AI-powered threat intel feed — CVEs, cyberattacks, TTPs, exploits, malware. Hosted at security.damianvillarreal.com.
Private repository — UTRGV Cybersecurity Club members only.
- Frontend: Next.js 14 + TypeScript + Tailwind CSS
- Database: PostgreSQL via Neon + Drizzle ORM
- AI: OpenAI GPT-4o-mini (or AWS Bedrock Claude Haiku)
- Auth: Clerk
- Payments: Stripe ($5/mo)
- Hosting: Cloudflare Pages (frontend) + cron triggers (agents)
# 1. Clone
git clone https://github.com/YOUR_ORG/threat-intel-platform
cd threat-intel-platform
# 2. Install (requires pnpm)
npm i -g pnpm
pnpm install
# 3. Environment
cp .env.example .env.local
# Fill in DATABASE_URL, OPENAI_API_KEY, NVD_API_KEY, CLERK_*, STRIPE_*
# 4. Create DB tables
pnpm db:migrate
# 5. Run locally
pnpm dev
# 6. Seed minimum actor data (recommended)
pnpm run:ttp # MITRE ATT&CK STIX (no AI)
pnpm run:attack # RSS ingestion + AI extraction (backfills ~30 days)
# 7. Test VulnAgent
pnpm run:vulnIf you see intermittent Next.js dev errors like missing files under apps/web/.next/** (e.g. _buildManifest.js.tmp.* or app-build-manifest.json), it’s almost always one of:
- Two
next devprocesses running at the same time (both writing to the same.nextdirectory) - Something deleting/locking
.nextwhile dev is running (manual deletes, antivirus/EDR, OneDrive/Dropbox sync)
Fix:
- Stop all dev servers.
- Run
pnpm dev:clean(orpnpm --filter web dev:clean). - If it keeps happening, exclude
apps/web/.nextfrom Defender/EDR and ensure the repo isn’t in a synced folder.
threat-intel-platform/
├── apps/
│ ├── web/ # Next.js app (UI + API routes)
│ ├── agents/ # Agent scripts (run on cron)
│ └── mcp/ # MCP server (FastMCP) for external clients
├── packages/
│ ├── db/ # Drizzle schema + client
│ └── ai/ # Shared AI helpers
├── .env.example
└── turbo.json
The repo includes an MCP server at apps/mcp that connects to the platform via API-key authenticated /api/v1/* endpoints.
- Local install/run details:
apps/mcp/README.md - Required API key scopes include:
findings:read,actors:read,cves:read,query:run,navigator:read,playbooks:write,detections:generate
| Agent | Schedule | Sources |
|---|---|---|
| VulnAgent | Every 6h | NVD, CISA KEV |
| AttackAgent | Every 4h | Threat blogs, CISA Alerts |
| TTPAgent | Weekly Sun 06:00 UTC | MITRE ATT&CK STIX |
| ExploitAgent | Every 2h | GitHub, ExploitDB |
| MalwareAgent | Every 12h | MalwareBazaar, Any.run |
- Connect repo to Cloudflare Pages
- Set build command:
pnpm build - Set output directory:
apps/web/.next - Add all env vars in Pages dashboard
- Add Cron Triggers in
wrangler.tomlto call/api/cron/vulnetc.
See research/TRACKS.md for research track instructions.
Pick a track, create a branch research/your-name/topic, submit a PR.