· via Hacker News – Front Page (hnrss.org)
Local Cyber-OSINT MoE model with 262K context released for threat intel work
A security researcher has released a locally runnable mixture-of-experts model tuned for OSINT and cyber threat intelligence, with a 262K-token context and a smaller 7B variant that fits on 8GB GPUs.
A locally runnable model built for investigations
Security researcher @0x0SojalSec has announced a Cyber-OSINT language model intended to run entirely on local hardware, in a post on X that surfaced on the Hacker News front page on 29 September. Rather than positioning it as a general-purpose chat model with a security-themed prompt, the developer describes it as a supervised fine-tune (SFT) aimed squarely at open-source intelligence (OSINT) and cyber threat intelligence (CTI) workflows.
The main model uses a mixture-of-experts (MoE) design: 26 billion parameters in total, with roughly 4 billion active per token, which is what makes local deployment plausible at that size. It offers a 262,000-token context window and was trained on around 6,500 OSINT and CTI instruction examples, according to the announcement. The weights are hosted on Hugging Face under the DeepHat organisation.
What it is tuned to do
The fine-tune targets concrete analyst tasks rather than generic security Q&A. The capabilities listed in the announcement include:
- Threat-actor attribution: reasoning about which group may sit behind a set of activity.
- IoC pivoting: working outward from indicators of compromise such as hashes, domains and IP addresses toward related infrastructure.
- Geolocation: tying data points to physical location, a classic OSINT exercise.
- Admiralty source grading: applying the long-standing intelligence framework that scores a source's reliability and a report's credibility as separate measures.
The very long context window is directly relevant to this workload, since analysts frequently need to feed entire reports, court filings, leak dumps or log extracts into a model at once rather than working in small chunks.
A smaller sibling for 8GB GPUs
The same announcement also describes a 7-billion-parameter cyber model fine-tuned on cyber and DevOps post-training datasets covering both offensive and defensive work. It has a 32K native context, extendable to roughly 131K tokens using YaRN, a RoPE-based context extension technique, and it is small enough to run on an 8GB GPU, putting it within reach of consumer laptop and entry-level desktop cards.
Fine-tune versus system prompt
The developer's central pitch is a jab at how security models are usually sold: most of them amount to a general-purpose model with a security-flavoured system prompt attached, whereas this release changes the weights themselves through training on domain data. That distinction matters in practice, because prompt-wrapped general models often drift off tradecraft or hallucinate under specialized pressure. Whether this fine-tune actually performs better is precisely what independent evaluation would need to establish, and no such benchmarks are cited in the announcement.
Open questions
Some caution is warranted before operational use. A training set of about 6,500 instructions is modest by current fine-tuning standards, and capability claims around attribution or geolocation come from the developer rather than third parties. The link in the announcement points at the Hugging Face repository in truncated form, so the exact license terms, base model and training mix would need to be verified there first.
Why it matters
Two things lift this above the usual model drop. First, locality: threat-intel and investigative work often involves sensitive material that cannot be sent to a hosted API, and a model that runs offline on an 8GB-class GPU removes the data-egress problem entirely. Second, the shape of the model: MoE efficiency combined with a 262K-token context means an analyst can process whole documents locally, something that until recently required large GPUs or cloud services. The focus on tradecraft-specific skills such as Admiralty grading also signals a shift from chatbots that know about security toward tooling built around the actual analytical workflow. If the fine-tune holds up under scrutiny, it is a useful template for other narrow domains; even if it does not, the demand it reflects, for private, long-context, domain-tuned models, is clearly real.
- #cyber-security
- #osint
- #llm
- #threat-intel
- #mixture-of-experts
- #local-ai