Initializing portfolio

000

Aravind.
All projects

Case study 04 / 16

Private LLM for Threat Intelligence Automation

Deployed a private LLM that ingests threat feeds, CVE databases, and dark web chatter to automatically triage and summarize emerging threats for the SOC team, reducing analyst investigation time significantly.

Case study
04 / 16
Sector
Cybersecurity Firm
Stack
4 technologies
Published
2026
Private LLM for Threat Intelligence Automation

The problem

A SOC drowns in threat intelligence. Feeds, CVE disclosures and chatter arrive faster than analysts can read them, and the triage question — does this affect us, and how urgently — is judgement work that does not scale by hiring.

How it works

A privately hosted Llama model reads incoming intelligence and produces analyst-facing summaries: what the threat is, what it affects, and why it might matter here. Elasticsearch indexes the corpus so the model answers against what the organisation has actually collected rather than from parametric memory, which is what keeps summaries current with feeds that change hourly.

MISP integration means findings land in the platform analysts already use for sharing and correlation, rather than in a separate tool competing for their attention.

What shaped it

Running the model privately was a requirement, not a preference. Threat intelligence reveals what an organisation is worried about and what it has already been hit by — sending that to a third-party endpoint leaks exactly the information the SOC exists to protect.

Triage output also has to be auditable. An analyst needs to see the source behind a summary to trust it, so retrieval was designed to cite what it drew on rather than assert conclusions.

Outcome

Analyst investigation time per item dropped significantly, with the team's attention going to threats that warranted it rather than to reading everything.

Let's keep in touch

Get in touch