From narrative to technique
Prose descriptions of attacker behaviour become mapped techniques, which makes two reports about the same activity comparable for the first time.
Threat Intelligence Mapper takes raw reporting and returns something a defender can act on. Mapped techniques, sector relevance, and a short answer to whether this changes anything for the organisation reading it.
Security teams receive far more intelligence than they can act on. The bottleneck is almost never collection. It is the translation from what somebody observed somewhere into what this organisation should check this week.
Prose descriptions of attacker behaviour become mapped techniques, which makes two reports about the same activity comparable for the first time.
Relevance depends heavily on who you are. The same campaign can be urgent for one sector and irrelevant to the one next door.
The useful output is a check. If this behaviour reached our environment, which control would have stopped it, and are we confident that control is working.
A mapped technique is only half an answer. The other half is which control was supposed to cover it and whether that control has been confirmed recently, which is where the platform work joins up.
This is the thread that runs from here into ControlGraph, and it is why threat informed prioritisation sits on the CyberNexus direction of travel rather than in a separate tool.
A threat report that ends without a check to run has told you about the weather. It has not helped you decide whether to leave the house.
Four steps, each of which throws away the part you did not need, so that what reaches a defender is small enough to act on.
Vendor reporting, advisories, sector notices and research, in whatever shape they turn up in.
Prose descriptions become recognised technique references, which is the first point at which two reports about the same activity become comparable.
Relevance depends heavily on who you are. The same campaign can be urgent for one sector and irrelevant next door.
Which control was supposed to cover this, and whether anybody has confirmed it lately. A summary that ends in a check rather than a worry.
The questions that come up most often, answered the way we would answer them on a call.
No, it sits after them. Feeds are the input. The value is in the translation from what somebody observed somewhere to what this organisation should check this week.
A short piece of reporting that ends in a check. Which technique, whether it is relevant to your sector, which control was meant to cover it, and whether that control has been confirmed recently.
Yes. Mapping behaviour to a recognised reference is what makes two reports about the same activity comparable, which is the first thing that has to be true before anything else is useful.
A mapped technique is half an answer. The other half is whether the control that was supposed to stop it is currently working, which is the join ControlGraph and CyberNexus are built to hold.
That is usually a translation problem rather than a sourcing problem, and it is a solvable one.