OpenAI 2026 hackathon

UTIX

From raw IOCs to actionable confidence — automated threat intel scoring.

Team of 2 · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #7,486 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

UTIX is a self-reported open-source project that aggregates Indicators of Compromise (IOCs) from multiple threat intelligence feeds into a PostgreSQL database with a web dashboard. The author describes it as a tool for security teams to understand why IOCs have certain scores and whether they are still relevant, using explainable scoring and automatic decay.

What changed

UTIX evolved from a basic data warehouse (v1) to a more advanced defense tool (v2) that includes an explainable scoring engine, self-cleaning exports, and log-matching capabilities. The v2 version implements multi-source confidence aggregation and MISP polynomial decay models.

The single most important open question

Is there any evidence of actual usage or adoption beyond the authors' own development work? There is no evidence of revenue, customers, or traction beyond the project's existence as a self-reported GitHub-style hackathon submission.

Back to contents

What The Product Actually Is

  • The description states that UTIX aggregates IOCs from multiple open threat intelligence feeds (ThreatFox, abuse.ch, VirusTotal) into a PostgreSQL database with a live web dashboard.
  • It includes two main versions:
    • v1: Data warehouse with modular connector architecture and a single-page HTML dashboard
    • v2: Adds explainable scoring, self-cleaning exports, and log-matching features
  • The backend is built using Python (Flask) and PostgreSQL
  • UTIX supports exporting blocklists in formats like Palo Alto EDL, Suricata, Snort, Sigma, STIX 2.1
  • It includes a provenance API that shows full scoring audit trails
  • Log-matching engine extracts observables from raw text and cross-references against the IOC database

Evidence Self-reported by authors; no independent verification or third-party confirmation.

Back to contents

Positioning & Claim Evolution

  • The description states that UTIX addresses two key problems faced by SOC analysts:
    • Black-box scoring in commercial platforms
    • Stale threat intelligence that is never cleaned up
  • It positions itself as a tool that answers "Why does this IOC have this score?" and "Is this IOC still relevant today?"
  • The authors claim to implement a mathematically grounded scoring model aligned with Intelligence Processing Architecture documents, including Sections 2.2–2.6 (multi-source confidence aggregation) and Section 3.2–3.6 (MISP polynomial decay)
  • UTIX is described as going beyond free TIPs by offering:
    • Explainable scoring with full provenance
    • Self-cleaning exports that automatically drop stale IOCs
    • Log matching to identify communication with malicious infrastructure

Evidence Self-reported claims; no external validation or performance data.

Back to contents

Target Customer & ICP

  • The description states that UTIX is designed for security teams, particularly SOC analysts who operate threat intelligence feeds.
  • It targets users who want to understand the source and relevance of IOCs rather than just ingest them blindly.
  • The authors note that it addresses "every security team" they've seen operating similarly — ingesting feeds, dumping into databases, blocking forever without cleanup.

Evidence Self-reported; no specific customer segmentation or market data provided.

Back to contents

Business Model & Pricing Evidence

  • Not evidenced. No mention of pricing, monetization strategy, or business model in the description.
  • The project is described as open-source and built for a hackathon.
  • There are no indications of paid features, subscriptions, or revenue streams.

Evidence Self-reported; no commercial details provided.

Back to contents

Technical & Delivery Signals

  • Built with Python (Flask), PostgreSQL, HTML5, CSS3, JavaScript
  • Uses libraries like requests, stix2, psycopg2, flask-cors
  • Implements modular connector architecture for data ingestion
  • Includes a scheduler for configurable cron-like loops
  • Features a scoring engine aligned with Intelligence Processing Architecture
  • Has a corroboration engine that computes weighted-average confidence with pairwise vendor agreement bonuses
  • Implements time decay and auto-revocation of IOCs below threshold
  • Supports defanged IOC parsing (hxxp://, [dot], etc.)
  • Uses environment variables for secrets management instead of hardcoding in source code

Evidence Self-reported technical details; no independent verification.

Back to contents

Traction & Maturity Signals

  • Not evidenced. No data on user adoption, customer base, or usage metrics.
  • The project is described as a hackathon submission (Devpost entry).
  • No mention of production deployments, active users, or community engagement.
  • The authors note that the v2 version implements features not seen in any free tool, but this does not imply traction.

Evidence Self-reported; no third-party validation or usage data.

Back to contents

Competitive Context

  • The description states that UTIX addresses shortcomings in commercial Threat Intelligence Platforms (TIPs) that provide black-box scores without transparency.
  • It claims to implement models similar to those found in MISP and other open standards, but with additional features like automatic decay and self-cleaning exports.
  • No mention of direct competitors or competitive positioning beyond "no free TIP does this out of the box."

Evidence Self-reported; no external competitive analysis provided.

Back to contents

Key Risks & Red Flags

  • The project is described as a hackathon submission, suggesting it may be experimental or incomplete
  • No evidence of production use, scalability, or long-term maintenance plans
  • The authors note challenges in getting multi-vendor math right and calibrating decay curves — indicating complexity that may not have been fully resolved
  • Lack of any commercial or user feedback mechanisms beyond self-assessment
  • No evidence of security hardening, testing, or production readiness beyond basic implementation

Inference Given the hackathon context and lack of traction, there is a high risk that UTIX has not yet achieved meaningful adoption or operational maturity.

Back to contents

Diligence Questions To Ask The Founders

  1. What is the actual usage or feedback from security teams who have tried UTIX?
  2. How does UTIX handle feed overlap between different sources (e.g., ThreatFox and OTX)?
  3. Has the scoring model been validated against real-world threat data or SIEM hits?
  4. Are there any plans for monetization or commercial deployment?
  5. What is the roadmap for addressing dependencies in source feeds?
  6. How does UTIX integrate with existing SIEMs or EDR tools beyond log matching?

Back to contents

Investment/Partnership Verdict

  • Not evidenced. No indication of investment interest, partnership opportunities, or strategic value beyond its current hackathon-stage form.
  • The project appears to be an experimental tool developed by two individuals for a hackathon, with no evidence of commercial traction or scalability.
  • It may represent early-stage innovation in threat intelligence tools, but lacks any demonstrated market validation.

Confidence Level Low — based entirely on self-reported description with no external corroboration.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.