REDCELL packages OSINT and threat-intelligence workflows into a local model

Md Ismail Sojal promoted the Gemma 4 fine-tune on September 29th; its model card reports no formal benchmarks and warns users to verify its conclusions.

By · Published

Primary source: X

Why it matters

REDCELL targets investigations where sending data to a hosted model may be undesirable, but its local packaging comes with substantial memory requirements and no published formal benchmarks for its core attribution and source-grading claims.

An anonymous analyst's hands glow from a computer screen displaying complex cyber threat intelligence and network analysis visuals in a dark office.

Md Ismail Sojal promoted REDCELL, a locally runnable model fine-tuned for open-source intelligence and cyber threat analysis, in a September 29th post on X. The model was already listed on Hugging Face: its repository history shows an update on July 12th, and the model card dates the project to 2026. The post is a fresh promotion of an existing release, not evidence that the model launched that day.

The REDCELL model card describes a supervised fine-tune of Google's Gemma 4 26B-A4B, a mixture-of-experts model with 26 billion total parameters and about 4 billion active for each token. It advertises a 262,144-token context window and weights in GGUF format, which the card says can be run with tools including llama.cpp. The card credits development to the Hugging Face account terrorswift; Sojal's post points to that repository but does not identify whether he operates that account.

Sojal's public work is rooted in cybersecurity. His GitHub profile describes him as a cybersecurity researcher focused on malware analysis and AI, and highlights open-source resources including collections of Telegram OSINT tools and dark-web research material. The profile provides relevant context for the model's subject matter, while the release itself is credited to terrorswift.

The model card says REDCELL was tuned on roughly 6,500 instruction examples divided across 33 categories. Those cover cyber threat intelligence, investigative journalism, counter-disinformation and research methodology. Examples include threat-actor and campaign attribution, indicator-of-compromise pivoting, vulnerability triage, image geolocation, source credibility grading, and public-records research. The documentation also says the corpus was grounded in reference material and MITRE resources, then deduplicated and balanced. These are the developer's descriptions of the training process, not an independent audit of the data or its quality.

The release's practical bet is that investigators may prefer a specialized model they can run on their own machines, particularly when prompts involve sensitive threat intelligence or investigative notes. REDCELL's quantized files range from 11.4GB to 47GB, according to its model card. That makes "local" a deployment option, not a promise that the model runs comfortably on any laptop. Google's Gemma 4 documentation estimates 14.4GB of memory for the base 26B A4B model at 4-bit precision, before adding memory for software and the context cache. Long-context use adds further memory demand.

Infographic distinguishing REDCELL quantized file sizes from the base Gemma 4 model’s estimated memory use and additional memory demands.
The model card lists REDCELL files at 11.4–47GB; Google estimates 14.4GB of memory for the base model at 4-bit, before software and context-cache overhead — AI explanatory infographic, not documentary evidence. RuntimeWire · AI-generated infographic.

The model card gives a detailed suggested setup for llama.cpp and lists several downloadable quantizations. It also says the release is an experimental research tool, is not a source of ground truth, and can produce confident but incorrect attributions or relationships. Its performance section reports informal spot checks, while stating that formal capability and refusal-behavior benchmarks may be added later. That leaves the central performance claim untested in published, comparable evaluations: the documentation describes the intended analytical style, but does not show that REDCELL attributes actors or grades sources more accurately than its base model or other available models.

The distinction matters for the use cases REDCELL names. An incorrect attribution can turn a lead into a false accusation; an OSINT model's confident prose does not verify the evidence it summarizes. The model card instructs users to confirm outputs independently and says that performance outside OSINT and threat intelligence is at the base model's level at best. It lists an Apache-2.0 license for REDCELL and says there is no inference-provider deployment on Hugging Face; users can download the weights and run them through local software.

REDCELL is therefore a specialized open-weight release, not a hosted investigation service or a validated analyst replacement. Its differentiator is the combination of a cyber and investigative training focus, a long advertised context window and local deployment formats. Whether that combination improves real investigative work remains a question its published documentation does not yet answer.

Reader comments

Conversation for this story loads after sign-in.