AADITHYA VIMAL

Security · 2026 · Live demo · Open source · 2026

ThreatStream

A frontend-only live cyber threat intelligence monitor visualizing real-world malicious IP indicators across 7 switchable globe views with zero fabricated attack paths.

My role
Designed and built the browser-based multi-feed ingestion pipeline, diff-driven state engine, and Globe.GL 3D operations visualization.
Status
Live demo · Open source · 2026
Category
Security · Live cyber threat intelligence monitor
Live demoSource on GitHub

Live demo · interactive

🔒threatstream.pages.dev
CONNECTING TO THREATSTREAM...

Embedded for convenience — if it doesn’t load here, open the full site directly.

01

Understand

Why it exists. Conventional cyber attack maps fabricate sensational flight paths between random coordinates. ThreatStream visualizes verified observations from authoritative public feeds with complete attribution.

What I built. Frontend-only cyber threat intelligence monitor that ingests, normalizes, and renders live public security feeds directly in the browser across 7 switchable globe views (Operations, Threat Heatmap, Verified Flows, Threat Rings, Hex Density, Satellite, Minimal).

The problem it solves. Cyber threat intelligence feeds are scattered across disparate raw text files and blocklists, frequently presented through simulated attack maps with fabricated flight paths rather than verified telemetry.

What it does

  • Real-time client-side polling of Spamhaus DROP, SANS DShield, ET Block, ISC Attack Sources, OpenPhish, and CISA KEV
  • Globe.GL 3D operations viewport with 7 switchable views (Operations, Threat Heatmap, Verified Flows, Threat Rings, Hex Density, Satellite, Minimal)
  • Diff-driven state transitions with smooth enter/fade/pulse lifecycles and stable provider IDs
  • Honesty architecture: reports 0 verified paths instead of drawing speculative attack lines
02

Technical depth

Architecture. Direct in-browser polling of 5 authoritative public sources on staggered schedules (Spamhaus DROP, SANS DShield, Emerging Threats ET Block, SANS ISC Attack Sources, OpenPhish, and CISA KEV). Feeds normalize into immutable ThreatEvents with stable provider IDs, diff-driven enter/exit visual lifecycles, and in-browser keyless GeoIP/ASN enrichment.

Security model. Strict honesty architecture: zero fabricated paths — arcs render only when both endpoints are genuinely supplied by feeds (reporting 0 verified paths instead of inventing connections). Operates 100% client-side with zero telemetry and zero third-party API secret exposure.

Tradeoff. Strict adherence to verified endpoint telemetry means arcs render only when both source and destination are explicitly confirmed by feeds.

  • JavaScript
  • React
  • Globe.GL
  • Three.js
  • GeoIP
  • Vite
  • Cloudflare Pages
How it works, step by step

Direct in-browser polling of 5 authoritative public sources on staggered schedules (Spamhaus DROP, SANS DShield, Emerging Threats ET Block, SANS ISC Attack Sources, OpenPhish, and CISA KEV). Feeds normalize into immutable ThreatEvents with stable provider IDs, diff-driven enter/exit visual lifecycles, and in-browser keyless GeoIP/ASN enrichment.

Security notes

Strict honesty architecture: zero fabricated paths — arcs render only when both endpoints are genuinely supplied by feeds (reporting 0 verified paths instead of inventing connections). Operates 100% client-side with zero telemetry and zero third-party API secret exposure.

Security