DOI: 10.3390/info17080794 ISSN: 2078-2489

Time-Series and Social-Media Threat Analytics over a Deployed Cyber-Threat Knowledge Graph

Kalin Kopanov, Kristina Dineva, Ivaylo Keremidarski, Velizar Varbanov, Vitalii Toderian, Petrica Butusina, Andrei Ionut Damian

Security teams decide which vulnerabilities to patch first, which alerts to trust, and whether social media warns of new threats earlier than the official feeds. We answer these questions by directly measuring EdgeGuard, a deployed cyber-threat knowledge graph that merges eleven public threat feeds into one Neo4j database via MISP (an open threat-sharing platform) and the STIX 2.1 exchange format, recording for every entry which feed reported it and when. These records let the graph be read as a time series. Read this way, it shows that half of the vulnerabilities known to have been exploited were listed as exploited within five days of their publication (352 cases), and that a large ingestion spike in early 2026 came from a single feed rather than a real attack wave. Benchmarked against 10,000 threat-related social-media posts, the graph already held 96% of the actionable vulnerabilities the posts discussed and reported them at least as quickly, while most posts carried no actionable signal and social media led only in early warning of active exploitation. A crowd-sourced community layer additionally supplies the only intelligence tagged by industry sector. The deployed graph is thus a clean, timely, and comprehensive base, and live social ingestion a small, targeted enhancement.

More from our Archive