FinSight CTI: A Mini Threat Intelligence Platform for African Fintech
# FinSight-CTI-Threat-Intelligence
FinSight CTI: A Mini Threat Intelligence Platform for African Fintech
# FinSight CTI
> A threat intelligence program tracking adversary activity
> against African fintech and financial services.
## 🎯 Mission
This project simulates the work of a Cyber Threat Intelligence (CTI)
analyst at a fictional Nigerian fintech, "PayNaija." The goal is to
identify, track, and report on threats relevant to financial sector
organizations in emerging markets.
## 📊 What's Inside
- **Threat Actor Profiles** — In-depth dossiers on ransomware groups
(LockBit, Cl0p) and stealer malware families (RedLine, Lumma) with
MITRE ATT&CK mappings and Diamond Model breakdowns
- **IOC Repository** — Structured, deduplicated indicators of compromise
sourced from public threat feeds (abuse.ch, AlienVault OTX, CISA KEV)
- **Weekly Threat Briefings** — Executive-style intelligence reports
covering threats observed in the past 7 days
- **OSINT Playbook** — Documented procedures for monitoring open
sources, including Shodan, certificate transparency, leak-site
monitoring (via reporting), and brand impersonation detection
- **MITRE ATT&CK Mapping** — Adversary TTPs mapped to the framework
with a focus on initial access, credential access, and impact tactics
## 🛠️ Frameworks & Tools
- MITRE ATT&CK
- Diamond Model of Intrusion Analysis
- Pyramid of Pain
- Traffic Light Protocol (TLP) for intel sharing
- Free OSINT tools: VirusTotal, urlscan.io, Shodan, abuse.ch,
AlienVault OTX, crt.sh
## 📁 Repository Structure