ARTIFICIAL INTELLIGENCE

A new open-weight AI model REDCELL Releases Locally Runnable Gemma-Based AI Model Fine-Tuned for Cyber Threat Intelligence

REDCELL, a fine-tune of Google's Gemma 4 26B-A4B model, is built specifically for OSINT and cyber threat intelligence work, from source grading to threat-actor attribution, and can run on consumer hardware.

Analyst's dual-monitor workstation showing threat intelligence dashboards, IP lookup data, and a terminal window running a local AI modelARTIFICIAL INTELLIGENCE

Image: Redcell · Uploaded by IntraGoals — usage rights confirmed

A new open-weight AI model tailored to open-source intelligence (OSINT) and cyber threat intelligence (CTI) work has surfaced on Hugging Face and been picked up by Hacker News. Called REDCELL, the model is a supervised fine-tune of Google DeepMind's Gemma 4 26B-A4B, a mixture-of-experts architecture with 26 billion total parameters and roughly 4 billion active at any time, and it supports a context window of 262,144 tokens.

The model was developed by a Hugging Face user going by the name terrorswift and is released under the Apache-2.0 license. According to the model card, REDCELL was trained on a custom instruction dataset of about 6,500 examples spanning four domain axes and 33 subcategories, designed to teach the model the habits of a senior intelligence analyst rather than the cautious hedging typical of general-purpose chatbots.

Among the tasks the model card says REDCELL is tuned for are threat-actor attribution, pivoting on indicators of compromise (IoCs), geolocation analysis, and source grading using the Admiralty system, a standard reliability-and-credibility scale used across the intelligence community. The developer describes the model as intended for OSINT researchers, threat intelligence teams, computer emergency response teams (CERTs), and investigative journalists, rather than as a general-purpose or deliberately uncensored model.

Unlike so-called "abliterated" models, which have safety behaviors surgically removed after training, the developer says REDCELL retains its inherited safety reasoning intact and was shaped instead through its training data, which the model card frames as a deliberate choice to avoid technical side effects associated with post-hoc modification, such as broken code paths.

The model is distributed in GGUF format, a file format used for running large language models locally via tools such as llama.cpp, with several quantization options ranging from a full 47-gigabyte 16-bit version down to an 11.4-gigabyte compact variant, intended to let it run on consumer-grade hardware. Smaller quantized versions use a custom method called APEX, which assigns different levels of precision to different parts of the model to balance size against accuracy.

The model card includes a suggested system prompt instructing REDCELL to act as a methodical analyst: showing its reasoning, grading sources, stating confidence levels explicitly, citing real tools such as Shodan, VirusTotal, and crt.sh, and flagging when a task moves from passive reconnaissance into active collection that could carry legal or ethical risk. The prompt also directs the model to acknowledge the limits of its training data, which the developer says ends around May 2024, rather than guessing at the current date.

Training details listed on the model card include a 16-bit LoRA fine-tuning run of 808 steps over two epochs on a single high-end GPU, taking roughly four hours, with eval loss declining from 1.39 to 0.94 over the course of training. The developer describes this pattern as consistent with normal domain adaptation rather than harmful overfitting.

The model card is explicit about its limitations, describing REDCELL as an experimental research tool whose output is not a source of ground truth and must be independently verified, and noting that outside the OSINT/CTI domain its performance reverts to that of the base Gemma 4 model. Formal benchmark results have not yet been published; the developer says informal local testing has been promising but encourages users to verify claims themselves.

This account is based on the model's published documentation and a Hacker News post surfacing the release. Independent testing or third-party benchmarking of REDCELL's claimed capabilities has not been verified.

Sources and further readingMd Ismail Šojal 🕷️ (@0x0SojalSec) on X ↗
ABOUT THE DESK

IntraGoals News Desk

IntraGoals reports on important changes in technology and work. We check each story for clear writing, trusted sources and useful information before it is published.

KEEP READING

Latest from IntraGoals.

All latest stories ↗