Real-time threat intelligence from a live sensor network
ProjectCTI turns attacker traffic into actionable CTI for critical-infrastructure operators — attack telemetry, OT/ICS deception and MITRE ATT&CK-mapped intelligence, streamed as it happens.
From first packet to finished intelligence
Every connection to the sensor fleet is captured, classified and enriched in seconds — then rendered on a live console built for analysts.
LIVE ATTACK MAP
Global attack sources on a real-time map with per-country drill-down, arc replay of live sessions and severity filtering.
OT/ICS DECEPTION
Purpose-built decoys emulating 12 industrial device profiles — Modbus, S7, IEC-104, BACnet — surface attackers probing operational networks.
ATTACK ANALYTICS
Campaign clustering, CVE exploitation tracking, credential-capture analysis and SIP toll-fraud intelligence — mapped to MITRE ATT&CK.
PAYLOAD CAPTURE
Dropped binaries and scripts are captured, classified by file type and risk, and linked back to the campaigns that delivered them.
SESSION REPLAY
Full command-by-command replay of attacker SSH sessions — watch tooling, tactics and objectives unfold as they were typed.
STIX EXPORT
Indicators, sightings and attack patterns exported as STIX 2.1 bundles for direct ingestion into your SIEM or TIP.
Broad protocol coverage, professionally operated
A hardened, containerized fleet across SSH, web, RDP, VoIP, ICS and network layers.
See what is probing your sector
ProjectCTI is available to critical-infrastructure operators and security teams. Request access and we will follow up directly.
REQUEST ACCESS