CLASSIFIED
Case File // 2026-Q2-0847

Threat Intelligence,
Declassified.

An enterprise-grade monitoring and alerting platform for security operations centers, intelligence analysts, and threat researchers operating in hostile information environments.

Platform
umbrawatch-cli // v1.0.0
$ umbrawatch status
Platform initialization complete.
Threat feeds connected: 20/20
Keyword monitors active: 15
Pending alerts: 18 (2 critical)
System health: OPTIMAL
---
$ umbrawatch feeds scan --recent
[INFO] Scanning 20 sources...
[OK] API: CISA KEV (12 new entries)
[OK] RSS: DarkReading (3 new articles)
[OK] Onion: Tor Feed 07 (1 match)
[ALERT] Keyword match: "zero-day" in Feed #14
$ _
20
Threat Feeds
15
Keywords
18
Alerts
11
Tags

Platform Capabilities

Comprehensive tooling for intelligence gathering, analysis, and response coordination.

UW-CMD-01
📊

Command Dashboard

Real-time command center with statistics tiles, criticality distribution charts, 7-day trend analysis, and a live recent alerts feed with 30-second refresh.

Operational Recharts Auto-refresh
UW-FED-02
🌐

Multi-Source Feed Management

Aggregate intelligence from API endpoints, RSS feeds, website scraping, and dark web .onion sources via Tor proxy. 20 default feeds with full CRUD.

Operational API / RSS / Web / Onion 20 Feeds
UW-KWD-03
🔍

Keyword Matching & Alerts

Simple text or regex pattern matching with case sensitivity controls. Four criticality levels with automatic alert generation on match.

Operational Regex Support 4 Levels
UW-ALR-04
🚨

Alert Triage System

Advanced alert viewer with bulk operations, 6 filter types, read/unread tracking, content detail dialog with raw JSON viewer, and keyword highlighting.

Operational Bulk Ops Deduplication
UW-TAG-05
🏷

Tag Organization

Many-to-many tag relationships across feeds, keywords, and alerts. Custom color picker with 16 presets, usage counts, and detailed association views.

Operational Color Coded Many-to-Many
UW-TPL-06
📄

API Template System

JSONPath-based field extraction from JSON API endpoints. Support for pagination, nested responses, API key authentication, and a built-in testing interface.

Operational JSONPath Live Testing
UW-NTF-07
🔔

Multi-Channel Notifications

Configure Email (SMTP), generic Webhooks, and Discord webhooks. Per-channel criticality filtering, test notifications, and enable/disable controls.

Operational Email / Webhook / Discord Test Mode
UW-HLT-08
📡

Feed Health Monitoring

Comprehensive health dashboard with consecutive failure tracking, error message display, CSV export, and 4-state status indicators.

Operational Health Tracking CSV Export
UW-SET-09

Settings & Maintenance

Alert cleanup with retention preview, safety confirmation, system information display, general configuration with fetch intervals, timezone, and auto-cleanup.

Operational Retention Policy System Info