CTIForge
Cyber threat intelligence triage for small security teams. Early stage.
What it does
Security analysts spend hours reading threat reports and sorting indicators of compromise. CTIForge is a tool in development that helps with that first pass.
- Reads threat reports and writes a short summary: actors, techniques (mapped to MITRE ATT&CK), and affected sectors.
- Pulls out indicators (IPs, domains, hashes, CVEs) and groups them for triage, so analysts can see what needs attention first.
- Drafts a daily digest for the team, which an analyst reviews before it goes anywhere.
How Claude is used
CTIForge uses the Claude API to read report text, extract and classify indicators, and write the summaries and digests. A person reviews the output. Detection and matching logic stays deterministic, outside the model.
Who it is for
Small SOC and threat intelligence teams that run OpenCTI or similar platforms and do not have time to read every report in full.
Status
CTIForge is a young project, built in 2026 and being tested with a small number of early users. There is no public sign-up yet.