Cyber threat intelligence
Evidence-based knowledge about existing or emerging cyber threats used to inform defensive decisions.
SOCs and CTI teams operationalise CTI feeds into detections, blocks and threat hunts.
Mandiant's APT1 report (2013) publicly attributed hundreds of intrusions to China's PLA Unit 61398 — the case study for modern CTI.
A live — tool is on the roadmap. In the meantime, explore the definition and application above.
RoadmapCheck whether an email/phone appeared in a public breach.
Google dork queries for exposed assets.
Search engine for internet-connected devices.
Automated OSINT reconnaissance framework.
Emails, subdomains and hosts from public sources.
Full-featured reconnaissance framework.
Fast subdomain enumeration.
RSS/OSINT feed aggregator with AI enrichment.
Information about adversaries, their capabilities, intent and opportunity to harm an organisation.
Intelligence derived from the surface, deep and dark web — forums, marketplaces and websites.
Leadership Intelligence refers to the discipline of gathering, analysing and applying information related to leadership, producing insight that supports decision-making.
Analysis of blockchain activity to identify wallets, flows and illicit behaviour.
Information about network traffic, topology and behaviour derived from telemetry.
Intelligence derived from decoy systems that attract and observe attackers.