Swarup Saha

Defensive Security

Threat Intelligence Integrations

Integrations for threat intelligence APIs — indicators of compromise, reputation checking, and SIEM enrichment.


Project metadata
CategoryDefensive Security
TechnologiesPython, MISP, IBM QRadar, REST APIs
Linkssource

Overview

Integration work that connects threat intelligence sources to the places analysts actually look: pulling indicators of compromise, checking reputations, and enriching SIEM events so triage starts with context instead of raw addresses.

Problem

Threat intelligence is only useful at the moment of triage. When reputation data lives in separate portals, analysts either waste time pivoting between tabs or skip the check entirely.

Solution

Glue integrations that bring IOC feeds and reputation lookups into the SIEM pipeline, so events arrive pre-enriched with the context needed to make a fast, correct call.

Key features

  • IOC ingestion from threat intelligence platforms
  • Automated reputation checking for IPs, domains, and hashes
  • SIEM event enrichment
  • De-duplication and ageing of stale indicators

Lessons learned

Enrichment is a latency problem: intelligence that arrives after the analyst has moved on might as well not exist.


Related projects

SOC RegisterDefensive Security

A security operations management application for tracking SOC activities, incidents, users, roles, and operational records.

Built with TypeScript, Next.js, PostgreSQL, RBAC

case studysource

Security Automation ScriptsAutomation

Python and Bash scripts for vulnerability scanning, threat intelligence, security monitoring, and repetitive security workflows.

Built with Python, Bash, REST APIs

case studysource

PassGuardJSOpen Source

An open-source JavaScript and TypeScript password strength and password policy validation library.

Built with TypeScript, JavaScript, npm

case studysource

← All projects