute cache. No PyTorch. No SageMaker. Just adjacency matrices and smart sampling.

tack: FastAPI + Neo4j 5 + Next.js 16 + Caddy

If you work in threat intel, detection engineering, or security operations — I'd love your feedback.

https://ninjasignal.ninja

#cybersecurity#threatintelligence#machinelearning#graphml#python#opensource
The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

View the original on LinkedIn ↗

← All writing