
Threat intelligence products
Four MITRE CTI Blueprint reports generated from STIX 2.1 data, with traceable facts and bounded AI-assisted prose.
See reports and templatesBlackStork retrieves data from your security stack, evaluates reusable templates, and produces consistent Markdown, HTML, and PDF reports.
Use controlled AI only where narrative drafting is useful.

BlackStork is designed for recurring, high-value documents built from data spread across several systems. Inspect the rendered output and the templates behind it.

Four MITRE CTI Blueprint reports generated from STIX 2.1 data, with traceable facts and bounded AI-assisted prose.
See reports and templates
A client-ready assessment built from structured OWASP PTRS findings and the consultant's attack narrative.
See reports and templates
A repeatable weekly overview that turns security operations data into useful context for technical and business stakeholders.
See the workflowSecurity reporting usually requires analysts to manually gather data from a zoo of disconnected UIs, structure it, and format it. BlackStork turns this process into an automated, repeatable workflow.
Native plugins connect directly to your SIEM, TIP, and security APIs. BlackStork queries the exact structured data you need - alerts, CTI entities, CVEs, tickets, etc - and pulls it into the evaluation context.
Define the structure of your reports using reusable template blocks. You control the exact layout and styling of the document, so every report adheres to your standard.
Pass specific, bounded data to LLMs. Use them to draft executive summaries, incident narratives, or risk translations exactly where you need them in the document.
Review the fully rendered document in the BlackStork web platform. Make final edits, adjust formatting, and distribute the report to stakeholders via a secure, hosted link.
Define the required data, transformations, sections, and presentation once. Rerun the template whenever the underlying data changes.
Retrieve and transform data directly from siloed tools instead of asking analysts to copy it into recurring reports by hand.
Define the structure once. Every generated report adheres to the exact same layout, styling, and branding, establishing a high baseline of quality across your entire team.
Move away from disjointed file attachments. Edit rendered documents collaboratively in the web platform, distribute them via secure links, and track stakeholder engagement.
BlackStork does not replace analyst judgment, peer review, or security expertise. It automates data retrieval, repeatable structure, controlled drafting, formatting, and delivery so practitioners can focus on the analysis.
AI is optional. Templates determine which data a model receives and where generated prose may appear. Required sections, factual tables, and document formatting remain deterministic.
BlackStork connects directly to your existing infrastructure. Our plugin ecosystem of 20+ plugins supports fetching structured data across your entire security stack.
Work directly with BlackStork founder Sergey Polzunov to assess one recurring report, connect its data sources, and reproduce its production workflow. If the workflow is suitable, we will scope the first implementation and define how its results will be measured.
Discuss your reporting workflow