Skip to content

About

๐Ÿ•ต๏ธ AI-native dark web & cyber threat intelligence platform. Monitors Tor, Telegram, paste sites & breach databases. Sub-60min credential alerts, LLM-powered threat analysis, real-time dashboard.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

ย 

History

19 Commits

Folders and files

NameName
Last commit message
Last commit date
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

โ–ˆโ–ˆโ•—   โ–ˆโ–ˆโ•—โ–ˆโ–ˆโ–ˆโ•—   โ–ˆโ–ˆโ–ˆโ•—โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•— โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—  โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—
โ–ˆโ–ˆโ•‘   โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ–ˆโ–ˆโ•— โ–ˆโ–ˆโ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ•”โ•โ•โ–ˆโ–ˆโ•—โ–ˆโ–ˆโ•”โ•โ•โ–ˆโ–ˆโ•—โ–ˆโ–ˆโ•”โ•โ•โ–ˆโ–ˆโ•—
โ–ˆโ–ˆโ•‘   โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ•”โ–ˆโ–ˆโ–ˆโ–ˆโ•”โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ•โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ•โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•‘
โ–ˆโ–ˆโ•‘   โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ•‘โ•šโ–ˆโ–ˆโ•”โ•โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ•”โ•โ•โ–ˆโ–ˆโ•—โ–ˆโ–ˆโ•”โ•โ•โ–ˆโ–ˆโ•—โ–ˆโ–ˆโ•”โ•โ•โ–ˆโ–ˆโ•‘
โ•šโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ•โ–ˆโ–ˆโ•‘ โ•šโ•โ• โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ•โ–ˆโ–ˆโ•‘  โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ•‘  โ–ˆโ–ˆโ•‘
 โ•šโ•โ•โ•โ•โ•โ• โ•šโ•โ•     โ•šโ•โ•โ•šโ•โ•โ•โ•โ•โ• โ•šโ•โ•  โ•šโ•โ•โ•šโ•โ•  โ•šโ•โ•

The Shadow Intelligence Platform

See what lives in the shadows โ€” before it finds you.


License Node Next.js TypeScript Prisma Redis PostgreSQL pnpm


What is UMBRA?

UMBRA is a developer-first, AI-native cyber threat intelligence platform that monitors underground networks โ€” Tor, I2P, Telegram channels, paste sites, dark marketplaces, and hacker forums โ€” for credential breaches, leaked PII, brand threats, and adversary planning signals targeting your organization.

Over 88% of basic web application attacks use stolen credentials (Verizon 2025 DBIR). More than 24 billion username-password pairs currently circulate on criminal markets. The window between credential harvest and weaponization is your only chance to act. UMBRA closes that window.

Why UMBRA?

Problem with existing tools UMBRA's answer
Enterprise-only pricing ($50Kโ€“$100K+/yr) Self-serve plans from $99/month
Sales-gated, weeks to onboard Under 5 minutes to first alert
Raw data dumps, no context AI-generated summaries + remediation playbooks
Dated, slow dashboards Modern Next.js UI with real-time WebSocket feeds
No API-first approach REST API with full OpenAPI 3.0 spec
High false-positive alert noise XGBoost risk scoring + LLM triage reduces noise

Dashboard Preview

UMBRA Command Center โ€” Platform Overview showing real-time threat telemetry, risk scoring, watchlist, critical findings, AI insights powered by Claude

UMBRA Command Center โ€” Real-time threat telemetry, AI-powered risk scoring, and live breach activity feed. Organization risk score, active watchlist, critical findings, and Claude-generated AI insights โ€” all in one view.

Note

All company names, domains, and organizations shown in the screenshot (e.g. "acme.com", "project titan") are fictional and used for demonstration purposes only. Any resemblance to real companies is purely coincidental.


Key Features

  • ๐Ÿ•ต๏ธ Dark Web Monitoring โ€” Tor, I2P, Telegram, Discord, paste sites, ransomware leak sites
  • ๐Ÿ” Credential Breach Detection โ€” sub-60-minute detection from harvest to alert
  • ๐Ÿค– AI Threat Intelligence โ€” Claude-powered summaries, risk scoring, MITRE ATT&CK mapping
  • ๐Ÿ“Š Real-Time Dashboard โ€” Live alert feed, threat metrics, watchlist management
  • ๐Ÿ”” Multi-Channel Alerts โ€” Email, Slack, Teams, webhooks, PagerDuty, Jira
  • ๐Ÿ—„๏ธ Watchlist Management โ€” Monitor domains, email ranges, brand keywords, IP ranges
  • ๐Ÿ“ˆ Executive Reports โ€” PDF/CSV exports, weekly digests, compliance-ready audit logs
  • ๐Ÿ”‘ API-First โ€” Full REST API + SDK for programmatic integration in CI/CD pipelines
  • ๐Ÿข Multi-Tenant (MSSP) โ€” Manage multiple client organizations from one dashboard
  • ๐Ÿ›ก๏ธ Privacy by Design โ€” Credentials hashed/anonymized; plaintext PII is never stored

Architecture Overview

UMBRA is a pnpm monorepo with a domain-driven microservices backend and a Next.js frontend. The current repository contains the web dashboard and REST API; the full microservices platform is designed to run on Kubernetes (EKS).

umbra-platform/
โ”œโ”€โ”€ apps/
โ”‚   โ”œโ”€โ”€ api/          โ† Express + TypeScript REST API (Node.js 22)
โ”‚   โ””โ”€โ”€ web/          โ† Next.js 16 dashboard (React 19, TailwindCSS 4)
โ”œโ”€โ”€ docs/             โ† Architecture, PRD, API contracts, roadmap
โ”œโ”€โ”€ docker-compose.ymlโ† Local dev: PostgreSQL + Redis
โ””โ”€โ”€ package.json      โ† pnpm workspace root

Data Pipeline

Dark Web Sources          Intelligence Pipeline         Delivery
โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€         โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€         โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
Tor .onion sites  โ”€โ”€โ–ถ     Content Classifier      โ”€โ”€โ–ถ   Email
Telegram channels โ”€โ”€โ–ถ     Credential Extractor    โ”€โ”€โ–ถ   Slack / Teams
Paste sites       โ”€โ”€โ–ถ     MinHash Deduplication   โ”€โ”€โ–ถ   Webhook
Ransomware leaks  โ”€โ”€โ–ถ     Risk Scorer (XGBoost)   โ”€โ”€โ–ถ   PagerDuty
I2P / ZeroNet     โ”€โ”€โ–ถ     LLM Enrichment (Claude) โ”€โ”€โ–ถ   Dashboard UI
Hacker forums     โ”€โ”€โ–ถ     MITRE ATT&CK Mapper     โ”€โ”€โ–ถ   REST API

Tech Stack

Frontend (apps/web)

Layer Technology
Framework Next.js 16 with App Router + Turbopack
UI React 19 with Concurrent Rendering
Styling TailwindCSS 4 with custom design tokens
Components Radix UI primitives
Animations Motion + GSAP + Lenis smooth scroll
State Zustand
Data Fetching TanStack Query
Charts Recharts
Forms React Hook Form + Zod validation

Backend (apps/api)

Layer Technology
Runtime Node.js 22 LTS
Framework Express + TypeScript
Database PostgreSQL 16 via Prisma ORM
Cache / Pub-Sub Redis 7 (ioredis)
Job Queues Bull (background job processing)
Auth JWT (access + refresh tokens)
AI Integration Google Gemini API
Breach Lookup HaveIBeenPwned API
Email Nodemailer (SMTP/SendGrid)

Infrastructure (Production)

Concern Technology
Cloud AWS (us-east-1 primary, eu-west-1 GDPR)
Orchestration Kubernetes 1.30 (EKS)
Service Mesh Istio (mTLS)
IaC Terraform + Helm
CI/CD GitHub Actions โ†’ ECR โ†’ EKS
Edge / WAF Cloudflare
Secrets HashiCorp Vault
Observability Prometheus + Grafana + OpenTelemetry + Jaeger

Getting Started

Prerequisites

1. Clone the repository

git clone https://github.com/SnehalPrince/UMBRA-Intelligence-platform.git
cd UMBRA-Intelligence-platform

2. Install dependencies

pnpm install

3. Start local infrastructure

# Starts PostgreSQL (port 5432) and Redis (port 6379)
docker-compose up -d

4. Configure environment

# API environment
cp apps/api/.env.example apps/api/.env

Edit apps/api/.env with your values:

DATABASE_URL="postgresql://umbra:umbra@localhost:5432/umbra_db"
REDIS_URL="redis://localhost:6379"
JWT_SECRET="your-super-secret-jwt-key"
JWT_REFRESH_SECRET="your-refresh-secret"
GEMINI_API_KEY="your-gemini-api-key"
HIBP_API_KEY="your-hibp-api-key"
SMTP_HOST="smtp.sendgrid.net"
SMTP_USER="apikey"
SMTP_PASS="your-sendgrid-api-key"

5. Run database migrations

pnpm db:migrate

6. Start the development servers

# Start both API and Web concurrently
pnpm dev

# Or individually:
pnpm --filter api dev      # API on http://localhost:4000
pnpm --filter web dev      # Web on http://localhost:3000

Project Structure

API (apps/api/src)

src/
โ”œโ”€โ”€ index.ts                  โ† Server entry point
โ”œโ”€โ”€ app.ts                    โ† Express app setup (CORS, helmet, morgan)
โ”œโ”€โ”€ controllers/
โ”‚   โ”œโ”€โ”€ auth.controller.ts    โ† Register, login, logout, token refresh
โ”‚   โ”œโ”€โ”€ dashboard.controller.ts โ† Threat metrics and summary stats
โ”‚   โ”œโ”€โ”€ findings.controller.ts  โ† CRUD for threat findings
โ”‚   โ””โ”€โ”€ watchlist.controller.ts โ† Target watchlist management
โ”œโ”€โ”€ routes/
โ”‚   โ”œโ”€โ”€ auth.routes.ts        โ† POST /api/auth/*
โ”‚   โ”œโ”€โ”€ dashboard.routes.ts   โ† GET  /api/dashboard/*
โ”‚   โ”œโ”€โ”€ findings.routes.ts    โ† GET/POST/PATCH /api/findings/*
โ”‚   โ””โ”€โ”€ watchlist.routes.ts   โ† GET/POST/DELETE /api/watchlist/*
โ”œโ”€โ”€ services/
โ”‚   โ”œโ”€โ”€ ai.service.ts         โ† Gemini AI threat analysis
โ”‚   โ”œโ”€โ”€ email.service.ts      โ† Alert email delivery
โ”‚   โ””โ”€โ”€ hibp.service.ts       โ† HaveIBeenPwned breach lookup
โ”œโ”€โ”€ middlewares/
โ”‚   โ”œโ”€โ”€ auth.ts               โ† JWT bearer token verification
โ”‚   โ””โ”€โ”€ error.ts              โ† Centralized error handler
โ””โ”€โ”€ lib/
    โ”œโ”€โ”€ prisma.ts             โ† Singleton Prisma client
    โ”œโ”€โ”€ redis.ts              โ† ioredis client
    โ”œโ”€โ”€ jwt.ts                โ† JWT sign/verify helpers
    โ””โ”€โ”€ queue.ts              โ† Bull background job queue

Web (apps/web/src)

src/
โ”œโ”€โ”€ app/
โ”‚   โ”œโ”€โ”€ layout.tsx             โ† Root layout, fonts, metadata
โ”‚   โ”œโ”€โ”€ page.tsx               โ† Landing / splash page
โ”‚   โ”œโ”€โ”€ globals.css            โ† UMBRA dark theme + CSS variables
โ”‚   โ”œโ”€โ”€ (auth)/
โ”‚   โ”‚   โ”œโ”€โ”€ layout.tsx         โ† Centered auth layout
โ”‚   โ”‚   โ”œโ”€โ”€ login/page.tsx     โ† Login form with JWT flow
โ”‚   โ”‚   โ””โ”€โ”€ register/page.tsx  โ† Registration with validation
โ”‚   โ””โ”€โ”€ (dashboard)/
โ”‚       โ”œโ”€โ”€ layout.tsx         โ† Sidebar navigation
โ”‚       โ”œโ”€โ”€ dashboard/page.tsx โ† Threat intelligence overview
โ”‚       โ”œโ”€โ”€ search/page.tsx    โ† Dark web search interface
โ”‚       โ”œโ”€โ”€ watchlist/page.tsx โ† Monitored target management
โ”‚       โ”œโ”€โ”€ alerts/page.tsx    โ† Security alerts feed
โ”‚       โ”œโ”€โ”€ reports/page.tsx   โ† Threat analytics & exports
โ”‚       โ””โ”€โ”€ settings/page.tsx  โ† Account & org settings
โ”œโ”€โ”€ components/
โ”‚   โ””โ”€โ”€ ui/
โ”‚       โ”œโ”€โ”€ button.tsx         โ† Variant-based Button (CVA)
โ”‚       โ””โ”€โ”€ input.tsx          โ† Styled Input with ref forwarding
โ”œโ”€โ”€ providers/
โ”‚   โ”œโ”€โ”€ QueryProvider.tsx      โ† TanStack React Query setup
โ”‚   โ””โ”€โ”€ SmoothScrollProvider.tsx โ† Lenis smooth scroll
โ””โ”€โ”€ lib/
    โ””โ”€โ”€ utils.ts               โ† cn() class merging utility

API Reference

Base URL: http://localhost:4000/api

Authentication

Method Endpoint Description
POST /auth/register Register a new organization & user
POST /auth/login Authenticate and receive JWT tokens
POST /auth/logout Invalidate refresh token
POST /auth/refresh Rotate access token using refresh token

Dashboard

Method Endpoint Description
GET /dashboard/stats Threat metrics and KPI summary
GET /dashboard/recent-alerts Most recent alert events

Findings

Method Endpoint Description
GET /findings List all threat findings (paginated)
GET /findings/:id Get a single finding with AI enrichment
PATCH /findings/:id/status Update finding status (resolved / FP)

Watchlist

Method Endpoint Description
GET /watchlist List monitored assets
POST /watchlist Add a domain, email range, or keyword
DELETE /watchlist/:id Remove a monitored asset

Full OpenAPI 3.0 specification: docs/API.md


Database Schema

Core entities managed by Prisma + PostgreSQL:

User โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ Organization
 โ”‚                              โ”‚
 โ”œโ”€โ”€ Sessions                   โ”œโ”€โ”€ WatchlistItems (domains, emails, keywords)
 โ”‚                              โ”‚
 โ””โ”€โ”€ (via org)                  โ”œโ”€โ”€ Findings (threat events)
                                โ”‚     โ””โ”€โ”€ AI Enrichment (summary, severity, remediation)
                                โ”‚
                                โ””โ”€โ”€ Alerts (delivery log)

Full schema: apps/api/prisma/schema.prisma ยท Database design: docs/Database.md


Documentation

Document Description
docs/PRD.md Product Requirements Document โ€” vision, personas, features, pricing
docs/Architecture.md Full system architecture with diagrams
docs/TechStack.md Technology choices and rationale
docs/API.md API endpoint contracts and request/response schemas
docs/Database.md Database schema design and ERD
docs/Design.md UI/UX design system and component library
docs/Roadmap.md Product roadmap across 4 phases
docs/Requirements.md Functional and non-functional requirements
docs/Implementation.md Implementation plan and developer guide
docs/Contracts.md Service contracts and inter-service API specs
docs/Progress.md Build progress tracker
docs/ProjectStructure.md Monorepo directory map
docs/Mobile-Responsiveness.md Mobile UX strategy

Roadmap

โœ… Phase 1 โ€” Foundation (Current)

  • Monorepo scaffold (pnpm workspaces)
  • Express REST API with auth, findings, watchlist, dashboard
  • Prisma schema with all core entities
  • Next.js dashboard with auth flows and all page routes
  • Real-time WebSocket alert infrastructure
  • AI service integration (Gemini)
  • HIBP breach lookup service
  • Redis cache + Bull job queues

๐Ÿ”„ Phase 2 โ€” Intelligence Layer (Months 4โ€“6)

  • AI threat summarization (Claude enrichment per finding)
  • Dark forum & paste site monitoring
  • Ransomware leak site monitoring (200+ sites)
  • SIEM integrations (Splunk, Microsoft Sentinel)
  • Multi-tenant MSSP workspace support
  • Python + Node.js SDKs
  • Stripe billing integration

๐Ÿ”ฎ Phase 3 โ€” Visualization & Depth (Months 7โ€“9)

  • 3D Threat Intelligence Graph (Three.js / R3F)
  • Threat actor profiling and MITRE ATT&CK mapping
  • Initial Access Broker (IAB) monitoring
  • Automated remediation workflows (Okta, Azure AD)
  • Brand protection & lookalike domain detection
  • SOC 2 Type II certification

๐Ÿš€ Phase 4 โ€” Enterprise & Scale (Months 10โ€“12)

  • Executive / VIP monitoring module
  • Mobile app (React Native + Expo)
  • White-label solution for MSSPs
  • Custom threat intelligence report generation
  • Integration marketplace ecosystem

Security & Privacy

UMBRA is built with privacy by design:

  • โœ… No plaintext credentials ever stored โ€” emails are SHA-256 hashed; passwords are partially masked
  • โœ… Zero Trust networking โ€” mTLS between all microservices via Istio service mesh
  • โœ… Encryption everywhere โ€” AES-256 at rest, TLS 1.3 in transit
  • โœ… Secrets in Vault โ€” HashiCorp Vault; no secrets in environment variables in production
  • โœ… GDPR-compliant โ€” EU data residency in eu-west-1; data minimization enforced
  • โœ… Immutable audit logs โ€” S3 WORM bucket with 7-year retention
  • โœ… Passive monitoring only โ€” UMBRA performs defensive intelligence only; no offensive operations

Full security architecture: docs/Architecture.md#10-security-architecture


Pricing

Plan Price For
Scout Free Individuals, researchers โ€” 1 domain, manual lookups
Operator $99/mo Startups, SMBs โ€” 3 domains, API access, Slack alerts
Sentinel $299/mo Growing teams โ€” 10 domains, SIEM integration
Guardian $599/mo Security teams โ€” 25 domains, remediation workflows
Enterprise $999+/mo Large orgs, MSSPs โ€” unlimited, white-label, SLA

Contributing

  1. Fork the repository
  2. Create a feature branch: git checkout -b feat/your-feature
  3. Commit with conventional commits: git commit -m "feat(api): add threat scoring endpoint"
  4. Push and open a Pull Request

Please read docs/Implementation.md for coding conventions and contribution guidelines.


License

MIT License โ€” see LICENSE for details.


Built with ๐Ÿ–ค by SnehalPrince

UMBRA Intelligence โ€” Defensive dark web monitoring. All data used solely for organizational protection.

About

๐Ÿ•ต๏ธ AI-native dark web & cyber threat intelligence platform. Monitors Tor, Telegram, paste sites & breach databases. Sub-60min credential alerts, LLM-powered threat analysis, real-time dashboard.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages