How AI Threat Forecasts Work
Our automated system collects threat intelligence from multiple sources, analyzes patterns with AI, and generates actionable briefings every 6 hours - around the clock.
The Analysis Process
Data Collection
Every 6 hours, our system aggregates threat data from the previous period across all sources. We collect statistics including:
- Total threats and unique IP addresses
- Attack category breakdown (malware, brute force, spam, etc.)
- Geographic distribution (top 10 countries)
- Nordic-specific intelligence (NO, SE, DK, FI, IS)
- Comparison with previous period (trend analysis)
Context Enrichment
The raw statistics are enriched with additional context:
- ISP and ASN information for top attackers
- Datacenter vs residential IP classification
- Tor exit node detection
- Relevant security advisories (from CERT-EU when applicable)
AI Analysis
The enriched data is sent to Google's Gemini 2.0 Flash model with a carefully crafted prompt. The AI is instructed to:
- Summarize the threat landscape (60-80 words)
- Highlight significant changes from previous period
- Identify notable patterns (e.g., datacenter vs residential attacks)
- Provide tactical recommendations (40-60 words)
- Use percentages and relative comparisons, not raw numbers
Publication
The generated briefing is stored with full metadata and made available through:
- HTML pages with rich formatting and visualizations
- JSON API for programmatic access
- RSS and Atom feeds for subscription
- JSON Feed for modern feed readers
Data Sources
Our forecasts are powered by multiple threat intelligence sources, each contributing unique insights:
AbuseIPDB
Community-reported IP abuse data from network administrators worldwide. Updated every 3 minutes.
Spamhaus DROP
Expert-curated list of professional cybercrime networks. 14.7M IPs with less than 1% false positive rate.
abuse.ch
Malware URL intelligence including URLhaus, ThreatFox, and Feodo tracker data.
fail2ban Network
Real-time intrusion detection from our reporter network. Live SSH, FTP, and web attack data.
AI Model Details
Frequently Asked Questions
How accurate are the AI forecasts?
The forecasts are based on real threat data from our database of 190M+ reports. The AI synthesizes this data into readable briefings. While the underlying statistics are precise, the AI's interpretations are probabilistic. We recommend using forecasts as one input among many in your security decision-making process.
Why every 6 hours?
Six-hour intervals provide a balance between timeliness and meaningful pattern detection. Shorter periods may not capture enough data for significant trends, while longer periods would miss emerging threats. This schedule also aligns well with SOC shift handoffs.
Can I access the raw data?
Yes! Every forecast page includes links to the underlying statistics. The API provides both the briefing text and the full context data used for generation. Premium API tiers offer even deeper access to historical data.
Why focus on Nordic countries?
WAYSCloud is a Norwegian company, and our initial user base is primarily Nordic. We provide dedicated Nordic intelligence (NO, SE, DK, FI, IS) while maintaining global coverage. This focus helps regional security teams identify threats specifically targeting their geography.
How do you ensure AI doesn't hallucinate?
We constrain the AI to only discuss data points explicitly provided in the context. The prompt instructs it to use percentages and relative comparisons from the actual statistics. We also store the full context sent to the AI alongside each briefing for transparency and verification.
Ready to Explore?
Check out the latest forecast or browse our complete archive of threat briefings.