Idea
Automated pipeline extracting high-quality cyber threat intelligence from Telegram to support security teams and researchers.
Research Paper
Core Innovation
This paper introduces an end-to-end automated pipeline that systematically identifies relevant Telegram channels and scrapes large volumes of messages. It applies a BERT-based classifier to accurately filter threat intelligence from generic content, achieving high accuracy. The approach results in a comprehensive dataset of malicious indicators, enabling improved cyber threat detection and research.
Market Size (TAM)
$10–20B TAM for cyber threat intelligence platforms; $2–10B SAM from cybersecurity firms and enterprises. Driven by increasing cyber threats and demand for real-time intelligence.
Potential Customers & Pain Points
- Cybersecurity firms needing timely threat data
- Security operations centers requiring accurate indicators
- Researchers lacking large-scale CTI datasets
- Threat intelligence platforms seeking diverse data sources
Business Model
Subscription-based access to curated CTI datasets and API integration for security platforms.
Competitive Landscape
- Recorded Future
- Anomali
- ThreatConnect
Implementation Challenges
- Data privacy and compliance concerns
- Evolving adversary tactics requiring continuous updates
- Integration with existing security workflows
Validation Strategy
- Deploy pipeline on additional Telegram channels to test scalability
- Evaluate classifier performance on new data sources
- Partner with cybersecurity firms for real-world testing
Research Paper Overview
CTI Dataset Construction from Telegram
Summary
This paper presents an automated pipeline to collect and filter cyber threat intelligence from Telegram channels. It scrapes 145,349 messages from 12 curated channels and uses a BERT-based classifier with 96.64% accuracy to identify threat-related content. The resulting dataset includes 86,509 malicious indicators such as domains, IPs, URLs, hashes, and CVEs, providing a large-scale, high-quality resource for cyber threat detection research and operations.