Good intelligence is auditable. Here is each feed Project Cyber Echelon draws on, what it adds, and the enrichment step every item passes through before it reaches you.
These are the same primary sources the commercial platforms build on. Project Cyber Echelon's value is not exclusive access to them — it is fusing them, scoring them for Texas, and explaining them.
| Source | What it adds | Status |
|---|---|---|
| CISA KEV | Vulnerabilities confirmed exploited in the wild — the highest-priority signal there is. | Live |
| NVD | Full CVE detail and CVSS scoring for every referenced vulnerability. Queried with an authenticated API key for the higher rate limit. | Live |
| VulnCheck KEV | A broader known-exploited catalog than CISA KEV, with exploit references — often flags exploited vulnerabilities before they reach the CISA list. | Live |
| CISA ICS advisories | Industrial control-system advisories relevant to Texas water, power, and manufacturing. | Live |
| abuse.ch | ThreatFox live malware, C2, and malicious-URL indicators (URLhaus and Feodo Tracker to follow). Free with an auth key. | Live (ThreatFox) |
| AlienVault OTX | Community threat "pulses" and IOCs, available over a free STIX/TAXII endpoint. | Live |
Each of these turns "this vulnerability exists" into "this is being attacked right now" or "this many Texas systems are exposed." We use the entry tier of each and keep the whole set inside the monthly budget.
| Source | What it adds | Status |
|---|---|---|
| ransomware.live | Ransomware leak-site victim postings, filtered to Texas — often weeks ahead of public disclosure. Free PRO key. | Live |
| Shodan | Second exposure source and historical banners. Optional; a low-cost membership. | Coming Soon |
Every item carries a 0–100 score and a severity. Both are computed in code from measured inputs, so the same evidence always produces the same number and anyone can audit it. The design follows CISA's SSVC decision model: prioritize by whether a threat is being used, how bad it is if it lands, and whether it touches the people we serve — not by CVSS alone.
| Score | Severity | SSVC decision |
|---|---|---|
| 75–100 | Critical | Act |
| 55–74 | High | Attend |
| 35–54 | Elevated | Track* |
| 0–34 | Moderate | Track |
Fusion and scoring happen in code. Explanation happens in the model. Every deduplicated threat is passed to a language model on Aegis Recon cloud services with the source material and a tightly scoped instruction.