Watcher: Open-Source AI Cyber Threat Intelligence and Hunting Platform on Django and React
An architectural review of Watcher by Thales Group CERT: an open-source threat intelligence platform using Django, React, and Hugging Face AI models for automat
Developed and maintained by the Thales Group Computer Emergency Response Team (Thales Group CERT), Watcher is gaining traction among security engineers, threat analysts, and incident response teams as an open-source Cyber Threat Intelligence (CTI) and threat hunting platform. Built on a full-stack architecture combining a Django backend and a React JS frontend, Watcher aggregates and tracks emerging cyber threats while integrating open-source artificial intelligence models to automatically summarize and extract entities from complex threat telemetry. As of October 2026, the project maintains an active open-source footprint on GitHub with over 1,300 stars and 200 forks.

Image source: Thales Group CERT / GitHub
Designed for Security Operations Centers (SOCs) and computer incident response teams, Watcher delivers a self-hosted alternative to proprietary cloud CTI offerings, allowing organizations to retain complete sovereignty over sensitive threat data and indicators of compromise.
Django and React Architecture for Open-Source CTI and Threat Hunting
At its foundation, Watcher pairs Python's robust enterprise web framework, Django, with React JS to provide a responsive and scalable interface for daily threat analysis.
The architecture is structured to help security analysts organize high-volume security alerts, track threat actors, and map relationships across indicators.
- Self-Hosted Data Sovereignty: By deploying entirely within an organization's on-premises infrastructure or Virtual Private Cloud (VPC), teams avoid leaking sensitive incident data, Indicators of Compromise (IoCs), and internal telemetry to third-party multi-tenant cloud services.
- Modular Full-Stack Design: The Django ORM manages relational threat models and complex data feeds, while the React-based single-page application (SPA) ensures seamless querying and fast navigation across large sets of intelligence data.
- API Extensibility: Watcher ships with auto-generated Swagger REST API documentation powered by
drf-spectacularat/api/, enabling straightforward programmatic integration into internal Security Orchestration, Automation, and Response (SOAR) workflows, SIEM collectors, and automated ingest pipelines.
Open-Source AI Analysis Pipeline with Flan-T5 and BERT NER
A defining technical characteristic of Watcher is its direct integration of Hugging Face Transformers models into the threat analysis pipeline without requiring proprietary cloud LLM subscriptions.
By orchestrating verified open-source models, Watcher processes unstructured threat feeds directly on host infrastructure.
- Automated Threat Summarization via google/flan-t5-base: Raw intelligence reports, advisories, and unstructured incident writeups are ingested and processed by the
google/flan-t5-basetext-to-text generation model to synthesize concise, actionable threat summaries for incident responders. - Named Entity Recognition via dslim/bert-base-NER: The platform applies
dslim/bert-base-NERto automatically extract named entities—including threat actors, targeted industries, malware families, and infrastructure markers—transforming free-form text into structured, searchable tags. - Zero API Lock-In: Running inference locally eliminates per-token API costs and prevents operational downtime caused by external rate limits or provider policy changes.
CyberWatch External Feed Integration, Dashboards, and Enterprise Controls
Beyond raw data aggregation, Watcher provides real-time situational awareness through rich dashboarding and modular feed integration.
Successive releases, including the v3.4.0 milestone, have introduced enterprise-grade capabilities tailored to operational environments.
- CyberWatch Standalone Module: Continuously fetches, correlates, and surfaces external threat intelligence feeds directly within the central interface, establishing context across disparate threat sources.
- Interactive Global Mapping and Dynamic Layouts: Features an interactive world map for geographical threat visualization alongside resizable, draggable dashboard widgets and custom KPI metrics panels such as
CyberWatchStats. - Identity and Access Controls: Supports Single Sign-On (SSO) and OIDC federated authentication, reinforced by granular permission guards enforced across all system modules.
- Domain Monitoring: Includes automated UDRP (Uniform Domain-Name Dispute-Resolution Policy) case tracking to assist brand protection and anti-phishing operations.
Docker Deployment, Schema Migrations, and AGPL-3.0 Licensing Considerations
Organizations planning to deploy Watcher in production or lab environments should consider several operational and legal factors:
- Deployment Flexibility: In addition to standard manual web server configurations, Watcher provides official Docker containerization for rapid, reproducible deployment. The codebase has been modernized to run on Python 3.12 and Django 6.0.5.
- Database Schema Migrations: Upgrading between releases may introduce database schema adjustments. Operators must run standard database migrations (
python manage.py migrate) following updates. - AGPL-3.0 Copyleft Compliance: The repository is licensed under the GNU Affero General Public License v3.0 (AGPL-3.0). Because AGPL-3.0 requires source availability even when software is accessed over a network, engineering teams modifying Watcher for commercial software-as-a-service offerings must ensure compliance with copyleft redistribution obligations.
Watcher offers security teams an effective, self-contained platform that unites structured threat hunting with local machine-learning intelligence and modern web ergonomics.
Sources
- GitHub Repository: thalesgroup-cert/Watcher
- Official Documentation: Watcher Documentation
- Dark Web Informer on X (@DarkWebInformer): Watcher Release Overview