Bounce-CTI
An autonomous CTI investigation agent. You give it one observable (a domain, an IP, a hash, a JARM fingerprint, even the bare filename of a malicious binary). A headless Claude Code agent then pivots across public sources, using MCP tools only: no shell, no filesystem. The infrastructure graph streams live to the browser.
CDN ranges, parking nameservers and sinkholes are defused before the agent can pivot on them. Anything the model proposes from its own knowledge becomes a lead: its confidence is capped at 0.35, it is kept out of STIX, blocklists and detection rules, and it is promoted only once a primary source corroborates it. OSINT and due-diligence modes (registries, sanctions screening) sit on the same engine.
- 12 casesdrawn from public vendor write-ups and scored on two tracks: capability (pivot choice, budget, defusing, hypothesis) and recallEVAL_PROTOCOL v3
- 92.9mean capability score on the fresh subset, up 6.9 on the previous runrun of 2026-06-01
- 0 / 5cases failing the hallucination gate, where a single invented node or edge fails the runhard gate
- 3benign seeds (Cloudflare, jsDelivr, Wikipedia) that check the agent knows when to stoprestraint track