Opportunity
SAM #FA255026AC002
Cyber Threat Intelligence Software Platform Market Research for Schriever Space Force Base
Buyer
50th Contracting Squadron
Posted
September 21, 2026
Respond By
September 24, 2026
Identifier
FA255026AC002
NAICS
541512, 541511, 541513
The Department of the Air Force's 50th Contracting Squadron at Schriever Space Force Base is seeking market research for a cyber threat intelligence software platform. - Government Buyer: - Department of the Air Force - 50th Contracting Squadron (50 CONS PKP) - Schriever Space Force Base - OEMs and Vendors: - No specific OEMs or vendors are named in the notice - Products/Services Requested: - Secure, high-fidelity network flow analytics software platform - Key features required: - Netflow telemetry querying - Threat infrastructure tracking - Passive DNS and IP reputation analysis - Encrypted traffic profiling - API endpoints for integration with local security tools and SIEM systems - Web-based interface, accessible 24/7/365 - Operations and maintenance support (software updates, database maintenance, search engine optimization, feature additions, technical support) - Unique/Notable Requirements: - Platform must be web-based and available at all times - Must support integration with local security tools and SIEM systems via API - Ongoing support and maintenance required, including troubleshooting and configuration - This is a sources sought notice for market research; no quotes or awards will be made at this stage
Description
This is a new requirement for a secure, high-fidelity network flow analytics platform. The system must meet or exceed the following technical capabilities:
Netflow Telemetry Querying: Provide access to a massive, global network flow database with the ability to run targeted queries on source/destination IP addresses, ports, protocal types, packet counts, and timestamps.
Threat Infrastructure Tracking: Enable users to trace malicious command and control (C2) servers, map botnets, analyze hostile infrastructure, and perform forensic attribution.
Passive DNS & IP Reputation: Integrated access to historical passive DNS databases and IP threat scores to quickly context-resolve suspect nodes.
Encrypted Traffic Profiling: Capabilities to identify and analyze anomalous traffic patterns and identify threat actors utilizing virtual private networks (VPNs) or encrypted tunneling.
Secure, web-based software platform with 24/7/365 availability.
API endpoints for integrating intelligence feeds directly into the unit'slocal security tools, Security Information and Event Management (SIEM) systems, or data orchestrators.
Operations & Maintenance Support: • Software Updates: Ongoing platform upgrades, database maintenance, search engine optimization, and feature additions throughout the performance periods at no extra cost. • Technical Support: Helpdesk and administrator support for user troubleshooting, configuration assistance, and platform optimization
This posting is a Sources Sought only for market research, no quotes will be evaluated at this time.