Just shipped 6 ML features for threat intelligence — no GPU, no cloud ML, just graph math.
Just shipped 6 ML features for threat intelligence — no GPU, no cloud ML, just graph math.
I've been building Ninja Signal, a threat intel platform and data science platform that turns CVEs, MITRE ATT&CK techniques, threat actors, and indicators into a live knowledge graph (160K+ nodes in Neo4j).
The latest release adds 6 graph ML capabilities, all running pure Python on CPU:
Phase 1 — Quick wins:
- Community Mitigation Prioritization — "deploy these 3 controls to cover 87% of this threat cluster's attack surface"
- Multi-hop Katz Link Prediction — traces 3-hop paths with temporal decay to predict connections before they're observed
- Temporal Changepoint Detection — z-score anomaly detection on weekly activity buckets to flag technique surges and actor emergence
Phase 2 — Deeper analysis:
- Threat Actor Attribution Clustering — weighted Jaccard + DBSCAN to surface actor aliases and rebrands by TTP overlap
- MetaPath2Vec Embeddings — relation-aware random walks across TTP/exploit/infrastructure meta-paths, SVD to 64 dimensions
- Hierarchical Community Detection — multi-resolution Louvain to reveal nested threat ecosystems
The whole ML layer runs on NetworkX + scipy with a 15-minute cache. No PyTorch. No SageMaker. Just adjacency matrices and smart sampling.
tack: FastAPI + Neo4j 5 + Next.js 16 + Caddy
If you work in threat intel, detection engineering, or security operations — I'd love your feedback.
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·