Intel Sonar is a native iOS app that puts real cyber threat intelligence in a practitioner's hands — daily AI-generated briefings, a live IOC feed, and actor attribution with technique mapping. CTI shouldn't require a six-figure platform contract and a desk.
Threat intelligence is locked behind enterprise platforms, priced for teams that already have budget, and delivered in dashboards you can only open at your desk. Meanwhile the practitioners who need it most — analysts on call, responders in transit, engineers between meetings — are reading raw feeds on their phones. Intel Sonar is built for that reality: the same signal, correlated and scored, on the device already in your hand.
A concise threat briefing each day, synthesized from the day's correlated intelligence. What changed, what's being exploited, what it means for your sector — not a firehose of raw entries.
Indicators aggregated continuously from multiple public CTI sources into a single stream. Deduplicated across feeds, with source provenance retained on every indicator.
Activity visualized geographically and by sector. See where threats are concentrating and which industries are absorbing them — orientation before you drill in.
Threat-actor profiles with explicit confidence scoring and MITRE ATT&CK technique mapping. The reasoning is visible — attribution you can question, not a verdict handed down.
Track the actors, CVEs, sectors, and indicators that matter to your environment. Your watchlist shapes what surfaces first, so the briefing reflects your exposure — not the average.
Query an indicator directly — hash, domain, IP, URL. Get every source that has seen it, when, and in what context. Answer the "have we seen this before" question from anywhere.
Intel Sonar ingests public threat intelligence feeds — CISA KEV for known-exploited vulnerabilities, EPSS for exploit prediction scoring, abuse.ch and ThreatFox for indicator telemetry. One pipeline, many sources.
Indicators are cross-referenced across feeds and deduplicated. When multiple independent sources converge on the same indicator, that corroboration is recorded and surfaced — because one feed saying something is not the same as three.
Attribution and severity carry explicit confidence scores, with EPSS informing exploitation likelihood and ATT&CK mapping providing behavioral context. You see the strength of the claim alongside the claim.
The output is written for a practitioner reading between other things — briefed, scannable, and drillable. Native SwiftUI, built for the platform rather than wrapped for it.
Intel Sonar is a native SwiftUI application backed by an AWS serverless stack — Lambda for the ingest and correlation pipeline, DynamoDB for indicator storage, API Gateway for the app-facing surface, and Cognito for authentication. No servers to babysit, and a cost model that scales to the practitioner rather than the enterprise.
Intel Sonar is in active development and currently running as a private beta on TestFlight. It is not on the App Store yet. We're onboarding practitioners who will actually use it in anger — analysts, responders, detection engineers — and who will tell us plainly where it falls short.
Tell us what you work on. We'll send a TestFlight invite.
Intel Sonar is being built for practitioners who don't get to read threat intel at a desk. If that's you, come break it early.