Sigalit Mualem
← Back to work

Malanta.ai · 2024-2026

IoPA: Research Changed the Roadmap. AI Changed the Delivery Speed.

My role: Product Designer and Researcher

911
Assets rendered on one screen at peak density
6
Research sessions with 2 senior analysts over ~2 months
2 days
Figma screenshots to an interactive Cursor prototype
11
Enterprise and government organizations actively investigating in IoPA

Tools

FigmaCursorClaude CodeGitHub

Teams

Security AnalystsBackend EngineeringFrontend Engineering

Bottom line

My role: Product Designer and Researcher. I owned the investigation flow, the filtering design, the production UX states, and the behavioral research that reset the roadmap for Malanta's flagship analyst tool.

The problem: The version customers were using had the user's own assets stripped out and roughly 200 assets attached to every attack infrastructure. A senior SOC analyst at a Fortune 500 customer said it plainly: "it looks like a mess, I'm losing my hands and feet here." R&D read that as a request for visual polish. I read it as a functional blocker.

  • Mixpanel, session recordings, and interviews backed my read, and moved filtering from backlog to an immediate sprint.
  • Hierarchical filtering shortened the path from a raw indicator to a filtered, actionable view, built against real 800-asset clusters, not test cases.
  • An AI-built prototype wired to real backend data compressed the path from design to build.
V1 · Threat landscape without the user

Challenge

Job to be done: an analyst arrives holding one signal (a domain, an IP, an email) that alone says nothing about scale. They need to see how far it reaches, so they can decide what's worth investigating and what to do about it.
The version customers were actually using had the user's own assets stripped out, and each attack infrastructure expanded to roughly 200 assets, a product call made to prove detection scale.
R&D read the complaint as a request for visual polish, low priority. I read it as a functional blocker: analysts were working around the product, not with it.

Approach

Before designing the map, researched how the industry displays dense, high-volume threat data: attacker-centric exposure radars (IONIX), graph-pivot investigation tools (OpenCTI, Amazon Detective, Google Threat Intelligence), and compliance network diagrams. None solved the specific problem here: 200+ assets in one cluster, some isolated, some deeply connected.
Researched real high-asset scenarios, not the polished demo, and added My Assets so the analyst could locate themselves in the threat story.
V2 · Adding the user to the story
Refused to stamp clusters with a single severity label the system couldn't back; showed structural facts (counts, seeds, pivots) instead.
Ring clusters, hover-to-focus, a full-width side panel, and a 200-node table fallback so the view stayed honest at real density.
V3 · Shipped: ring clusters
  • 1911 nodes, real density: Built against real cluster scenarios, not the 6-node demo, so the taxonomy held at the density analysts actually hit.
  • 2Pivot node, not a severity label: The system couldn't back a single risk verdict for this node, so it shows a structural role instead, seed, pivot, or connection, never a certainty it doesn't own.
Added click-to-drill for deeper detail per asset type, and connection lines between elements so the map reads as the threat's path, not a static inventory.
Designed every runtime state (loading, enriching, error, empty, ready) on its own, so the UI never implied more certainty than the backend could support.
The ring colors, badges, and side panel aren't a custom palette invented for this screen: they pull from the same token set and component library documented in Imminent Threats, the shared source every Malanta workflow draws from.

Two entry points, one investigation

Where the flow stops today, and where it's going

IoPA isn't a standalone tool, and analysts never arrive cold from nowhere. Two separate flows lead here: from a threat card in Imminent Threats, where the context carries over automatically, or from an external IOC (a threat intel report, a vendor bulletin, an indicator another team flagged) that the analyst has to enter themselves. Either way they land in the same investigation, and today, have to leave IoPA to act on what they found. That loop back is the real bottleneck the roadmap below is built to close.

shippedLive in the product today
visionRoadmap, not yet built
Decision point

From a threat card

shippedThreat card, Imminent Threats page
shippedOpen IoPA: context carries over automatically

From an external IOC

shippedIOC received: threat intel report, vendor bulletin, or flagged by another team
shippedAnalyst enters the IOC in IoPA, cold

both land in the same investigation

shippedAttack Infrastructure view (cluster view)
shippedGeneral cluster information, in context of the IOC

How does the analyst act on what they found?

Today

shippedBack to Imminent Threats page to apply the action

Vision

visionCluster info also shown in context of the user's own assets
visionThreat investigation: attack infrastructure + user's assets together
visionDeep dive investigation

Does the IOC relate to the user's assets?

Yes

visionPrevention action, taken directly in IoPA, no loop back

No

visionNo prevention action surfaced here
Step 1 · Enter the IOC
Step 2 · Graph loads
Step 3 · Drill into a cluster
Step 4 · Filter to focus

Impact

Triangulated Mixpanel, session recordings, and analyst interviews to ground the redesign. Six months post-launch, Mixpanel confirmed it: 27 of 31 verified customer accounts had used IoPA independently, spanning 11 organizations across cybersecurity, government, healthcare, insurance, and finance. Nearly half of those users returned 11+ times, averaging 80 seconds per session, the third-highest dwell time in the product.
30% of page visits (52 of 172) were analysts navigating to IoPA directly, not redirected from an alert, evidence it functions as a standalone investigation tool, not just a click-through from a notification.
Built the filtering against real cluster scenarios: 800 assets tied to a single node, clusters scaling into the hundreds of nodes, up to 911 assets rendered on one screen.
Shipped production workspace
An AI-built prototype wired to live backend data let me hand engineering an interaction-complete spec, not a static mockup.
Defined how I'd validate the redesign before shipping it, not after: adoption (independent-entry rate, return rate), depth (filter, pivot, and export usage paired with dwell time), and outcome (investigations ending in a concrete action, time-to-action), backed by a small customer advisory sample.

Validation

Qualitative first, quantitative confirmed it later

Malanta's SOC analyst base was small, 5-10 active users at any point, not enough for a quantitative test to reach significance. So instead of one-off usability tests, I built an ongoing relationship with the 2 analysts closest to daily use: cyber researchers and analysts inside the company, not external test subjects. Six sessions over about two months, spanning early feature ideation and later usability testing, each one covering something different: sometimes the whole system, sometimes a single feature or flow, sometimes how information connects across screens. The same two voices recur across my case studies because they were the two people who actually lived in the product every day. Six months after launch, Mixpanel data confirmed what those two analysts predicted: independent, repeat usage across a real base of enterprise and government accounts, not just the redirect traffic the roadmap originally optimized for.

The complaint that started this: a senior SOC analyst at a Fortune 500 customer said it plainly, "it looks like a mess, I'm losing my hands and feet here," describing an attack infrastructure view with roughly 200 unfiltered assets and no way to locate their own.

Changed to:

Moved filtering from backlog to an immediate sprint, added My Assets, and built hierarchical filtering against real 800-asset clusters instead of the polished demo scenario.

What I'd do differently

Retrospective

  • Follow-up interviews with 2 senior analysts confirmed the fix cut visual noise, but time-on-screen barely moved, which surfaced the real finding: analysts don't browse IoPA, they arrive only mid-investigation from a concrete threat to their own assets. That reframed what success on this screen should even measure. If I had more research bandwidth, I'd want a small quantitative check (time-to-triage) to back that signal before this pattern scales to other workflows.
  • The loop back to Imminent Threats to act on a finding is still a manual step today, that's the real bottleneck the vision branch is built to close, not yet shipped.
  • I'd bring the user's own assets back onto the map, ranked by significance instead of arrival order. I prototyped exactly that with AI in an afternoon, to prove the interaction, not just describe it.
  • I recommended progressive disclosure of assets inside a cluster, revealing them on demand instead of rendering all ~200 at once, an idea V2's cluster-bubble view had already tested at the cluster level. The product manager prioritized a client demo deadline instead, so V3 shipped at full density. Progressive disclosure at the asset level is still the plan for the next version.
Retro, prototyped: assets back on the map
What changed vs. before