saascode

Threatrecollect

A managed threat-memory workspace that extracts entities and indicators from analyst notes, reconciles aliases and serves a governed graph to approved analysis tools.

Genesis score6.08/10
Make Threatrecollect real.0/500
500 more votes and Threatrecollect is authorized for build.
0%500 to authorize
Backing is the vote. When an idea crosses 500, we pull it into the build pipeline and ship it for real — the votes decide what gets built next, not an editor.
The case

Lean threat-intelligence teams accumulate observations across notes, reports and cases, then repeatedly reconstruct which indicator, actor alias or technique appeared where. Threatrecollect proposes a managed memory layer that extracts structured candidates, links them to source passages and makes the resulting graph available to approved analyst tools. The supplied research confirms a mature open implementation substrate and a private-beta product, while finding no published compliance posture for the closest managed offering. That supports a deployment and governance wedge, not a claim that the category is empty.

The hard problem is epistemic control. A mention is not a validated indicator; an alias match is not proven identity; an extracted relationship is not an attribution. Source, collection time, handling marking, parser output, analyst assessment, confidence, review, dissemination and later correction must remain distinct. Compliance labels cannot be promised from architecture alone, and a managed service cannot inherit authorization to ingest every customer source.

The opportunity is strongest for small teams that want the usefulness of persistent agent memory but cannot safely operate and govern the stack themselves. The product earns trust through tenant isolation, provenance, retention, export, deletion, access review and auditable human decisions. It does not determine threat truth, replace intelligence analysis or confer regulatory compliance.

Who pays — and why

A threat-intelligence, detection-engineering or security-operations leader at a lean regulated team that needs governed shared memory without maintaining the underlying infrastructure.

What it unlocks
A source-linked threat graph that keeps raw observations, extracted candidates, analyst judgments and approved intelligence separate
Alias and relationship review queues with confidence, disagreement, supersession and handling markings visible before reuse
A managed operating envelope for isolation, retention, deletion, access review, export and audit evidence
How Genesis scored it
6.08across seven criteria
tension 7temporal 6blindspot 5buyer 8leverage 6convergence 5why-not 5
8
Buyer persona

Lean threat-intelligence and security-operations teams are identifiable users with a clear self-hosting and governance burden.

7
Productive tension

Persistent memory improves recall precisely while increasing the risk that an old or weak assertion is reused as current intelligence.

5
Why nobody did it

The product gap is clearer than the historical barrier, and mature open components lower entry costs for others.

Why it scored well

The input defines a specific regulated buyer, a concrete entity-and-alias memory mechanism and a credible managed-governance gap over a mature open substrate.

What's holding it back

Convergence is limited, the closest managed product is already in private beta, one cited capability remains unverified and operating a compliance-sensitive service adds customer-specific work.

Signals detected4 sources crossed
SignalSupplied repository research

SignalSupplied competitor research

SignalSupplied architecture research

SignalSupplied market scan

Direction briefthreatrecollect.md
threatrecollect.md
Want this pointed at your vertical?Point Genesis at your own market and constraints — it invents adjacent, fork-ready ideas, private to you before they hit the public feed.

Discussion

?

No comments yet — be the first to weigh in.