INTELSTACK SAAS // PRODUCT SPECIFICATION & ROADMAP
IntelStack
A threat intelligence platform that shows its working. It scans an indicator against twenty providers and tells you which one contributed each point of the verdict, detonates files and URLs in an isolated worker, and records what it observes as a graph you can pivot through. The capabilities below are running in the current build.
Join our waitlist to be among the first security teams to test IntelStack V1.
Join Beta WaitlistWhy We Are Building IntelStack
Solving the Core Challenges in Modern Threat Intelligence
Fragmented & Stale Feeds
A SOC ingests millions of disconnected hashes and addresses. Without correlation there is no way to tell whether an address is live attacker infrastructure or a CDN edge node that happened to appear in a feed.
Hours Lost on Manual Reports
Pulling indicators out of a PDF advisory and checking each one by hand costs hours per incident — hours spent during the window where containment still matters.
Automated Graph Intelligence
IntelStack scans against every configured provider at once, shows which one contributed each point of the verdict, and records what it observed — so the next analyst to see that indicator starts from what is already known about it.
Core Platform Capabilities
Deep Dive into IntelStack's Modular Engine
Multi-Source Indicator Scanning
An indicator is scanned against twenty threat intelligence providers in parallel. Each provider carries a weight that is visible in the source rather than buried in a model, because a MalwareBazaar hit and a GreyNoise classification are not the same claim and should not count the same.
File and URL Detonation
Submissions are asynchronous — you get an identifier back and the report when it is ready. The pipeline reads the file's structure, recovers its strings including the hidden ones, inspects URL, DNS and certificate behaviour, and where execution is enabled, runs the sample in an isolated environment built for the purpose.
Graph Topology and Similarity
Indicators and the infrastructure behind them are stored as a graph an analyst can pivot through rather than a table they have to join by hand. The rule that keeps it trustworthy is that an edge is only ever written from a relationship actually observed — never inferred from the fact that something scored badly.
MITRE ATT&CK Navigator
The full Enterprise matrix, loaded from the official MITRE dataset that ships with the platform. An earlier build asked a language model to generate the framework instead, which rendered invented technique IDs and group attributions as though they were real. It now reads the real thing.
Where We Sit in an Intrusion
Seven Stages, and What Is Actually Visible at Each
An attack is a sequence, not an event. The useful question about any threat intelligence platform is which parts of that sequence it can genuinely see — so here is ours, including the two stages where the honest answer is that we cannot.
Maps your exposed surface and picks a way in.
Exposure data on the infrastructure they stage from — open services, certificates, hosting.
Builds the payload. This happens entirely on their side.
Nothing, and we say so. A platform claiming visibility here is guessing.
Sends the link or the attachment.
The URL or file, checked against every configured source before anyone opens it.
Runs code on the target.
Behaviour recorded while the sample executes in an isolated environment.
Establishes a foothold that survives a reboot.
Persistence artefacts the sample creates, captured during analysis.
Calls home and waits for instructions.
The strongest signal we get — every destination contacted, and what else has contacted it.
Takes what they came for.
Destinations that appeared during analysis. What leaves your network is your telemetry, not ours.
Weaponization happens on the attacker's machine and exfiltration happens inside your network. We mark both rather than claiming coverage we do not have — a chain drawn all in one colour is a sales diagram, not a capability map.
What Each Provider Is Worth
The Weights, and the Reasoning Behind Them
Most scanners count votes. We do not, because a MalwareBazaar hit means somebody submitted the actual binary and a GreyNoise hit means the address scans the internet — and those are not the same claim. Here is the whole table. Disagree with it if you like; that is why it is published.
Enrichment sources are absent from this table on purpose. Geolocation and exposure lookups return Info: unscored, and excluded from the coverage figure, because knowing where an address lives is not a judgement about it.
Four Rules We Broke First
Each One Is a Defect We Shipped and Removed
None of these were hypothetical. Each was written by somebody making a failure path stop crashing, and each put a green badge in front of an analyst where no evidence existed.
We asked and learned nothing. That is not a finding.
We never asked. Coverage you do not have cannot reassure you.
Enrichment is context, not corroboration. It scores nothing.
Source counts set the floor, independently of the arithmetic.
What Happens to a Submitted File
Five Phases, and What Each One Can Tell You
Detonating an unknown sample is a privileged operation, so it stays switched off until an operator turns it on deliberately. The platform reports whether it is available rather than leaving you to assume.
When part of the analysis does not run, the report names it and the reason. A missing result is never rendered as a passed check.
Only What Was Observed
How an Edge Gets Written, and When It Does Not
Every edge above records something that was seen happening: the sample contacted the host, the host was resolved from that domain, the two hosts presented the same certificate. The verdict sits outside the graph with nothing attached to it. Drawing an edge because something scored badly is how a graph starts asserting attribution it cannot support — so the writer refuses to.
Where a Request Gets Checked
One Boundary, No Way Around It
A browser never reaches an analysis service directly. Every request crosses a boundary that establishes who is asking before anything downstream will act on it.
Signed in, working an indicator.
A session, and nothing else.
Every request is checked here, without exception.
Decides whether the request continues at all.
Scanning and detonation, reachable only from the boundary.
Verify independently — they do not trust the caller.
A convenience route once let the browser skip the boundary entirely, taking every session check with it. It was deleted, and the reason it must not come back is written down where the next person will find it.
Each analysis service checks its own caller rather than assuming that anything which reached it was allowed to. Being inside the network is not an authorisation.
Build Status
What Is Built, What Is Being Built, and What Is Not
Working in the Pre-Release Build
Work Toward the V1 Release
Under Consideration After V1
Interested in Early Beta Access or Technical Partnership?
Reach out to the engineering team directly and we will walk you through the build.