Your infrastructure as a graph.

ThreatClaw models your assets, vulnerabilities and attackers in a STIX 2.1 graph. The result: analyses impossible with a traditional SIEM.

STIX 2.1Compatible ANSSI / ENISA / OpenCTI / MISP

Blast Radius

If an asset is compromised, ThreatClaw calculates in real time all impacted assets at 1, 2 and 3 hops. Impact score weighted by criticality.

Attack Paths

Passive simulation: what paths would an attacker take to reach your critical data? Monthly proactive report without touching infra.

Actor Profiling

ThreatClaw automatically builds attacker profiles (country, ASN, MITRE techniques) and compares them to 7 known APT groups.

NIS2 Compliance

The graph IS your NIS2 Article 21 mapping. Supply chain risk, dependencies, exportable report for regulators.

threatclaw graph
$ curl /api/tc/graph/blast-radius/srv-prod-01 { "source_asset": "srv-prod-01", "total_impacted": 4, "critical_impacted": 1, "impact_score": 23.0, "recommendation": "Immediate network isolation, critical assets exposed", "hops": [ { "hop": 1, "count": 2, "assets": ["srv-web-02", "srv-app-01"] }, { "hop": 2, "count": 1, "assets": ["srv-db-01 (CRITICAL)"] }, { "hop": 3, "count": 1, "assets": ["srv-backup-01"] } ] }

How ThreatClaw reasons

01

Observe

Collects findings, Sigma alerts, syslog. Continuously syncs the STIX 2.1 threat graph.

02

Correlate

The native STIX 2.1 graph detects lateral movement, coordinated campaigns, and attack paths to your critical assets.

03

Enrich

19+ threat intelligence sources (NVD, CISA KEV, EPSS, GreyNoise, CERT-FR...). Contextual confidence score 0-100.

04

Decide & Act

AI proposes actions (44-command whitelist). Auto-generated MITRE playbooks. HITL to stay in control.

3 pillars. Zero blind spots.

Detection, response, compliance, each pillar works independently.

Detection

  • 3 independent layers: Sigma + ML + AI
  • 26 automatic CTI enrichments
  • DGA detection (malicious DNS)
  • STIX 2.1 attack graph
  • Automatic Blast Radius
  • Lateral movement detected

Response

  • HITL, 1-click approval on Telegram
  • Emergency Kill Switch
  • AI-generated playbooks
  • 4 modes: Analyst · Investigator · HITL · Autonomous
  • Multi-channel notifications
  • Slack, Telegram, Discord, Mattermost, Ntfy, Gotify, Email, Signal, WhatsApp, Olvid

Compliance & AI Governance

  • 11 automatic PDF reports
  • NIS2 · GDPR · ISO 27001 · NIST 800-61
  • EU AI Act Art.12 · ISO 42001 · NIST AI RMF 2025
  • Shadow AI detection (0 MITM, passive)
  • AI governance whitepaper, 15 pages in 30s
  • Hash-chained cryptographic audit log