# SAM #FA255026AC002

Cyber Threat Intelligence Software Platform Market Research for Schriever Space Force Base

**Buyer:** 50th Contracting Squadron
**Posted:** September 21, 2026
**Respond By:** September 24, 2026
**Identifier:** FA255026AC002
**NAICS:** 541512, 541511, 541513

The Department of the Air Force's 50th Contracting Squadron at Schriever Space Force Base is seeking market research for a cyber threat intelligence software platform.
- Government Buyer:
  - Department of the Air Force
  - 50th Contracting Squadron (50 CONS PKP)
  - Schriever Space Force Base
- OEMs and Vendors:
  - No specific OEMs or vendors are named in the notice
- Products/Services Requested:
  - Secure, high-fidelity network flow analytics software platform
  - Key features required:
    - Netflow telemetry querying
    - Threat infrastructure tracking
    - Passive DNS and IP reputation analysis
    - Encrypted traffic profiling
    - API endpoints for integration with local security tools and SIEM systems
    - Web-based interface, accessible 24/7/365
    - Operations and maintenance support (software updates, database maintenance, search engine optimization, feature additions, technical support)
- Unique/Notable Requirements:
  - Platform must be web-based and available at all times
  - Must support integration with local security tools and SIEM systems via API
  - Ongoing support and maintenance required, including troubleshooting and configuration
  - This is a sources sought notice for market research; no quotes or awards will be made at this stage

### Description

<p>This is a new requirement for a secure, high-fidelity network flow analytics platform. The system must meet or exceed the following technical capabilities:</p>

<p>Netflow Telemetry Querying: Provide access to a massive, global network flow database with the ability to run targeted queries on source/destination IP addresses, ports, protocal types, packet counts, and timestamps.</p>

<p>Threat Infrastructure Tracking: Enable users to trace malicious command and control (C2) servers, map botnets, analyze hostile infrastructure, and perform forensic attribution.</p>

<p>Passive DNS &amp; IP Reputation: Integrated access to historical passive DNS databases and IP threat scores to quickly context-resolve suspect nodes.</p>

<p>Encrypted Traffic Profiling: Capabilities to identify and analyze anomalous traffic patterns and identify threat actors utilizing virtual private networks (VPNs) or encrypted tunneling.</p>

<p>Secure, web-based software platform with 24/7/365 availability.</p>

<p>API endpoints for integrating intelligence feeds directly into the unit&#39;slocal security tools, Security Information and Event Management (SIEM) systems, or data orchestrators.</p>

<p>Operations &amp; Maintenance Support:<br />
&bull; Software Updates: Ongoing platform upgrades, database maintenance, search engine optimization, and feature additions throughout the performance periods at no extra cost.<br />
&bull; Technical Support: Helpdesk and administrator support for user troubleshooting, configuration assistance, and platform optimization</p>

<p></p>

<p>This posting is a Sources Sought only for market research, no quotes will be evaluated at this time.</p>

[View original listing](https://sam.gov/opp/2f53f3558ac34d7fa297af74b2b56ba2/view)
