Cybersecurity is broken.

Current tools generate noise, not security.

4 500+
alerts/day on average in a SOC
194
days to detect a breach (IBM 2025)
3.5M
unfilled cybersecurity jobs worldwide
68%
of alerts ignored due to lack of resources

Too many alerts, not enough analysts

SIEMs generate thousands of daily alerts. SOC teams are overwhelmed and real threats slip through the cracks.

Passive tools that wait

Current solutions detect but don't act. The time between detection and remediation is measured in hours, sometimes days.

A global talent shortage

3.5 million unfilled positions. Even with budget, finding and retaining experts is a major challenge.

ThreatClaw thinks. Acts. Protects.

An autonomous agent that doesn't just detect, it correlates, decides and proposes.

STIX 2.1 Graph Intelligence

Native STIX 2.1 graph: automatic correlation, attack paths, blast radius, actor profiling. STIX 2.1 standard compatible with ANSSI/ENISA.

19+ source enrichment

NVD, CISA KEV, EPSS, MITRE ATT&CK, CERT-FR, GreyNoise, CrowdSec, ThreatFox and more. Automatic weighted confidence score 0-100.

5 sovereign AI levels

L0 Conversational, L1 Triage, L2 Forensic, L2.5 Instruct, L3 Anonymized Cloud. Auto pipeline stays 100% local. Cloud only when the CISO speaks.

Multi-channel + NLP Bot

Alerts via Slack, Telegram, Mattermost, Ntfy. Conversational NLP bot with memory and pronoun resolution.

2:17 AM.

What happens while you sleep.

From first anomaly to contained incident:2 minutes 32 seconds
tsourceévénement
02:17:03
Integrated syslog collector + Sigma
47 SSH attempts in 8 min, Sigma rule triggered

IP 185.220.101.47 · srv-prod-01 · user rotation: root, admin, backup

02:17:04
+1s
CrowdSec CTI
Known malicious IP, 1,247 community reports

Reputation: malicious · Behavior: ssh:bruteforce · Active for 18 days

02:17:09
+6s
AI Agent, correlation
Kill chain reconstructed, 4 cross-referenced sources

Successful backup user login at 02:09 · CVE-2023-38408 unpatched OpenSSH (EPSS 0.91) · AWS key exposed in /var/log/deploy.log for 6h

02:17:13
+10s
Slack HITL
CISO woken up, full analysis + 3 proposed actions
CRITICAL · srv-prod-01 · Kill chain detected

IP 185.220.101.47 malicious (CrowdSec) · backup user compromised

1. Block IP
2. Lock account
3. Patch OpenSSH
All 3 actions~ IP + account I'll handle it
02:19:28
+2m25s
RSSI
Approval from phone, actions 1 and 2

The CISO reads the analysis, verifies the CrowdSec source, approves IP block and account lock. Prefers to patch OpenSSH during the day.

02:19:29
+1s
Execution
Remediation executed · NIS2 report generated · IP reported to CrowdSec

IP blocked · Account locked · Cryptographically signed audit log · NIS2 §2b incident report available

4
Correlated sources
10s
Full analysis
2m32s
Incident contained
1
Human decision

19+ sources. 4,500 alerts/day. One single graph.

SIEM, EDR, firewalls, logs, CTI, scans, ThreatClaw ingests everything, correlates everything, and turns noise into clear signal.

With ThreatClaw
Without ThreatClaw

Data correlated in a STIX 2.1 graph. Every alert enriched, scored, linked to context. Clear signal.

4,500 alerts/day from 19+ different sources. 68% ignored. No correlation. Noise.

AtraditionalSOCproducesalerts.ThreatClawproducesdecisions.

11 regulatory reports. Pre-filled. Signed. Audit-ready.

NIS2, GDPR, EU AI Act, ISO 27001, ISO 42001, NIST AI RMF, NIST CSF 2.0, EU CRA, SOC 2, HDS, PCI-DSS, each incident triggers the right document, Ed25519-signed, defensible before ANSSI or a third-party auditor.

Incident responseCompliance & auditAI Governance

Early Warning 24h

NIS2 Art.23

Initial notification within 24h, auto pre-filled

72h Report

NIS2 Art.23

Intermediate update with indicators of compromise

Final Report

NIS2 Art.23

Full analysis, root causes, actions taken, recommendations

GDPR Article 33

RGPD

CNIL breach notification, auto PII detection + CISO override

NIST SP 800-61

NIST

CSF 2.0 format, US federal agencies compatible

ISO 27001

ISO 27001:2022

A.5.24-A.5.28 controls, classification, response, lessons learned

Checklist Art.21

NIS2

The 10 mandatory security measures, live score per measure

Executive Report

Management

Non-technical board summary, business impact, residual risks

Technical Report

RSSI / SOC

Detailed forensics, IOCs, MITRE ATT&CK timeline, blast radius

Audit Trail

Legal proof

Hash-chained immutable log, every ThreatClaw action logged, signed, timestamped

EU AI Act

EU 2024/1689 Art.12

High-risk AI inventory · logging · gaps · 2026-08-02 deadline

ISO 42001

AI Management System

2023 AI standard, 8 Annex A controls (policy, life cycle, third-party)

NIST AI RMF

2025 Revision

4 Govern/Map/Measure/Manage functions, shadow AI explicitly named

AI Governance Whitepaper

Corporate · 15 pages

Procurement-ready document · inventory + 4 frameworks + roadmap

Without ThreatClaw
  • ×CISO writes NIS2 reports manually after each incident
  • ×Audit trail scattered across 5 tools, no signed timestamping
  • ×Risk of missing items on the Art.21 10-measure checklist
  • ×During audit, evidence is hunted in Slack logs
With ThreatClaw
  • Document pre-filled as soon as the incident is classified, operator validates
  • Single Ed25519 hash chain, exportable as evidence
  • Live Art.21 checklist, live per-measure score
  • During audit, auditor downloads the PDF + signed audit-trail

The operator validates, signs, exports. Everything stays self-hosted, with cryptographic audit trail included.

Your infrastructure as a graph.

ThreatClaw models your assets, vulnerabilities and attackers in a STIX 2.1 graph. The result: analyses impossible with a traditional SIEM.

STIX 2.1Compatible ANSSI / ENISA / OpenCTI / MISP

Blast Radius

If an asset is compromised, ThreatClaw calculates in real time all impacted assets at 1, 2 and 3 hops. Impact score weighted by criticality.

Attack Paths

Passive simulation: what paths would an attacker take to reach your critical data? Monthly proactive report without touching infra.

Actor Profiling

ThreatClaw automatically builds attacker profiles (country, ASN, MITRE techniques) and compares them to 7 known APT groups.

NIS2 Compliance

The graph IS your NIS2 Article 21 mapping. Supply chain risk, dependencies, exportable report for regulators.

threatclaw graph
$ curl /api/tc/graph/blast-radius/srv-prod-01 { "source_asset": "srv-prod-01", "total_impacted": 4, "critical_impacted": 1, "impact_score": 23.0, "recommendation": "Immediate network isolation, critical assets exposed", "hops": [ { "hop": 1, "count": 2, "assets": ["srv-web-02", "srv-app-01"] }, { "hop": 2, "count": 1, "assets": ["srv-db-01 (CRITICAL)"] }, { "hop": 3, "count": 1, "assets": ["srv-backup-01"] } ] }

How ThreatClaw reasons

01

Observe

Collects findings, Sigma alerts, syslog. Continuously syncs the STIX 2.1 threat graph.

02

Correlate

The native STIX 2.1 graph detects lateral movement, coordinated campaigns, and attack paths to your critical assets.

03

Enrich

19+ threat intelligence sources (NVD, CISA KEV, EPSS, GreyNoise, CERT-FR...). Contextual confidence score 0-100.

04

Decide & Act

AI proposes actions (44-command whitelist). Auto-generated MITRE playbooks. HITL to stay in control.

Not just an agent. A bunker.

An AI agent touching your infra, scary? We think so too. That's why we armored everything.

Written in Rust, the only language where 70% of critical CVEs are impossible by construction.

Recommended by NSA, CISA and Microsoft for critical security software. Learn more →

Your data stays with you

Default anonymizer before each cloud LLM call · internal IPs, credentials, emails and FQDNs replaced by tokens. Custom regex patterns extend the mask to public IPs, business identifiers or any proprietary format. Never mode disables cloud calls entirely.

Technical details →

5 AI levels, 3 fully local

L0 conversational, L1 triage and L2 forensic run on Mistral Small or Qwen 14B hosted on your infrastructure. No cloud call required for day-to-day operations. L3 cloud stays optional, anonymized, for complex cases only.

Technical details →

Audited supply chain

All dependencies come from crates.io (no unverified git sources). cargo audit runs in CI every Monday to catch CVEs published on the crates we use. Over 3000 tests pass on every PR.

Technical details →

12+ SOC connectors already wired

Wazuh, Microsoft Sentinel, Microsoft Defender XDR, Active Directory, Velociraptor, OPNsense, pfSense, Fortinet, Mikrotik, Graylog, Elastic SIEM, Proxmox, GLPI. Wired through the dashboard, no glue code to write. Your hosts auto-enrol as soon as they ship their logs.

Technical details →

Open source AGPL · auditable code

The source code is public. You (or a consultant) can audit it line by line, compile it yourself, verify the binary matches. A commercial dual-license is available for proprietary needs.

Technical details →

Skills in a cage

Each skill runs in an isolated sandbox with cryptographic signature. CPU limited, network off by default. A modified file won't load.

Technical details →

Blockchain-style audit log

Cryptographic signature chain in PostgreSQL. No modification possible after insertion, even by a DBA. Native NIS2 audit proof.

Technical details →
OWASP ASI 2026 · 9/9 pillars covered (self-assessed)
9 out of 10 risks covered by the 5 security pillars.
Explore the full security architecture

2 commands. Installed.

ThreatClaw installs in minutes on Linux. Then configure it to match your infrastructure.

bash
# Install ThreatClaw
$ curl -fsSL https://get.threatclaw.io | sudo bash
# Start ThreatClaw
$ threatclaw run

Supported platforms

LinuxmacOSWindowsDocker

Ready to take back control?

Deploy ThreatClaw in 5 minutes. Open source, free, no telemetry.