
Plataforma de threat intelligence em PT-BR - CVEs, briefings, IOCs e noticias de segurança
Threat intelligence platform in Portuguese built from scratch as a personal Blue Team project. It aggregates data from global open sources and transforms it into technical briefings, classified news, enriched CVEs, and structured IOCs — all in PT-BR, continuously updated.
Site: statecraftcyber.vercel.app
NewsCache to serve subsequent reads without a new LLM call/api/health for monitoring availability and database integrity| Layer | Technology |
|---|---|
| Frontend / Backend | Next.js 16.2.6 (App Router), TypeScript, Tailwind CSS v4 |
| Database | PostgreSQL (Neon) + Prisma 6 |
| AI | Groq API (LLaMA 3.3 70B) |
| Sanitization | isomorphic-dompurify + marked |
| Threat sources | NVD API, CISA KEV, OTX AlienVault, EPSS (FIRST.org) |
| News feeds | 19 global RSS sources |
| Deploy | Vercel (app) + cron-job.org (external hourly scheduler, Hobby plan) |
External sources (NVD, CISA KEV, OTX, RSS)
│
▼
cron-job.org → Vercel — runs every hour (Hobby plan)
vercel.json defines the schedule for future migration to Pro plan
│
├── Collects news (RSS feeds) → NewsCache (PostgreSQL)
│
└── Collects threats (NVD, CISA, OTX)
│
▼
Groq LLaMA 3.3 70B
Generates structured briefing (title, summary,
severity, IOCs, CVEs, MITRE ATT&CK)
│
▼
Briefing → PostgreSQL (status: published)
│
├── Structured IOCs → Ioc table
└── Exposed via REST API → Frontend (Next.js)
| Model | Description |
|---|---|
Briefing | Complete briefing generated by AI with threat metadata |
Ioc | Normalized indicators of compromise with indices |
NewsCache | Enriched news from RSS feeds |
CronLog | Execution log of cron jobs |
git clone https://github.com/ptkthg/statecraftcyber
cd statecraftcyber
npm install
Copy the example file and fill in the variables:
cp .env.example .env
| Variable | Description |
|---|---|
DATABASE_URL | PostgreSQL connection URL with ?sslmode=require |
GROQ_API_KEY | Groq API Key (groq.com) |
NVD_API_KEY | NVD API Key — optional, without key the rate limit is lower |
OTX_API_KEY | AlienVault OTX Key — optional |
CRON_SECRET | Secret token to authenticate cron calls (header Authorization: Bearer) |
ADMIN_SECRET | Password to access the /admin/status panel |
AUTO_PUBLISH | true to automatically publish briefings |
MAX_HOURLY_BRIEFINGS | Limit of briefings per hour (default: 3) |
# Create tables and apply migrations
npx prisma migrate dev
# View data in browser
npx prisma studio
npm run dev
Access http://localhost:3000.
npm run build
npm start
# Apply migrations in production (without generating migration files)
npx prisma migrate deploy
# Regenerate Prisma Client after schema changes
npx prisma generate
# Reset database (CAUTION: deletes all data)
npx prisma migrate reset
| Source | Type | Endpoint |
|---|---|---|
| NVD (NIST) | CVEs | services.nvd.nist.gov/rest/json/cves/2.0 |
| CISA KEV | Exploited vulnerabilities | www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json |
| EPSS (FIRST.org) | Exploitation score | api.first.org/data/v1/epss |
| AlienVault OTX | IOCs and pulses | otx.alienvault.com/api/v1 |
| 19x RSS feeds | News | CISA, Krebs on Security, The Hacker News, CERT.br, SANS ISC, Bleeping Computer and others |
Threat Intelligence data must be validated against primary sources before any critical action in production.
Developed by Patrick Santos — Security Analyst, Blue Team.