Threat Intelligence
Connect indicators, behavior and exposure to sources that can be checked.
IOC tracking
Hashes, domains, IPs and technical artifacts. Every indicator needs a source, timestamp and context.
View detailsTTP map
Examine the sequence from initial access to data theft, encryption and disruption.
View detailsExposure Watch
CVEs, exposed services and management layers to review in enterprise infrastructure.
View detailsRansomware families
Behavioral profiles, extensions, ransom notes and variants; do not assign a family from extensions alone.
TTPs and entry paths
Track vulnerability exploitation, credentials, RDP/VPN and lateral movement.
From intelligence to hunting
Use indicators within their context, timeframe and confidence level.
Look up IOCsPreventive measuresIndicators expire
IPs and domains can change ownership. Historical data is not a current blocklist.
Behavior needs evidence
TTPs are a comparison framework. Do not mark a stage as observed without supporting data.
Exposure requires an inventory
A CVE's existence does not establish that every system using the product is affected.