Intel Sonar · in development · private beta

Threat intelligence, in your pocket.

Intel Sonar is a native iOS app that puts real cyber threat intelligence in a practitioner's hands — daily AI-generated briefings, a live IOC feed, and actor attribution with technique mapping. CTI shouldn't require a six-figure platform contract and a desk.

$ intel-sonar brief --today

correlating sources...
CISA KEV — 3 new exploited CVEs
EPSS — 12 scores crossed threshold
abuse.ch / ThreatFox — 847 fresh IOCs

corroboration:
2 sources agree · confidence: high
attribution candidate · T1190, T1059
sector exposure · Finance, Healthcare

briefing generated · 3 sources · deduplicated
$ _
CISA KEV EPSS scoring abuse.ch / ThreatFox IOC feed Threat heat map Actor attribution MITRE ATT&CK mapping Custom watchlists CISA KEV EPSS scoring abuse.ch / ThreatFox IOC feed Threat heat map Actor attribution MITRE ATT&CK mapping Custom watchlists

CTI is gatekept.

Threat intelligence is locked behind enterprise platforms, priced for teams that already have budget, and delivered in dashboards you can only open at your desk. Meanwhile the practitioners who need it most — analysts on call, responders in transit, engineers between meetings — are reading raw feeds on their phones. Intel Sonar is built for that reality: the same signal, correlated and scored, on the device already in your hand.

Six things Intel Sonar will do well.

01

AI-generated daily briefings

A concise threat briefing each day, synthesized from the day's correlated intelligence. What changed, what's being exploited, what it means for your sector — not a firehose of raw entries.

02

Live IOC feed

Indicators aggregated continuously from multiple public CTI sources into a single stream. Deduplicated across feeds, with source provenance retained on every indicator.

03

Threat heat map

Activity visualized geographically and by sector. See where threats are concentrating and which industries are absorbing them — orientation before you drill in.

04

Actor attribution profiles

Threat-actor profiles with explicit confidence scoring and MITRE ATT&CK technique mapping. The reasoning is visible — attribution you can question, not a verdict handed down.

05

Custom watchlists

Track the actors, CVEs, sectors, and indicators that matter to your environment. Your watchlist shapes what surfaces first, so the briefing reflects your exposure — not the average.

06

IOC search

Query an indicator directly — hash, domain, IP, URL. Get every source that has seen it, when, and in what context. Answer the "have we seen this before" question from anywhere.

From open feeds to a briefing you trust.

01 / Aggregate

Public CTI, unified.

Intel Sonar ingests public threat intelligence feeds — CISA KEV for known-exploited vulnerabilities, EPSS for exploit prediction scoring, abuse.ch and ThreatFox for indicator telemetry. One pipeline, many sources.

02 / Corroborate

Multi-source agreement.

Indicators are cross-referenced across feeds and deduplicated. When multiple independent sources converge on the same indicator, that corroboration is recorded and surfaced — because one feed saying something is not the same as three.

03 / Score

Confidence, not certainty.

Attribution and severity carry explicit confidence scores, with EPSS informing exploitation likelihood and ATT&CK mapping providing behavioral context. You see the strength of the claim alongside the claim.

04 / Deliver

Readable on a phone.

The output is written for a practitioner reading between other things — briefed, scannable, and drillable. Native SwiftUI, built for the platform rather than wrapped for it.

Native iOS. Serverless backend.

Intel Sonar is a native SwiftUI application backed by an AWS serverless stack — Lambda for the ingest and correlation pipeline, DynamoDB for indicator storage, API Gateway for the app-facing surface, and Cognito for authentication. No servers to babysit, and a cost model that scales to the practitioner rather than the enterprise.

// stack
client   · iOS, native SwiftUI
compute  · AWS Lambda
storage  · DynamoDB
api      · API Gateway
auth     · Amazon Cognito

// sources
CISA KEV
EPSS
abuse.ch / ThreatFox

Private beta. TestFlight.

Intel Sonar is in active development and currently running as a private beta on TestFlight. It is not on the App Store yet. We're onboarding practitioners who will actually use it in anger — analysts, responders, detection engineers — and who will tell us plainly where it falls short.

Tell us what you work on. We'll send a TestFlight invite.

Intelligence that travels with you.

Intel Sonar is being built for practitioners who don't get to read threat intel at a desk. If that's you, come break it early.