CyberShield AI
CyberShield AI is an advanced, AI-powered Cyber Threat Intelligence, Digital Scam Prevention, and Fraud Investigation Platform. It functions as a dual-sided ecosystem designed to protect Citizens from rapidly evolving digital financial fraud while equipping Law Enforcement Agencies (Police & Cyber Investigators) with automated graph analytics, evidence processing, and syndicate tracking capabilities. The system unifies multi-vector threat ingestion—spanning SMS/phishing text, malicious URLs, scam QR codes, UPI payment handles, and voice call recordings—into a centralized real-time scoring and correlation engine.
Tech Stack
“CyberShield AI has revolutionized our cybercrime operations. Automated entity extraction and graph network linkage cut syndicate tracing time from weeks to seconds.”
SoPSuperintendent of Police
Cyber Crime & Intelligence Division
System Architecture
Backend API & Core Engine
Node.js & Express.js 5 written in TypeScript for high-concurrency API performance. Neon PostgreSQL managed via Prisma ORM 6 with connection pooling. Caching layer powered by Redis (ioredis) for fast threat feed caching and public Tor exit nodes.
Frontend Portal & UX Engine
Next.js 16 App Router with React 19 and Tailwind CSS. Decoupled state management via Zustand 5 across auth, scanner, dashboard, and graph visualizers. Three.js 3D threat model visualizers.
AI & Intelligence Adapters
Google Gemini AI powering AEGIS 24/7 conversational security assistant and multimodal vision/voice threat classification. Live adapters for AbuseIPDB, GreyNoise, Tor Exit nodes, VirusTotal, RDAP, and MaxMind GeoLite2 (City & ASN).
Target Personas & User Journeys
1. The Citizen User
Goal: Verify link/QR/UPI safety before clicking or paying, seek instant advice during scams, and file reports.
2. The Police Officer / Cyber Investigator
Goal: Track fraud trends, investigate incidents, map syndicate networks, and trace infrastructure.
Key Modules & Feature Deep Dive
Unified Multi-Vector Threat Scanner
Technical Implementation: Single unified endpoint (/api/v1/analyze) handling SMS text, URLs, QR Code images, UPI payment handles, and Voice audio recordings. Implements entropy analysis, brand spoofing dictionaries, and live API adapters.
Business & Practical Impact: Reduces threat verification time from hours to under 3 seconds. Provides explicit 0–100 risk scores and color-coded risk levels.
AEGIS — AI Security Assistant & Responder
Technical Implementation: 24/7 conversational AI assistant powered by Google Gemini. Integrated with threat scan history and multi-turn persistent state with streaming responses.
Business & Practical Impact: Empowers citizens with immediate expert guidance to block accounts, freeze SIM cards, and file complaints during live fraud incidents.
IP Intelligence Engine & Threat Profiling
Technical Implementation: Automated profiling engine utilizing modular adapters: MaxMind GeoLite2 City & ASN, AbuseIPDB, GreyNoise, Tor exit list (cached in Redis), and RDAP queries.
Business & Practical Impact: Provides law enforcement and analysts with sub-second infrastructural context on suspicious IP addresses, proxies, and scanning bots.
Citizen Scam Reporting & Evidence Vault
Technical Implementation: Evidence ingestion pipeline accepting screenshots, call recordings, and chat transcripts. Automated NLP entity extraction (phone, UPI, domain, IP).
Business & Practical Impact: Transforms victim complaints into structured digital evidence, automatically feeding threat entities into police databases.
Police Fraud Network Graph & Linkage Engine
Technical Implementation: Visual graph analytics engine modeling entities (PHONE, EMAIL, UPI, DOMAIN, IP, BANK_ACCOUNT, DEVICE) and relationships (CONNECTED_TO, USES, SHARES).
Business & Practical Impact: Solves key investigative bottlenecks by automatically uncovering money mule networks and call center fraud syndicates.
Police Incident & Case Management Board
Technical Implementation: Enterprise case management board supporting full lifecycle management, priority scoring (LOW, MEDIUM, HIGH, CRITICAL), and tamper-evident audit logging.
Business & Practical Impact: Modernizes police operations by replacing manual spreadsheets with a synchronized digital case board.
Data Breach Checker
Technical Implementation: Integrated service allowing citizens to verify if credentials or emails appear in known data leaks.
Business & Practical Impact: Heightens personal cyber hygiene, prompting users to update compromised credentials proactively.
UPI & Financial Handle Reputation Engine
Technical Implementation: Specialized intelligence service tracking normalized VPAs, report counts, risk scores, and status flags (CLEAN, SUSPICIOUS, BLACK-LISTED).
Business & Practical Impact: Targets the largest financial fraud vector by enabling real-time recipient handle verification before authorizing payment transfers.
Geospatial Threat Mapping & Real-Time Analytics
Technical Implementation: Real-time visual map interface mapping threat distribution across geographic regions and monitoring attack trends.
Business & Practical Impact: Provides strategic intelligence for law enforcement leadership to deploy awareness campaigns and investigative resources effectively.
Multi-Role RBAC & Session Security
Technical Implementation: Role-Based Access Control enforcing CITIZEN, POLICE, and ORGANIZATION roles with bcrypt hashing and JWT tokens.
Business & Practical Impact: Guarantees strict data isolation and security compliance while giving law enforcement specialized access.
Data Model & Schema Architecture
User & Profile
Stores core identity, credentials (hashed), user roles (CITIZEN, POLICE, ORGANIZATION), and lock states.
ThreatScan & ThreatAnalysis
Tracks raw scan submissions and linked ThreatAnalysis records with RiskScore breakdowns and indicators.
ThreatReport & Investigation
Manages formal complaints, evidence attachments, priority levels, assigned officers, and linked cases.
GraphNode & GraphEdge
Represents extracted intelligence nodes (PHONE, EMAIL, UPI, DOMAIN, IP) and relationship edges forming FraudNetwork clusters.
Conversation & Message
Logs full multi-turn AEGIS chat threads linked to citizen user profiles.
IPHistory & IpLookupAudit
Tracks IP lookup audits, query counts, and blocklist/allowlist rules.
Business & Technical Impact Summary
| Feature Area | Before CyberShield AI | With CyberShield AI |
|---|---|---|
| Citizen Verification | Manual search or falling victim to phishing scams | Real-time multi-vector threat scanning (< 3s) with 0-100 Risk Score |
| Victim Guidance | Confused, delayed reaction leading to secondary losses | 24/7 AEGIS AI assistant delivering context-aware remediation steps |
| Threat Correlation | Disconnected reports across cities; zero cross-visibility | Automated Entity Extraction & Graph Linkage forming FraudNetwork syndicates |
| IP Profiling | Slow, manual WHOIS and individual command-line checks | Sub-second multi-adapter engine (MaxMind, AbuseIPDB, GreyNoise, Tor) |
| Police Workflow | Fragmented paper/spreadsheet complaint tracking | Centralized command dashboard with priority-ranked digital case board |
| UPI Fraud Defense | No centralized citizen handle reputation lookup | Real-time UPIReputation lookup prior to payment authorization |
Client
Completed
Interested in a similar project?
Book a free demo