# Schriever Cyber Threat Intelligence Software

Canonical: https://abierto.us/opportunities/fa255026ac002

- Solicitation number: FA255026AC002
- Notice type: Sources sought
- Status: Closed. Deadline was September 24, 2026 at 2:00 PM EDT
- Department: Department of the Air Force
- Agency: Department of the Air Force
- Contracting office: FA2550 50 Cons PKP (FA2550)
- NAICS: 541511 Custom Computer Programming Services
- Product or service code: DJ10 Security and Compliance support delivered as a service, by subscription, or service contract. Includes support of security policies/controls, processes, measuring compliance of relevant legal/compliance requirements, to include Section 508, and responding to security breaches. Also provides support for IT Security systems providing Continuous Diagnostics and Mitigation (CDM) for real-time Cyber Security and protection such as vulnerability scanning, managing firewalls, intrusion prevention systems, and security information and event management (SIEM). Includes Disaster Recovery (DR) services to support DR policy, process and means, dedicated failover facilities and perform DR testing.
- Place of performance: Colorado Springs, Colorado
- County: El Paso County (FIPS 08041). https://abierto.us/counties/el-paso-county-co-08041
- City: Colorado Springs. https://abierto.us/cities/colorado-springs-co-0816000
- First posted: September 21, 2026
- Last posted: September 21, 2026
- SAM.gov: https://sam.gov/workspace/contract/opp/2f53f3558ac34d7fa297af74b2b56ba2/view

## Description

This is a new requirement for a secure, high-fidelity network flow analytics platform. The system must meet or exceed the following technical capabilities:

Netflow Telemetry Querying: Provide access to a massive, global network flow database with the ability to run targeted queries on source/destination IP addresses, ports, protocal types, packet counts, and timestamps.

Threat Infrastructure Tracking: Enable users to trace malicious command and control (C2) servers, map botnets, analyze hostile infrastructure, and perform forensic attribution.

Passive DNS & IP Reputation: Integrated access to historical passive DNS databases and IP threat scores to quickly context-resolve suspect nodes.

Encrypted Traffic Profiling: Capabilities to identify and analyze anomalous traffic patterns and identify threat actors utilizing virtual private networks (VPNs) or encrypted tunneling.

Secure, web-based software platform with 24/7/365 availability.

API endpoints for integrating intelligence feeds directly into the unit'slocal security tools, Security Information and Event Management (SIEM) systems, or data orchestrators.

Operations & Maintenance Support:

&bull; Software Updates: Ongoing platform upgrades, database maintenance, search engine optimization, and feature additions throughout the performance periods at no extra cost.

&bull; Technical Support: Helpdesk and administrator support for user troubleshooting, configuration assistance, and platform optimization

This posting is a Sources Sought only for market research, no quotes will be evaluated at this time.

## Publications

- September 21, 2026: Sources sought, due September 24, 2026 at 2:00 PM EDT. Notice 2f53f3558ac34d7fa297af74b2b56ba2. https://sam.gov/workspace/contract/opp/2f53f3558ac34d7fa297af74b2b56ba2/view

## Points of contact

- David Anderson, david.anderson.182@spaceforce.mil, 7195677291
- Alejandro Castellanos, alejandro.castellanos@spaceforce.mil, 7195676185

---
Source: SAM.gov Contract Opportunities bulk extract. Confirm deadlines on SAM.gov before responding. Cite https://abierto.us/opportunities/fa255026ac002.
