PROJECT CYBER ECHELONCyber Threat Resources
Transparency

Every source, and exactly what we do with it.

Good intelligence is auditable. Here is each feed Project Cyber Echelon draws on, what it adds, and the enrichment step every item passes through before it reaches you.

Public

The backbone. Authoritative, no cost, already flowing.

These are the same primary sources the commercial platforms build on. Project Cyber Echelon's value is not exclusive access to them — it is fusing them, scoring them for Texas, and explaining them.

SourceWhat it addsStatus
CISA KEVVulnerabilities confirmed exploited in the wild — the highest-priority signal there is.Live
NVDFull CVE detail and CVSS scoring for every referenced vulnerability. Queried with an authenticated API key for the higher rate limit.Live
VulnCheck KEVA broader known-exploited catalog than CISA KEV, with exploit references — often flags exploited vulnerabilities before they reach the CISA list.Live
CISA ICS advisoriesIndustrial control-system advisories relevant to Texas water, power, and manufacturing.Live
abuse.chThreatFox live malware, C2, and malicious-URL indicators (URLhaus and Feodo Tracker to follow). Free with an auth key.Live (ThreatFox)
AlienVault OTXCommunity threat "pulses" and IOCs, available over a free STIX/TAXII endpoint.Live

Commercial

Paid, but chosen for the smallest plan that adds real signal.

Each of these turns "this vulnerability exists" into "this is being attacked right now" or "this many Texas systems are exposed." We use the entry tier of each and keep the whole set inside the monthly budget.

SourceWhat it addsStatus
ransomware.liveRansomware leak-site victim postings, filtered to Texas — often weeks ahead of public disclosure. Free PRO key.Live
ShodanSecond exposure source and historical banners. Optional; a low-cost membership.Coming Soon
Texas Impact Score · v2

How the score works

Every item carries a 0–100 score and a severity. Both are computed in code from measured inputs, so the same evidence always produces the same number and anyone can audit it. The design follows CISA's SSVC decision model: prioritize by whether a threat is being used, how bad it is if it lands, and whether it touches the people we serve — not by CVSS alone.

EXPLOITATION
0–40
Is it being used? Confirmed active exploitation (CISA KEV, VulnCheck KEV, a ransomware leak-site posting) scores the full 40. Malware indicators from abuse.ch score 20–36 by the feed's own confidence. Everything else uses the FIRST EPSS probability that the CVE will be exploited in the next 30 days (36 × EPSS), with a floor of 15 when public exploit code exists.
IMPACT
0–25
How bad if it lands? The CVSS base score × 2.5. When no CVSS exists (ICS advisories, leak-site postings, indicators) a fixed default for that item type is used instead — never a guess.
TX EXPOSURE
0–25
Does it touch Texas? 12 points if a lifeline sector is affected (water, energy, communications, emergency services, healthcare, government, transportation), 7 for any other sector, 3 for none. Plus 0–8 for how prevalent the product is among small Texas organizations, and 5 when the item explicitly names Texas or a Texas entity.
CORROBORATION
0–10
How sure, how fresh? 3 points for a second independent source, 6 for three or more. 4 points when the item is under a week old, 2 under a month — so the feed leans toward what is happening now.

Severity bands and guardrails

ScoreSeveritySSVC decision
75–100CriticalAct
55–74HighAttend
35–54ElevatedTrack*
0–34ModerateTrack
  • Critical requires exploitation evidence. A high CVSS score alone can never reach Critical; without active exploitation or a high EPSS, the item is capped at High.
  • Known-exploited against a lifeline sector is never below High.
  • Scores move with the evidence. Every stored item is re-scored on each six-hour run with fresh EPSS values, so a CVE climbs as exploitation becomes likely and ages down as it goes stale.
  • No model in the loop. The only inputs a model supplies are the sector list and the 0–8 prevalence judgment, both bounded and anchored.
Enrichment

What the enrichment step actually does

Fusion and scoring happen in code. Explanation happens in the model. Every deduplicated threat is passed to a language model on Aegis Recon cloud services with the source material and a tightly scoped instruction.

MODEL
U.S. Frontier models, run on Aegis Recon cloud services, in-region (us-east-1). Fast and inexpensive — roughly $1 per million input tokens and $5 per million output — which keeps per-item enrichment a fraction of a cent.
JUDGE
Two narrow judgments the score needs and code cannot make: which sectors the item touches, and how prevalent the affected product is among small Texas organizations (0–8, with fixed anchors). The model does not assign the score or the severity — that happens in code.
EXPLAIN
A plain-English summary a non-specialist operator can act on — what it is, who it affects, why it matters here.
PRIORITIZE
Two to four concrete, ordered fix steps, written for someone with limited time and no security team.
PIN DOWN
The affected systems, software, and hardware — vendor, product, version range, and the fixed version. Software comes straight from NVD's structured CPE data; ICS/OT hardware is extracted from the advisory text. The feed is searchable by vendor so you can check your own gear in one step.
CORROBORATE
A confidence level (1–3) computed from how many independent sources reported the same threat, with CISA feeds counting extra. Surfaced on every card.

The guardrails

  • Grounded only in the source. The model summarizes and scores what the feeds provide; it is instructed not to invent CVEs, vendors, or facts.
  • Never the last word. Every enriched item carries a standing note to confirm against the vendor advisory or CISA before acting.
  • No customer data in the public pipeline. The public feed enriches public advisories and open indicators only; nothing you submit through this site is fed into it.
  • Nothing you send trains a model. The model provider does not use inputs to train its foundation models, and Project Cyber Echelon adds no training step of its own.