Threat intelligence · AI agent

AI OSINT Security Analyzer

An AI agent that investigates IP addresses, domains, CVEs and software versions across several threat-intelligence sources, then writes an evidence-based security assessment. By default, Cohere's Command A+ model decides which tools to run (Command A and Command A Reasoning can also be chosen), and every finding in the report is tied back to the source that produced it.

Screenshots

Screenshots from a local run against scanme.nmap.org, a server the Nmap project provides for testing security tools, and against CVE-2021-44228 (Log4Shell). Click a screenshot to open it full size. Use the arrows, or select the gallery and press ← →.

How it works

  1. Classify the input as an IP, domain, CVE or software version, rejecting anything invalid or non-public.
  2. Baseline lookups in code: for IPs and domains, DNS, Shodan, VirusTotal and AbuseIPDB always run before the AI starts, so core coverage never depends on the model. Shodan results are checked against CISA KEV automatically.
  3. Investigate: the agent chooses further tools (NVD version check, NVD lookup, CISA KEV, keyword search) within a per-run budget. Duplicate calls are served from cache.
  4. Verify versions: CVEs come from NVD's CPE match API and are re-checked locally against each affected range, so nginx 1.20.1 isn't reported as vulnerable to a bug fixed in 1.20.1. The minimum safe version is computed from the range ends.
  5. Report: code builds the Key facts, and the model writes the summary, findings, details, recommendations and limitations, citing a source for every claim.

Security decisions