ThreatPop provides an interactive cyber threat discovery, investigative, and visualization experience for security analysts and network operators. ThreatPop allows an analyst to visualize attacks that have occurred in support of retrospective analysis by enabling the ability to visually replay attacks that have transpired within a specified timeframe. ThreatPop uses machine learning algorithms combined with a complex data flow processing capability to reduce the workflow of identifying cyber threats in complex data.