Malanta.ai · 2024-2026
IoPA: Research Changed the Roadmap. AI Changed the Delivery Speed.
My role: Product Designer and Researcher
- 911
- Assets rendered on one screen at peak density
- 6
- Research sessions with 2 senior analysts over ~2 months
- 2 days
- Figma screenshots to an interactive Cursor prototype
- 11
- Enterprise and government organizations actively investigating in IoPA
Tools
Teams
Bottom line
My role: Product Designer and Researcher. I owned the investigation flow, the filtering design, the production UX states, and the behavioral research that reset the roadmap for Malanta's flagship analyst tool.
The problem: The version customers were using had the user's own assets stripped out and roughly 200 assets attached to every attack infrastructure. A senior SOC analyst at a Fortune 500 customer said it plainly: "it looks like a mess, I'm losing my hands and feet here." R&D read that as a request for visual polish. I read it as a functional blocker.
- Mixpanel, session recordings, and interviews backed my read, and moved filtering from backlog to an immediate sprint.
- Hierarchical filtering shortened the path from a raw indicator to a filtered, actionable view, built against real 800-asset clusters, not test cases.
- An AI-built prototype wired to real backend data compressed the path from design to build.
Challenge
Approach
- 1911 nodes, real density: Built against real cluster scenarios, not the 6-node demo, so the taxonomy held at the density analysts actually hit.
- 2Pivot node, not a severity label: The system couldn't back a single risk verdict for this node, so it shows a structural role instead, seed, pivot, or connection, never a certainty it doesn't own.
Two entry points, one investigation
Where the flow stops today, and where it's going
IoPA isn't a standalone tool, and analysts never arrive cold from nowhere. Two separate flows lead here: from a threat card in Imminent Threats, where the context carries over automatically, or from an external IOC (a threat intel report, a vendor bulletin, an indicator another team flagged) that the analyst has to enter themselves. Either way they land in the same investigation, and today, have to leave IoPA to act on what they found. That loop back is the real bottleneck the roadmap below is built to close.
From a threat card
From an external IOC
both land in the same investigation ↓
How does the analyst act on what they found?
Today
Vision
Does the IOC relate to the user's assets?
Yes
No
Impact
Validation
Qualitative first, quantitative confirmed it later
Malanta's SOC analyst base was small, 5-10 active users at any point, not enough for a quantitative test to reach significance. So instead of one-off usability tests, I built an ongoing relationship with the 2 analysts closest to daily use: cyber researchers and analysts inside the company, not external test subjects. Six sessions over about two months, spanning early feature ideation and later usability testing, each one covering something different: sometimes the whole system, sometimes a single feature or flow, sometimes how information connects across screens. The same two voices recur across my case studies because they were the two people who actually lived in the product every day. Six months after launch, Mixpanel data confirmed what those two analysts predicted: independent, repeat usage across a real base of enterprise and government accounts, not just the redirect traffic the roadmap originally optimized for.
The complaint that started this: a senior SOC analyst at a Fortune 500 customer said it plainly, "it looks like a mess, I'm losing my hands and feet here," describing an attack infrastructure view with roughly 200 unfiltered assets and no way to locate their own.
Changed to:
Moved filtering from backlog to an immediate sprint, added My Assets, and built hierarchical filtering against real 800-asset clusters instead of the polished demo scenario.
What I'd do differently
Retrospective
- Follow-up interviews with 2 senior analysts confirmed the fix cut visual noise, but time-on-screen barely moved, which surfaced the real finding: analysts don't browse IoPA, they arrive only mid-investigation from a concrete threat to their own assets. That reframed what success on this screen should even measure. If I had more research bandwidth, I'd want a small quantitative check (time-to-triage) to back that signal before this pattern scales to other workflows.
- The loop back to Imminent Threats to act on a finding is still a manual step today, that's the real bottleneck the vision branch is built to close, not yet shipped.
- I'd bring the user's own assets back onto the map, ranked by significance instead of arrival order. I prototyped exactly that with AI in an afternoon, to prove the interaction, not just describe it.
- I recommended progressive disclosure of assets inside a cluster, revealing them on demand instead of rendering all ~200 at once, an idea V2's cluster-bubble view had already tested at the cluster level. The product manager prioritized a client demo deadline instead, so V3 shipped at full density. Progressive disclosure at the asset level is still the plan for the next version.