PROJECT

CTI-AI

CTI Workbench

LIVE OPERATIONS

Phase 1: Planning & Direction

Priority Intelligence Requirements (PIRs) driving the collection lifecycle.

Select Threat Report

Current Intelligence Priorities

PIR-01

Detect GitHub credential leaks & code scans

Monitor for intelligence indicating adversary intent to exploit leaked personal access tokens (PATs), scan private repositories, or target developer workspaces.

CRITICAL ACTIVE
PIR-02

Track AI Platform API key exposure

Identify behavioral anomalies indicative of exposed OpenAI/Anthropic/AWS model keys, dynamic proxy tunneling, and unauthorized high-cost GPU cluster usage.

HIGH ACTIVE
PIR-03

Track LOTL activity on edge infrastructure

Identify Living-Off-The-Land techniques and valid account abuse originating from anonymizing proxies targeting cloud perimeter gates.

HIGH ACTIVE
PIR-04

Monitor SaaS Access Broker chatter

Track dark web forums and Telegram channels for Initial Access Brokers (IABs) auctioning access to enterprise Salesforce portals, CRM databases, or OAuth configurations.

MEDIUM MONITORING

Strategic Direction

The intelligence lifecycle begins here. Without formally defined PIRs, collection efforts become aimless ("hunting in the dark").

These PIRs dictate the parameters for our automated Collection engines (Phase 2) and the semantic weighting utilized by the AI Normalization layer (Phase 3).

Cloud & AI Security Warning

PIR-02 remains escalated due to automated scraping of public Git repositories and OpenAI platform key abuse. All behavioral telemetry is currently weighted to surface token leakage and unauthorized GPU resource hijacking.

LIVE OSINT FEED
[--:--:--]RansomHub infrastructure detected actively scanning public repositories for secrets.[--:--:--]New leak: 14k internal developer credentials tied to corporate git repos posted on BreachForums.[--:--:--]OSINT Warning: Known ShinyHunters OAuth app redirect domains resurfacing via dynamic DNS.[--:--:--]Active exploit attempting to abuse Salesforce Experience Cloud Aura endpoints detected on multiple enterprise portals.[--:--:--]AI Security Alert: Abnormal volume of OpenAI API token requests from hijacked cloud GPU instances.[--:--:--]Threat group UNC6780 (Team PCP) observed pushing poisoned NPM package updates.[--:--:--]GitHub Breach Alert: Actor selling access to compromised corporate developer repositories.[--:--:--]RansomHub infrastructure detected actively scanning public repositories for secrets.[--:--:--]New leak: 14k internal developer credentials tied to corporate git repos posted on BreachForums.[--:--:--]OSINT Warning: Known ShinyHunters OAuth app redirect domains resurfacing via dynamic DNS.[--:--:--]Active exploit attempting to abuse Salesforce Experience Cloud Aura endpoints detected on multiple enterprise portals.[--:--:--]AI Security Alert: Abnormal volume of OpenAI API token requests from hijacked cloud GPU instances.[--:--:--]Threat group UNC6780 (Team PCP) observed pushing poisoned NPM package updates.[--:--:--]GitHub Breach Alert: Actor selling access to compromised corporate developer repositories.[--:--:--]RansomHub infrastructure detected actively scanning public repositories for secrets.[--:--:--]New leak: 14k internal developer credentials tied to corporate git repos posted on BreachForums.[--:--:--]OSINT Warning: Known ShinyHunters OAuth app redirect domains resurfacing via dynamic DNS.[--:--:--]Active exploit attempting to abuse Salesforce Experience Cloud Aura endpoints detected on multiple enterprise portals.[--:--:--]AI Security Alert: Abnormal volume of OpenAI API token requests from hijacked cloud GPU instances.[--:--:--]Threat group UNC6780 (Team PCP) observed pushing poisoned NPM package updates.[--:--:--]GitHub Breach Alert: Actor selling access to compromised corporate developer repositories.