ProjectCTI turns live attack traffic into actionable threat intelligence for critical-infrastructure operators. A distributed sensor network captures attempts against SSH, web, RDP, VoIP, SMB and industrial control protocols; each event is classified, enriched and mapped to MITRE ATT&CK within seconds.
The console shows a live global attack map with per-country drill-down, campaign clustering across related sources, CVE exploitation tracking, credential and payload analysis, OT/ICS protocol activity across twelve industrial device profiles, and SIP/VoIP toll-fraud intelligence. Indicators export as STIX 2.1 for ingestion into a SIEM or TIP.
The dashboard needs JavaScript. The underlying data does not — the read API is public, unauthenticated and returns JSON: /api/v1/stats and /api/v1/attacks/recent.
More about the platform