Time-Series and Social-Media Threat Analytics over a Deployed Cyber-Threat Knowledge Graph
EdgeGuard, a deployed cyber-threat knowledge graph that merges eleven public threat feeds into one Neo4j database via MISP and the STIX 2.1 exchange format, is measured, showing that half of the vulnerabilities known to have been exploited were listed as exploited within five days of their publication, and that a large ingestion spike in early 2026 came from a single feed rather than a real attack wave.