Take one, or take the set
Each module stands alone and each one feeds the others. Most clients start with the feeds and the portal, then add analysts once they know what they want asked.
Detection content
Rule packs your existing tools can load today
A curated library of YARA and Suricata rules covering malware families, APT tooling, web shells, exploits, packers and evasion techniques across Windows, Linux, macOS, Android and OT. Network rules cover botnet command and control, lateral movement, DDoS patterns, exploitation of infrastructure devices and known offensive tooling such as Mimikatz and Cobalt Strike.
Each detection is linked back to the actor and campaign it came from, so a hit is attribution rather than a filename.
Indicator feeds
Indicators that arrive scored, not raw
Continuous delivery of indicators for malware, phishing infrastructure, botnet controllers, DDoS sources and spam origins. Every indicator carries a score built from severity, likely impact on your environment and correlation with known adversary techniques, plus geolocation and MITRE ATT&CK mapping.
Indicators are separated into trusted, grey and malicious, so your team gets investigative depth instead of a blocklist that breaks a cloud provider.
Analyst portal
One place to look something up and get an answer
Query billions of indicators: hashes, addresses, domains, enriched with actor attribution, campaign links and risk scores. Submit a suspicious file for automated static and dynamic analysis in an isolated sandbox that detects evasion. Upload a packet capture and get lateral movement, exfiltration and exploitation surfaced against known indicators.
Role-based accounts for analysts, responders and leadership, with an API for anything you want to automate.
Advisory analysts
A named analyst, not a ticket queue
Dedicated threat intelligence analysts acting as an extension of your team: answering requests for information within an agreed SLA, monitoring for campaigns aimed at your sector and supply chain, attributing activity to specific actors, and writing the monthly briefing your board actually reads.
Standard response is eight to twelve hours. Premium is two to four for urgent requests during an incident.
Software supply chain
Your dependencies are somebody else’s attack surface
Continuous analysis of PyPI, npm and extension marketplaces including VSCode and Chrome, watching for malicious packages, dependency hijacking and typosquatted names. Findings are delivered in OSV format straight into your CI/CD pipeline, so a compromised package is blocked at build rather than discovered in production.
Package risk scoring uses obfuscation signals, domain registration anomalies and historical actor activity, with version history per library.
Three tiers, because blocking everything breaks the business
Generic feeds hand you one undifferentiated list. Indicators here arrive sorted, which is the difference between a control you can enforce and one you have to babysit.
Four weeks to useful, then it compounds
Onboarding
Scope agreed, feeds and portal access provisioned, connectors wired into your SIEM, EDR and pipeline. A named analyst is assigned if advisory is in scope.
Baseline
A first assessment against your environment: which actors target your sector, what your existing dependencies and detections already miss, and what to prioritise.
Operation
Daily rule and indicator updates, requests for information answered within SLA, and proactive alerts when something aimed at your sector appears.
Review
Scoring and focus refined against what proved useful, coverage extended to further ecosystems, and a strategic briefing for leadership.
Where the intelligence lands
SIEM
Indicators and rules become correlation content, which is the only place intelligence turns into an alert.
Managed SOC
Our analysts already work from this intelligence. Buying the SOC service includes it.
Incident response
Attribution during an incident changes the containment decision, not just the report.
