TIBlender: Early-Warning Threat Intelligence from Cross-Platform Social Media Evidence
For cybersecurity analysts, TIBlender provides an automated early-warning system that surfaces unique threat information from multiple social media platforms, reducing reliance on single-platform feeds.
TIBlender is a multi-agent system that integrates threat signals from X, Reddit, Telegram, and Discord into structured threat intelligence reports. In real-world deployment, it detected emerging threats across all four categories ahead of public feeds, with the majority of its Indicators of Compromise (IoCs) absent from each evaluated feed.
Cyber threat signals are fragmented across multiple social media platforms, yet no existing approach has fully automated their integration into actionable threat intelligence (TI) reports. We present TIBlender, a multi-agent system that monitors four platforms (X, Reddit, Telegram, and Discord) and produces structured TI reports via role-specialized LLM agents. These agents conduct multi-perspective investigations, tracing chains of evidence to uncover related Indicators of Compromise (IoCs) via collaborative, evidence-backed analysis. In a real-world deployment, TIBlender detected emerging threats across all four threat categories ahead of public feeds, including in-the-wild exploitation ahead of public vulnerability registries; the majority of its IoCs were absent from each evaluated feed. Quantitative evaluation confirms that each platform contributes unique threat information unavailable from the others, and that excluding any single platform results in substantial loss of reports in specific threat categories. Under identical single-platform input conditions, TIBlender's IoC extraction meets or exceeds each baseline; the full pipeline surfaces substantially more IoCs, most of which are absent from any single-platform baseline. These results establish cross-platform social media monitoring as an effective and scalable early-warning layer for operational TI pipelines.