Your infrastructure as a graph.
ThreatClaw models your assets, vulnerabilities and attackers in a STIX 2.1 graph. The result: analyses impossible with a traditional SIEM.
Blast Radius
If an asset is compromised, ThreatClaw calculates in real time all impacted assets at 1, 2 and 3 hops. Impact score weighted by criticality.
Attack Paths
Passive simulation: what paths would an attacker take to reach your critical data? Monthly proactive report without touching infra.
Actor Profiling
ThreatClaw automatically builds attacker profiles (country, ASN, MITRE techniques) and compares them to 7 known APT groups.
NIS2 Compliance
The graph IS your NIS2 Article 21 mapping. Supply chain risk, dependencies, exportable report for regulators.
How ThreatClaw reasons
Observe
Collects findings, Sigma alerts, syslog. Continuously syncs the STIX 2.1 threat graph.
Correlate
The native STIX 2.1 graph detects lateral movement, coordinated campaigns, and attack paths to your critical assets.
Enrich
19+ threat intelligence sources (NVD, CISA KEV, EPSS, GreyNoise, CERT-FR...). Contextual confidence score 0-100.
Decide & Act
AI proposes actions (44-command whitelist). Auto-generated MITRE playbooks. HITL to stay in control.
3 pillars. Zero blind spots.
Detection, response, compliance, each pillar works independently.
Detection
- ›3 independent layers: Sigma + ML + AI
- ›26 automatic CTI enrichments
- ›DGA detection (malicious DNS)
- ›STIX 2.1 attack graph
- ›Automatic Blast Radius
- ›Lateral movement detected
Response
- ›HITL, 1-click approval on Telegram
- ›Emergency Kill Switch
- ›AI-generated playbooks
- ›4 modes: Analyst · Investigator · HITL · Autonomous
- ›Multi-channel notifications
- ›Slack, Telegram, Discord, Mattermost, Ntfy, Gotify, Email, Signal, WhatsApp, Olvid
Compliance & AI Governance
- ›11 automatic PDF reports
- ›NIS2 · GDPR · ISO 27001 · NIST 800-61
- ›EU AI Act Art.12 · ISO 42001 · NIST AI RMF 2025
- ›Shadow AI detection (0 MITM, passive)
- ›AI governance whitepaper, 15 pages in 30s
- ›Hash-chained cryptographic audit log