C-THINK (CYBER THREAT INTELLIGENCE SYSTEM): An Innovative Solution that enables to conduct real time cyber threat intelligence, in each phase of a mission.

Authored by: Vittoria Sessa, Cyber Security Data Scientist, Leonardo

Role in PROTEAS project: Provider of the Cyber Threat Intelligence (CYBERINT) system, as well as the Cybersecurity Framework and OSINT services.

Leonardo participates in the PROTEAS project with its Cyber & Security Solutions Division, providing C-THINK, a Cyber Threat Intelligence System. C-THINK is a platform that supports the analysis and understanding of cyber threats that could affect an operation, enabling organizations to conduct cyber threat intelligence activities during both the mission-planning and operational phases.

Key Features

C-THINK is a complete Cyber Threat Intelligence (CTI) solution developed to manage the entire intelligence lifecycle, helping analysts and organizations improve their performance on the diverse intelligence tasks by providing automation functionalities to orchestrate the collection, processing and dissemination of the information.

The platform allows storage, organization, visualization and sharing of knowledge about cyber threats at all three levels: tactical, operational and strategic.

More specifically, C-THINK can provide support in the following Cyber Threat Intelligence process phases:

  1. Plan & Direction:
    • management and monitoring of information requests
    • development and tracking of collection plans, using configured information sources; task assignment to analysts and monitoring of performance
  2. Collection:
    • external threat intelligence, internal data sources, and user supplied data are fused in one single knowledge base
    • definition and integration of a personalized ontology
    • management of threat intelligence feeds through an extensive library of dedicated connectors, with full support for MISP, STIX, OTX, Sigma, YARA and many more formats
    • configuration and management of personalized data integration, through a REST API layer
  3. Process:
    • enrichment of incoming data with an event-based approach, based on a knowledge graph data model and a processing engine
    • library of processing tools with possibility of extension
    • customization of automatic and recursive data enrichment through playbooks
  4. Analyse:
    • exploratory data analysis functionalities
    • allows to navigate the underlying knowledge graph visually and through REST APIs
    • integrates a search engine DB that supports complex queries
    • provides a set of integrated tools to perform manual analysis and organize entities, evidences and findings in a threat analysis case
    • integrates an advanced editor to produce reports within the platform
  5. Disseminate:
    • automated notification about changes related to configurable topics of interest
    • dissemination of threat intelligence products through customized reports
    • distribution of intelligence feeds to SIEM, Firewalls, EDRs and other software products, through the integrated automation and orchestration functions.

Technical Components and Functionalities

C-THINK consists of various components:

  • Knowledge Graph and a Customizable Ontology: the graph data model at the heart of the CTI solution. A flexible data storage catalogue where entity types, their attributes and the possible relationships are defined.
  • Search Engine: The integrated search engine leverages the ontology definition and provides matches categorized by their entity types.
  • Web Interface: A user-friendly GUI, which allows the interaction with the platform, the navigation of the knowledge base through graph representations and supports all the intelligence lifecycles related activities. The knowledge dashboard allows to analyse data related to a given entity, together with all the entities that are linked through a direct or inferred relationship.
  • API interface: Baseline and specialized tools can be integrated leveraging existing connectors and APIs in such a way so as to provide customizable Collection, Processing and Dissemination phases of the intelligence cycle, fitting the needs of incident responders, Threat Intelligence analysts, SOC operators and CISOs, in one.

Operator Benefits

C-THINK solution is developed by Leonardo to manage the entire intelligence lifecycle, providing automatic functionalities aimed at orchestrating the collection, processing, and dissemination of information. It is based on a flexible and scalable knowledge base, that is built on top of a customizable ontology.

The C-THINK platform strengths include:

  • flexible and scalable knowledge base that is built on top of a customizable ontology containing all information related to both threat actors and victims
  • global and tailored Cyber Threat Intelligence services, crucial to effectively counter threat actors
  • coverage and operation support, through all phases of the intelligence lifecycle
  • possibility of integration with other products through APIs and consequently fusion of intelligence products with other data sources
  • support of two modes of use: as a stand-alone platform, since it has its own User Interface or with other intelligence systems, since it has an API interface that allows integration with external systems.

FIGURE: GUI Example – APT28 threat actor knowledge overview with malware types, attack patterns and tool types statistics

About Leonardo:

Leonardo is an international industrial group that delivers multi-domain technological capabilities for global security. A key player in the leading strategic Aerospace, Defence and Security programmes, it employs over 62,000 people worldwide. The company has a significant industrial presence in Italy, the UK, Poland and the US, and it also operates in 150 countries through subsidiaries, joint ventures and investments. Leonardo is a technological and industrial partner of governments, defence administrations, institutions and companies. Innovation, continuous research, digital industry and sustainability are the pillars of its business worldwide.

Focused on data protection, data valorization and data communication the Cyber & Security Solutions Division capitalizes on its Global Cybersec Center, cyber center of excellence, powered by Agentic-AI and based on a federated model, at logical and geographical level. The division delivers proprietary data platforms that transform complexity into actionable knowledge, trusted end-to-end cybersecurity to protect strategic and critical data across the entire data chain, and next-generation mission-critical communications that enable secure, resilient, and connected operations.

 

Leonardo S.p.A.
Piazza Monte Grappa 4
00195 Roma, Italy
https://www.leonardo.com

 

Scroll to Top