What it knows
This model was trained on 7,000 structured Q&A pairs sourced from 8 live intelligence feeds:
- CISA KEV — 1,991 actively exploited vulnerabilities with patch deadlines
- MITRE ATT&CK — 1,103 technique mappings with detection rules
- AbuseIPDB — 839 real attacker IPs with abuse scores and ISP attribution
- Malware Intelligence — 716 entries from URLhaus, SSL Blacklist, and MalwareBazaar
- Infrastructure Defense — 506 entries on SSH hardening, container security, and honeypot deployment
- Cowrie Honeypot — 370 entries from live SSH/Telnet attack sessions
- Threat Intelligence — 200 entries on campaign correlation, identity graphs, and alert dedup
- Phishing Detection — 169 entries on domain analysis and typosquatting
- BGP Monitoring — 106 entries on route hijack detection and ASN analysis
Dataset
Trained on 7,000 curated security Q&A pairs covering:
- Honeypot deployment & deception engineering
- BGP monitoring & route hijacking detection
- Web application security (OWASP Top 10)
- LLM prompt injection & AI red teaming
- Malware analysis & sandboxing
- Incident response playbooks
- Network forensics & threat hunting
- API security & authentication bypass techniques
The dataset was compiled from real-world security operations data, incident reports, and adversarial testing logs from live production honeypots. No synthetic or GPT-generated data.
Capabilities
Table with columns: Domain, What it does| Domain | What it does |
|---|
| Vulnerability triage | Classifies CVEs, maps to MITRE, recommends patch priority |
| Honeypot analysis | Analyzes Cowrie sessions, identifies attacker tools and TTPs |
| Threat hunting | Correlates IPs, campaigns, and infrastructure across sessions |
| Malware triage | Identifies malware families, extracts IOCs, recommends containment |
| Phishing detection | Analyzes domains for typosquatting and credential harvesting |
| Infrastructure defense | Recommends SSH hardening, container isolation, and honeypot deployment |
| BGP intelligence | Detects and explains route hijacks and ASN anomalies |
How to use
from transformers import AutoModelForCausalLM, AutoTokenizer
model = AutoModelForCausalLM.from_pretrained(
"NiffyHunt90/wraithwall-core-v3",
torch_dtype="auto",
device_map="auto"
)
tokenizer = AutoTokenizer.from_pretrained("NiffyHunt90/wraithwall-core-v3")
prompt = "Explain CVE-2024-6387 and how to detect exploitation."
inputs = tokenizer(prompt, return_tensors="pt").to(model.device)
outputs = model.generate(**inputs, max_new_tokens=200)
print(tokenizer.decode(outputs[0], skip_special_tokens=True))
Training
- Base model: Qwen 2.5 Coder 7B
- Method: LoRA (4.07% parameters trained)
- Hardware: 2x Tesla T4 (14.5GB VRAM)
- Framework: Unsloth + HuggingFace TRL
- Epochs: 3 | Steps: 2,625 | Batch size: 8
- Loss: 3.44 → 0.11 (96.8% reduction)
License
Apache 2.0 — same as base model.
Author
Adewale Babalola (Niffyhunt) — Founder, WraithWall
Built on live internet traffic. Deception-first intelligence, solo operator.