โโโ โโโโโโโ โโโโโโโโโโโ โโโโโโโ โโโโโโ
โโโ โโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโ โโโ โโโโโโโโโโโโโโ โโโโโโ โโโ
โโโโโโโ โโโ โโโโโโโโโโ โโโ โโโโโโ โโโ
See what lives in the shadows โ before it finds you.
UMBRA is a developer-first, AI-native cyber threat intelligence platform that monitors underground networks โ Tor, I2P, Telegram channels, paste sites, dark marketplaces, and hacker forums โ for credential breaches, leaked PII, brand threats, and adversary planning signals targeting your organization.
Over 88% of basic web application attacks use stolen credentials (Verizon 2025 DBIR). More than 24 billion username-password pairs currently circulate on criminal markets. The window between credential harvest and weaponization is your only chance to act. UMBRA closes that window.
| Problem with existing tools | UMBRA's answer |
|---|---|
| Enterprise-only pricing ($50Kโ$100K+/yr) | Self-serve plans from $99/month |
| Sales-gated, weeks to onboard | Under 5 minutes to first alert |
| Raw data dumps, no context | AI-generated summaries + remediation playbooks |
| Dated, slow dashboards | Modern Next.js UI with real-time WebSocket feeds |
| No API-first approach | REST API with full OpenAPI 3.0 spec |
| High false-positive alert noise | XGBoost risk scoring + LLM triage reduces noise |
UMBRA Command Center โ Real-time threat telemetry, AI-powered risk scoring, and live breach activity feed. Organization risk score, active watchlist, critical findings, and Claude-generated AI insights โ all in one view.
Note
All company names, domains, and organizations shown in the screenshot (e.g. "acme.com", "project titan") are fictional and used for demonstration purposes only. Any resemblance to real companies is purely coincidental.
- ๐ต๏ธ Dark Web Monitoring โ Tor, I2P, Telegram, Discord, paste sites, ransomware leak sites
- ๐ Credential Breach Detection โ sub-60-minute detection from harvest to alert
- ๐ค AI Threat Intelligence โ Claude-powered summaries, risk scoring, MITRE ATT&CK mapping
- ๐ Real-Time Dashboard โ Live alert feed, threat metrics, watchlist management
- ๐ Multi-Channel Alerts โ Email, Slack, Teams, webhooks, PagerDuty, Jira
- ๐๏ธ Watchlist Management โ Monitor domains, email ranges, brand keywords, IP ranges
- ๐ Executive Reports โ PDF/CSV exports, weekly digests, compliance-ready audit logs
- ๐ API-First โ Full REST API + SDK for programmatic integration in CI/CD pipelines
- ๐ข Multi-Tenant (MSSP) โ Manage multiple client organizations from one dashboard
- ๐ก๏ธ Privacy by Design โ Credentials hashed/anonymized; plaintext PII is never stored
UMBRA is a pnpm monorepo with a domain-driven microservices backend and a Next.js frontend. The current repository contains the web dashboard and REST API; the full microservices platform is designed to run on Kubernetes (EKS).
umbra-platform/
โโโ apps/
โ โโโ api/ โ Express + TypeScript REST API (Node.js 22)
โ โโโ web/ โ Next.js 16 dashboard (React 19, TailwindCSS 4)
โโโ docs/ โ Architecture, PRD, API contracts, roadmap
โโโ docker-compose.ymlโ Local dev: PostgreSQL + Redis
โโโ package.json โ pnpm workspace root
Dark Web Sources Intelligence Pipeline Delivery
โโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโ
Tor .onion sites โโโถ Content Classifier โโโถ Email
Telegram channels โโโถ Credential Extractor โโโถ Slack / Teams
Paste sites โโโถ MinHash Deduplication โโโถ Webhook
Ransomware leaks โโโถ Risk Scorer (XGBoost) โโโถ PagerDuty
I2P / ZeroNet โโโถ LLM Enrichment (Claude) โโโถ Dashboard UI
Hacker forums โโโถ MITRE ATT&CK Mapper โโโถ REST API
| Layer | Technology |
|---|---|
| Framework | Next.js 16 with App Router + Turbopack |
| UI | React 19 with Concurrent Rendering |
| Styling | TailwindCSS 4 with custom design tokens |
| Components | Radix UI primitives |
| Animations | Motion + GSAP + Lenis smooth scroll |
| State | Zustand |
| Data Fetching | TanStack Query |
| Charts | Recharts |
| Forms | React Hook Form + Zod validation |
| Layer | Technology |
|---|---|
| Runtime | Node.js 22 LTS |
| Framework | Express + TypeScript |
| Database | PostgreSQL 16 via Prisma ORM |
| Cache / Pub-Sub | Redis 7 (ioredis) |
| Job Queues | Bull (background job processing) |
| Auth | JWT (access + refresh tokens) |
| AI Integration | Google Gemini API |
| Breach Lookup | HaveIBeenPwned API |
| Nodemailer (SMTP/SendGrid) |
| Concern | Technology |
|---|---|
| Cloud | AWS (us-east-1 primary, eu-west-1 GDPR) |
| Orchestration | Kubernetes 1.30 (EKS) |
| Service Mesh | Istio (mTLS) |
| IaC | Terraform + Helm |
| CI/CD | GitHub Actions โ ECR โ EKS |
| Edge / WAF | Cloudflare |
| Secrets | HashiCorp Vault |
| Observability | Prometheus + Grafana + OpenTelemetry + Jaeger |
- Node.js 22 LTS
- pnpm 9+
- Docker Desktop (for local PostgreSQL + Redis)
git clone https://github.com/SnehalPrince/UMBRA-Intelligence-platform.git
cd UMBRA-Intelligence-platformpnpm install# Starts PostgreSQL (port 5432) and Redis (port 6379)
docker-compose up -d# API environment
cp apps/api/.env.example apps/api/.envEdit apps/api/.env with your values:
DATABASE_URL="postgresql://umbra:umbra@localhost:5432/umbra_db"
REDIS_URL="redis://localhost:6379"
JWT_SECRET="your-super-secret-jwt-key"
JWT_REFRESH_SECRET="your-refresh-secret"
GEMINI_API_KEY="your-gemini-api-key"
HIBP_API_KEY="your-hibp-api-key"
SMTP_HOST="smtp.sendgrid.net"
SMTP_USER="apikey"
SMTP_PASS="your-sendgrid-api-key"pnpm db:migrate# Start both API and Web concurrently
pnpm dev
# Or individually:
pnpm --filter api dev # API on http://localhost:4000
pnpm --filter web dev # Web on http://localhost:3000src/
โโโ index.ts โ Server entry point
โโโ app.ts โ Express app setup (CORS, helmet, morgan)
โโโ controllers/
โ โโโ auth.controller.ts โ Register, login, logout, token refresh
โ โโโ dashboard.controller.ts โ Threat metrics and summary stats
โ โโโ findings.controller.ts โ CRUD for threat findings
โ โโโ watchlist.controller.ts โ Target watchlist management
โโโ routes/
โ โโโ auth.routes.ts โ POST /api/auth/*
โ โโโ dashboard.routes.ts โ GET /api/dashboard/*
โ โโโ findings.routes.ts โ GET/POST/PATCH /api/findings/*
โ โโโ watchlist.routes.ts โ GET/POST/DELETE /api/watchlist/*
โโโ services/
โ โโโ ai.service.ts โ Gemini AI threat analysis
โ โโโ email.service.ts โ Alert email delivery
โ โโโ hibp.service.ts โ HaveIBeenPwned breach lookup
โโโ middlewares/
โ โโโ auth.ts โ JWT bearer token verification
โ โโโ error.ts โ Centralized error handler
โโโ lib/
โโโ prisma.ts โ Singleton Prisma client
โโโ redis.ts โ ioredis client
โโโ jwt.ts โ JWT sign/verify helpers
โโโ queue.ts โ Bull background job queue
src/
โโโ app/
โ โโโ layout.tsx โ Root layout, fonts, metadata
โ โโโ page.tsx โ Landing / splash page
โ โโโ globals.css โ UMBRA dark theme + CSS variables
โ โโโ (auth)/
โ โ โโโ layout.tsx โ Centered auth layout
โ โ โโโ login/page.tsx โ Login form with JWT flow
โ โ โโโ register/page.tsx โ Registration with validation
โ โโโ (dashboard)/
โ โโโ layout.tsx โ Sidebar navigation
โ โโโ dashboard/page.tsx โ Threat intelligence overview
โ โโโ search/page.tsx โ Dark web search interface
โ โโโ watchlist/page.tsx โ Monitored target management
โ โโโ alerts/page.tsx โ Security alerts feed
โ โโโ reports/page.tsx โ Threat analytics & exports
โ โโโ settings/page.tsx โ Account & org settings
โโโ components/
โ โโโ ui/
โ โโโ button.tsx โ Variant-based Button (CVA)
โ โโโ input.tsx โ Styled Input with ref forwarding
โโโ providers/
โ โโโ QueryProvider.tsx โ TanStack React Query setup
โ โโโ SmoothScrollProvider.tsx โ Lenis smooth scroll
โโโ lib/
โโโ utils.ts โ cn() class merging utility
Base URL: http://localhost:4000/api
| Method | Endpoint | Description |
|---|---|---|
POST |
/auth/register |
Register a new organization & user |
POST |
/auth/login |
Authenticate and receive JWT tokens |
POST |
/auth/logout |
Invalidate refresh token |
POST |
/auth/refresh |
Rotate access token using refresh token |
| Method | Endpoint | Description |
|---|---|---|
GET |
/dashboard/stats |
Threat metrics and KPI summary |
GET |
/dashboard/recent-alerts |
Most recent alert events |
| Method | Endpoint | Description |
|---|---|---|
GET |
/findings |
List all threat findings (paginated) |
GET |
/findings/:id |
Get a single finding with AI enrichment |
PATCH |
/findings/:id/status |
Update finding status (resolved / FP) |
| Method | Endpoint | Description |
|---|---|---|
GET |
/watchlist |
List monitored assets |
POST |
/watchlist |
Add a domain, email range, or keyword |
DELETE |
/watchlist/:id |
Remove a monitored asset |
Full OpenAPI 3.0 specification:
docs/API.md
Core entities managed by Prisma + PostgreSQL:
User โโโโโโโโโโโโโโโโโโโโ Organization
โ โ
โโโ Sessions โโโ WatchlistItems (domains, emails, keywords)
โ โ
โโโ (via org) โโโ Findings (threat events)
โ โโโ AI Enrichment (summary, severity, remediation)
โ
โโโ Alerts (delivery log)
Full schema:
apps/api/prisma/schema.prismaยท Database design:docs/Database.md
| Document | Description |
|---|---|
docs/PRD.md |
Product Requirements Document โ vision, personas, features, pricing |
docs/Architecture.md |
Full system architecture with diagrams |
docs/TechStack.md |
Technology choices and rationale |
docs/API.md |
API endpoint contracts and request/response schemas |
docs/Database.md |
Database schema design and ERD |
docs/Design.md |
UI/UX design system and component library |
docs/Roadmap.md |
Product roadmap across 4 phases |
docs/Requirements.md |
Functional and non-functional requirements |
docs/Implementation.md |
Implementation plan and developer guide |
docs/Contracts.md |
Service contracts and inter-service API specs |
docs/Progress.md |
Build progress tracker |
docs/ProjectStructure.md |
Monorepo directory map |
docs/Mobile-Responsiveness.md |
Mobile UX strategy |
- Monorepo scaffold (pnpm workspaces)
- Express REST API with auth, findings, watchlist, dashboard
- Prisma schema with all core entities
- Next.js dashboard with auth flows and all page routes
- Real-time WebSocket alert infrastructure
- AI service integration (Gemini)
- HIBP breach lookup service
- Redis cache + Bull job queues
- AI threat summarization (Claude enrichment per finding)
- Dark forum & paste site monitoring
- Ransomware leak site monitoring (200+ sites)
- SIEM integrations (Splunk, Microsoft Sentinel)
- Multi-tenant MSSP workspace support
- Python + Node.js SDKs
- Stripe billing integration
- 3D Threat Intelligence Graph (Three.js / R3F)
- Threat actor profiling and MITRE ATT&CK mapping
- Initial Access Broker (IAB) monitoring
- Automated remediation workflows (Okta, Azure AD)
- Brand protection & lookalike domain detection
- SOC 2 Type II certification
- Executive / VIP monitoring module
- Mobile app (React Native + Expo)
- White-label solution for MSSPs
- Custom threat intelligence report generation
- Integration marketplace ecosystem
UMBRA is built with privacy by design:
- โ No plaintext credentials ever stored โ emails are SHA-256 hashed; passwords are partially masked
- โ Zero Trust networking โ mTLS between all microservices via Istio service mesh
- โ Encryption everywhere โ AES-256 at rest, TLS 1.3 in transit
- โ Secrets in Vault โ HashiCorp Vault; no secrets in environment variables in production
- โ GDPR-compliant โ EU data residency in eu-west-1; data minimization enforced
- โ Immutable audit logs โ S3 WORM bucket with 7-year retention
- โ Passive monitoring only โ UMBRA performs defensive intelligence only; no offensive operations
Full security architecture:
docs/Architecture.md#10-security-architecture
| Plan | Price | For |
|---|---|---|
| Scout | Free | Individuals, researchers โ 1 domain, manual lookups |
| Operator | $99/mo | Startups, SMBs โ 3 domains, API access, Slack alerts |
| Sentinel | $299/mo | Growing teams โ 10 domains, SIEM integration |
| Guardian | $599/mo | Security teams โ 25 domains, remediation workflows |
| Enterprise | $999+/mo | Large orgs, MSSPs โ unlimited, white-label, SLA |
- Fork the repository
- Create a feature branch:
git checkout -b feat/your-feature - Commit with conventional commits:
git commit -m "feat(api): add threat scoring endpoint" - Push and open a Pull Request
Please read
docs/Implementation.mdfor coding conventions and contribution guidelines.
MIT License โ see LICENSE for details.
Built with ๐ค by SnehalPrince
UMBRA Intelligence โ Defensive dark web monitoring. All data used solely for organizational protection.
