Embedded Systems / Cybersecurity / Real-Time Intelligence Display

Global Threats Insights

Global Threats Insights is a real-time cybersecurity intelligence ticker device — a purpose-built "Cyber Ticker" running on the LilyGO T-Display-S3...

Global Threats Insights

Category: Embedded Systems / Cybersecurity / Real-Time Intelligence Display
Platform: LilyGO T-Display-S3 (ESP32-S3)
Framework: Arduino via PlatformIO | C++
Status: Active — Production Ready


Project Overview

Global Threats Insights is a real-time cybersecurity intelligence ticker device — a purpose-built "Cyber Ticker" running on the LilyGO T-Display-S3. It continuously aggregates live threat data from three premier cybersecurity intelligence APIs and displays it in a richly formatted, colour-coded, on-screen dashboard. The device also runs a companion web server accessible via browser over the local network, providing a live HTML dashboard mirroring the on-screen display.

The project is aimed at security analysts, researchers, SOC operators, and cybersecurity enthusiasts who want always-on, at-a-glance situational awareness of the global threat landscape — delivered on a compact, portable ESP32-powered display.


Data Sources

The device cycles through three authoritative cybersecurity intelligence feeds, auto-refreshing every 60 seconds:

1. NIST National Vulnerability Database (NVD)

  • Queries the official NIST NVD REST API v2.0 for the most recent CVEs published in the last 7 days
  • Displays:
    • CVE identifier (e.g., CVE-2026-12345)
    • CVSS base score (v3.1, v3.0, or v2.0 — auto-selected in order of preference)
    • Full vulnerability description (paginated if longer than display capacity)
  • Visual feature: Colour-coded circular CVSS score badge rendered directly on the TFT
    • Green: Low severity (0.0–3.9)
    • Orange: Medium/High severity (4.0–8.9)
    • Red: Critical severity (9.0–10.0)
  • NTP time-synced date range queries — always fetches the most recent 7-day window

2. MalwareBazaar (abuse.ch)

  • Queries the MalwareBazaar API for the most recently submitted malware sample
  • Displays:
    • Malware signature (family/variant name)
    • Classification tags (e.g., ransomware, trojan, loader)
    • Original filename of the submitted malware sample
  • Visual feature: Dangerous extension highlighting — if the filename ends in .exe, .js, or .vbs, a red bounding box is drawn around the filename entry

3. AlienVault OTX (Open Threat Exchange)

  • Queries the AlienVault OTX API for the most recently published threat intelligence pulse from subscribed feeds
  • Displays:
    • Campaign/pulse name
    • Author/researcher who published the pulse
    • Targeted country (if available)
  • Visual feature: Country tag badge — a filled green pill/tag renders the targeted country name directly on screen

Display Features

Styled UI Border System

  • Every screen features a custom multi-layer glowing cyan border with rounded corners and accent corner dots
  • Creates a professional "security terminal" aesthetic on the small display

Real-Time Battery Indicator

  • Battery voltage is read from GPIO 4 via ADC on every screen render
  • Percentage is calculated from LiPo voltage curve (3.2V = 0%, 4.2V = 100%)
  • Displayed in the top-right corner of every screen

Paginated Content Display

  • Long vulnerability descriptions and malware data are automatically paginated
  • Users can navigate forward and backward through content pages using the hardware buttons
  • Each page is displayed for 8 seconds before auto-advancing

Deep Sleep Power Management

  • Holding the left hardware button for 2 seconds initiates a graceful power-off sequence
  • Device enters ESP32 deep sleep with GPIO 14 configured as the wake-up trigger
  • Proper RTC GPIO pull-up configuration prevents false wake events

Hardware Button Controls

Button Short Press Long Press (2s+)
Right (GPIO 14) Advance to next data feed immediately Wake from deep sleep
Left (GPIO 0) Jump backward / shift feed state Enter deep sleep

Web Dashboard

The device runs an ESPAsyncWebServer on port 80, hosting:

  • Root page (/) — Full HTML dashboard with styled panels for each of the three data sources (NVD, MalwareBazaar, AlienVault OTX)
  • /api/data — JSON REST endpoint returning the latest fetched data for all three sources:
    {
      "nvd": "CVE-2026-XXXXX\nCVSS Score: 9.1\n...",
      "malware": "Sig: RedLine\nTag: stealer\n...",
      "alienvault": "Campaign: Operation Shadow\nAuthor: ..."
    }
    

The web dashboard is accessible from any browser on the same local network as the device.


Technical Architecture

Component Detail
MCU ESP32-S3 @ 240 MHz
Display ST7789 IPS TFT — 320x170 pixels (landscape)
Display Library TFT_eSPI with viewport system
WiFi WiFiManager — captive portal for first-run setup
HTTPS WiFiClientSecure (setInsecure — no cert pinning)
JSON ArduinoJson 7.x with streaming filter deserialization
Time NTP via pool.ntp.org and time.nist.gov
Web Server ESPAsyncWebServer + AsyncTCP
Power ESP32 deep sleep with ext0 wakeup on GPIO 14

API Credentials Required

Service API Key Location
AlienVault OTX ALIENVAULT_API_KEY constant in source
MalwareBazaar MALWARE_BAZAAR_API_KEY constant in source
NIST NVD No API key required (public endpoint)

Deployment

  1. Install PlatformIO in VS Code
  2. Configure API keys in source (AlienVault OTX key, MalwareBazaar key)
  3. Build and flash to LilyGO T-Display-S3
  4. On first boot, connect to CyberTicker_AP WiFi hotspot and enter home network credentials
  5. Device auto-connects, syncs NTP time, and begins cycling threat feeds immediately
  6. Access web dashboard via device IP address on your local network

Use Cases

  • Security Operations Centre (SOC) ambient awareness display
  • Personal threat intelligence monitoring station
  • Conference and event security awareness display
  • Home lab real-time vulnerability monitoring
  • Educational cybersecurity demonstration device
Return to Projects