Sentinel.STIX
AI-Powered CTI Engine Transforming Unstructured Telemetry to STIX 2.1
Multi-agent LLM intelligence pipeline utilizing Gemini 3 Pro and Claude 3.5 Sonnet to ingest raw vulnerability advisories and automate rigorous STIX 2.1 object graph serialization.
The Engineering Case Study
The Problem
Security analysts waste up to 20 hours per week manually extracting Indicators of Compromise (IoCs), malware signatures, and adversary tactics from PDF advisories and web disclosures to populate threat-sharing feeds.
How It Was Engineered
Sentinel.STIX ingests raw text, passes it through multi-stage LLM prompts with strict Pydantic/JSON schema guarantees, cross-references identified techniques against MITRE ATT&CK taxonomies, and serializes valid STIX 2.1 relationship bundles.
Engineering Hurdles Solved
Preventing LLM hallucinations of critical IP addresses, CVE IDs, or hashes. Implemented deterministic regex and database verification gates that validate all extracted entity values before bundle compilation.
Business & Production Outcome
Compresses hours of manual intelligence mapping into seconds of automated parsing, enabling real-time defensive intelligence exchange.