peng-gao-lab/ctinexus

CTINexus is a framework that leverages optimized in-context learning of LLMs to enable data-efficient extraction of cyber threat intelligence and the construction of high-quality cybersecurity knowledge graphs.

61
/ 100
Established

This tool helps cybersecurity analysts and security operations center (SOC) professionals automatically turn raw threat intelligence reports into structured knowledge graphs. You input unstructured text or a URL from a threat report, and it extracts key cybersecurity entities like malware, vulnerabilities, and tactics, along with their relationships. The output is an interactive visual graph and structured data that makes complex threat information easier to understand and use.

Available on PyPI.

Use this if you need to quickly extract and visualize critical entities and relationships from large volumes of unstructured cyber threat intelligence text without extensive manual effort or training data.

Not ideal if your primary goal is real-time anomaly detection or malware analysis directly from network traffic, as this tool focuses on processing textual threat intelligence.

cybersecurity-analysis threat-intelligence security-operations incident-response knowledge-management
Maintenance 10 / 25
Adoption 9 / 25
Maturity 24 / 25
Community 18 / 25

How are scores calculated?

Stars

71

Forks

16

Language

Python

License

MIT

Last pushed

Feb 25, 2026

Commits (30d)

0

Dependencies

14

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/llm-tools/peng-gao-lab/ctinexus"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.