Extending the Processing Capabilities of Threat Intelligence Platforms DUIRI - Discovery Undergraduate Interdisciplinary Research Internship Fall 2026 Accepted software engineering, cyber threat intelligence Threat intelligence platforms (TIPs) are important software tools used in cyber threat intelligence (CTI). We are extending one open source TIP, OpenCTI. OpenCTI provides an extensible framework for adding processing capabilities. This project will develop a new processing module ("connector" in OpenCTI parlance) that takes images and performs optical character recognition (OCR) to extract text. Image-to-text examples could include advertisements, memes, and captions. Courtney Allen Falk The student researcher will identify open-source, local large language model (LLM) candidates for integration. The researcher will also evaluate model performance to verify a 90%+ accuracy rate of the model. They will develop the code for running the local LLM to extract textual data from images (GIFs, JPEGs, PNGs, etc.). This image processing software will then get integrated into a running OpenCTI instance. See the Qualifications section for specific technologies involved. The final product will be made publicly available for users of the OpenCTI platform. The student must have experience developing Python code, using the Git version control system, and deploying solutions in a Docker environment. The student must also have experience with using AI models and evaluating their output for accuracy, precision, and recall. A well-qualified candidate will have experience developing for a microservices architecture. Experience with CTI is desirable but not required. Experience using any TIP (please specify) especially OpenCTI is highly desirable but not required. 0 10 (estimated)

This project is not currently accepting applications.