Inspiration
T-cells detect threats locally, then teach the rest of the immune system to recognize and destroy them - no single cell has to fight alone. We wanted cybersecurity to work the same way: instead of every device fighting malware from scratch, one device that solves a threat should immunize the whole globe instantly. T-Cell applies that biological model to endpoint defense, using a mesh network and blockchain as the "immune memory."
For our domain name, we chose t-cell.fishing because we thought it would be fun and fishing reminds of us phishing, which is where vulnerabilities that T-Cell eradicates can come from
What it does
T-Cell runs two castes per device: a Scout that watches process/file behavior in real time and scores it against known attack patterns, and a dormant Soldier that wakes only when a threat crosses the threshold. The Soldier isolates the threat, evolves a working "cure" (a sandboxed containment payload), and applies it, then self-terminates. Once verified, the cure is published to a Solana ledger and pushed instantly to paired local devices over a mesh network, so every other device inherits immunity without ever encountering the threat itself.
How we built it
The detection and response engine (Scout/Soldier) is written in Rust, consuming a native Endpoint Security telemetry and running cures inside a zero-import WebAssembly sandbox for safety. Verified cures are committed to a Solana devnet program (Anchor) behind a 3-of-5 multisig consensus check. The dashboard is an Electron + Vite + JavaScript app showing live telemetry and ledger activity, and DigitalOcean hosts our landing page/DMG downloads, a Postgres-backed advisor service, and a GPU-hosted local model that translates raw incidents into plain-language explanations.
Challenges we ran into
The hardest problem was teaching the Soldier to tell "malicious behavior" apart from "legitimate app doing something aggressive," freezing the wrong process breaks real work, so containment had to be precise and reversible. Getting two independent devices to reliably discover and pair with each other over a local network (without relying on infrastructure like mDNS) also took real trial and error.
Accomplishments that we're proud of
Getting the core detection-and-response loop actually working end-to-end, real telemetry, real scoring, real sandboxed cure, real on-chain commit, was the biggest win, since that's the whole premise the rest of the system depends on. We're also proud of the dashboard UI, which makes an otherwise invisible background process feel tangible and understandable.
What we learned
We came in wanting to build every stretch feature at once, and learned the hard way that scoping honestly and shipping a working core beats a half-finished pile of ambitious ones. We also learned a lot about working at the OS level, reading kernel-level telemetry, sandboxing untrusted code, without the safety net of cloud infrastructure to fall back on.
What's next for T-Cell
The natural next step is enterprise scaling: a per-location admin dashboard where IT teams can set policies once and forget them, with a manager view that aggregates alerts across every device and a full suite of recording/audit tools for compliance and incident review.

Log in or sign up for Devpost to join the conversation.