## Taranis AI Strategy
taranis-ai/taranis-ai
taranis.ai
Note: - Strategy context compiled from public Taranis AI documentation and repositories. --- ## PERSONS - Who are we?
- **Me** - Benjamin Akhras - **AI Team** - Lukas Linauer, Dzenan Hamzic, Elisabeth Woisetschläger - **Core Developers** - Stefania Sava, Armin Schreger, Peter Leitmann - **Chief Collaboration Officer** - Peter Leitmann - **Strategy & Support** - Florian Skopik & Petra Kölndorfer
Note: - Team description from https://taranis.ai/team/ - Service overview from https://github.com/taranis-ai/taranis-ai (README) - Target users highlighted in docs: https://taranis.ai/docs/ ---
## TOPIC - What do we stand for? - **Mission:** open-source automation that amplifies analysts' ability to collect, assess, and publish OSINT. - **Scope:** ingest websites, social, dark web, and public datasets; enrich items with NLP; package as actionable intelligence. - **Why it matters:** delivers faster situational awareness for defenders facing expanding threat surfaces.
Note: - Ingestion scope and NLP usage from GitHub README. - Mission aligns with documentation focus on Assess -> Analyze -> Publish. ----
## TOPIC - Challenges & Motivation - Scaling ingestion, deduplication, and story clustering across heterogeneous feeds. - Maintaining trust via relevance, reliability, timeliness, and impact checks inside Assess. - Bridging automation with analyst oversight to produce publish-ready intelligence products.
Note: - Challenge articulation derived from documentation guidance on Assess and Analyze. - Human-in-the-loop emphasis. ---- ## Taranis AI
--- ## RESULTS - What do we work on? - Production-ready OSINT stack: REST interface, Celery workers. - Deployable reference architectures covering Docker Compose, Kubernetes, TLS, and observability (Sentry) setups. - Comprehensive API surface with OpenAPI 3.1 spec, dev setup guides, and contributor onboarding. - Intelligence workflow assets: AI summarisation, entity recognition, story clustering, and report templating. Note: - Services, features, and OpenAPI references from repository README. - Deployment and observability coverage from documentation (Deployment, Advanced monitoring). ---- ## RESULTS - Artifacts & IPRs - Released under the European Union Public Licence (EUPL) to ensure openness and portability. - Connector catalogue covers web, RSS, email and experimental MISP story-level sharing for collaboration. - Providing a platform for gathering OSINT from diverse sources, for further research topics. - Bots catalogue covers AI summarisation, entity extraction, clustering, cyber security classification, sentiment analysis. - Providing a platform for developing and integrating new AI/ML capabilities. Note: - Licensing, connectors and bots --- ## IMPACT - What are we proud of? - Analysts close news-to-report loops quicker via AI summarisation, entity-aware clustering, and automation. - Story-level sharing through MISP strengthens cross-organisational collaboration among CSIRTs. - Distributed microservice architecture scales ingest, processing, and publishing independently, improving reliability, performance, and deployability. - STIX-compatible data exchange enables integration with external tools and platforms for bi-directional intelligence sharing. Note: - Impact statements anchored in README features, MISP integration, and EU funding disclosures. --- ## PARTNERS & COLLABORATIONS
- **AIT** Digital Safety & Security programmes host the core team and roadmap governance. - **European Union CEF** co-funds capability growth and operational deployments. - **MISP Project** integration enables federated sharing between threat intelligence communities.
- **Community roots:** inspired by NCSC-NL's Taranis3 and SK-CERT's Taranis-NG predecessors. - **Open-source ecosystem:** GitHub, Hugging Face, Pypi - **Research:** Log Analysis, Cyber Situational Awareness, NLP for Cybersecurity
Note: - Partner ecosystem references from README acknowledgements and funding notes. ----
## PARTNERS & COLLABORATIONS
Note: - Partner ecosystem references from README acknowledgements and funding notes. --- ## FUTURE - Where are we heading? - Productise AI-assisted report templating, entity linking, and assistant workflows already on the roadmap. - Expand multilingual NLP coverage so EU-wide analyst communities share a common intelligence fabric. - Deepen automated trust signals (source scoring, anomaly detection) while keeping humans in the loop. - Partner with adjacent AIT teams (data science, attack & defend, cyber range) for cross-domain insights. Note: - Future features align with ongoing roadmap items described in internal presentations. ---- ## FUTURE - Moonshot - LLM based AI Assistants that understand analyst workflows and context, providing real-time support. - Link OSINT with internal CTI and analyst feedback to build a living knowledge graph of threats. Note: - Moonshot ideas focus on high-leverage collaboration and innovation opportunities across teams. --- ## TL;DR - Recent success to remember - Deployment in Portalverbund at BRZ for new GovCERT. - Direct funding from BMI and via ECCC for continuous enhancements. - Multiple EU Projects (EUCINF, ECYSAP eye, Newsroom, ...) - Validated interoperable sharing through experimental MISP story exchange between Taranis instances. Note: - Success story grounded in published presentation and README highlights.