Skip to content

feat: Threat Intelligence Feed Framework#209

Merged
mijinummi merged 1 commit into
MD-Creative-Production:mainfrom
Leothosine:feat/threat-intelligence-feed-framework
Jul 21, 2026
Merged

feat: Threat Intelligence Feed Framework#209
mijinummi merged 1 commit into
MD-Creative-Production:mainfrom
Leothosine:feat/threat-intelligence-feed-framework

Conversation

@Leothosine

Copy link
Copy Markdown
Contributor

What

Implements the threat intelligence feed framework requested in #123, under src/modules/threat-intelligence/.

Why

Internal monitoring alone can miss known malicious actors already documented by external threat intel sources. This gives Sentinel a pluggable way to ingest and act on that data.

Implementation

  • Feed abstractionThreatIntelligenceFeed is an abstract base class; any upstream source (HTTP API, file drop, SDK, etc.) implements it by providing a name and a fetchIndicators() method. The ingestion pipeline only depends on this interface, not on any concrete feed.
  • Data ingestionThreatIntelligenceService.ingestFeed() fetches and stores indicators for a single feed, stamping each with an id, feed name, and fetch timestamp. ingestAll() runs ingestion across every registered feed in parallel and isolates per-feed failures (one feed throwing doesn't block the others). Ingestion results (success/failure, record count) are observable via onIngestion().
  • Feed schedulingschedule(feedName, { intervalMs, runImmediately }) runs recurring ingestion for a feed on an interval, with stopSchedule() / stopAllSchedules() / isScheduled() for lifecycle control.

Follows the same plain-class-plus-interfaces style already used by src/modules/detection/malicious-addresses.

Testing

16 new unit tests in threat-intelligence.service.spec.ts covering feed registration/removal, successful and failed ingestion (including isolation of per-feed failures), aggregate ingestion, subscriber notifications, and scheduling (interval firing, immediate run, stop/replace/stop-all, scheduling an unregistered feed).

Verified locally:

  • npm run lint — clean
  • npm run format:check — clean for these files
  • npm run build — passes
  • npx jest --config jest.backend.config.js src/modules/threat-intelligence — 16/16 passing

Acceptance Criteria

  • Framework implemented
  • Feed ingestion working
  • Scheduling supported

Closes #123

Introduces src/modules/threat-intelligence/ with a feed abstraction
(ThreatIntelligenceFeed), an ingestion pipeline that ingests one or
all registered feeds and isolates per-feed failures, and interval-based
scheduling for recurring ingestion.

Closes MD-Creative-Production#123
@mijinummi
mijinummi merged commit 26fccfd into MD-Creative-Production:main Jul 21, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Create Threat Intelligence Feed Framework

2 participants