Schriever Cyber Threat Intelligence Software
The government seeks a new secure, high-fidelity network flow analytics platform with 24/7/365 web-based availability and API endpoints for integrating intelligence feeds into local security tools, SIEM systems, or data orchestrators. Required capabilities include querying a massive global NetFlow database by IP, port, protocol, packet counts, and timestamps, plus tracking malicious C2 servers, mapping botnets, analyzing hostile infrastructure, and performing forensic attribution. The platform must also provide integrated historical passive DNS and IP reputation data for context resolution and encrypted traffic profiling to detect anomalous patterns and threat actors using VPNs or encrypted tunneling. Operations and maintenance support includes ongoing software updates, database maintenance, search engine optimization, and feature additions at no extra cost during performance periods, along with helpdesk and administrator support for troubleshooting, configuration, and optimization. This is a Sources Sought notice for market research only, and no quotes will be evaluated at this time.