Skip to content

Platform / Detect

Threat Intelligence

We track the crews operating against your sector, your suppliers and your brand — their infrastructure, tooling, staging domains and timing — and convert it into detections your SOC can deploy the same day.

1,400+

adversary infrastructures under continuous track

What you receive

  • Named adversary profiles mapped to MITRE ATT&CK
  • Collection from dark web and closed criminal forums
  • Pre-attack infrastructure detection and staging-domain alerts
  • STIX/TAXII feed into your existing SIEM
  • Quarterly sector threat briefing for your board

When you need this

Three situations that call for it. If none of them is yours, it probably is not the right spend.

  • 01

    A peer in your sector was breached last month

    The same crew rarely stops at one target — infrastructure, lures and tooling get reused across a sector for months. Knowing which group it was, and what they staged before they moved, tells you which detections to write this week.

  • 02

    Your SIEM runs on vendor default rules

    Default correlation rules catch commodity malware and little else. Adversary tradecraft mapped to ATT&CK gives your detection engineers something specific to write against — the loader, the beacon interval, the staging-domain pattern.

  • 03

    You are expanding into a new region

    Threat models do not travel. A crew that ignores your home market may run banking trojans, mobile fraud or hacktivist defacement in the one you are entering, and the language of the lure matters as much as the malware family.

How it runs

  1. 01

    Scoping call

    Thirty minutes with an engineer. We establish what you already run, where the gaps actually are, and whether a module earns its place beside your existing tooling.

  2. 02

    Connect and baseline

    We connect the data sources the module reads and spend the first weeks learning what normal looks like in your estate. Tuning against your traffic is what stops the alerts being noise.

  3. 03

    Go live

    The module starts writing to the adversary graph and escalating to you. Escalation routes, thresholds and who gets woken at 03:00 are agreed in writing beforehand.

  4. 04

    Continuous review

    A standing review of what fired, what did not, and what changed in your estate. A detection set that is not revisited decays — the attacks move even when your systems do not.

No lock-in

Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.

Who turns up

The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.

Scope

What this does not cover

  • Intelligence tells you who and how — it does not watch your estate; continuous monitoring of your own telemetry is Managed XDR.

  • We do not take down the adversary infrastructure we report on; domain and impersonation takedown sits under Brand Protection.

  • This is not a scan of your own environment — external exposure discovery belongs to Attack Surface Management.

Measured against

STIX 2.1 and TAXII 2.1 (OASIS)
OASIS standards for expressing and transporting threat intelligence, so a feed reaches your SIEM without bespoke parsing.
FIRST Traffic Light Protocol 2.0
Defines TLP:CLEAR, GREEN, AMBER, AMBER+STRICT and RED, which set how far a report may be passed on — AMBER+STRICT stops at your own organisation, RED at the people it was given to.
MITRE ATT&CK
A catalogue of observed adversary techniques; mapping to it is what turns a narrative report into a detection backlog.

If the scope is wrong

Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.

Questions

The ones we are actually asked.

Is this just another IOC feed we will never read?

No, but the risk is real — indicators decay within days and a feed nobody actions is a cost, not a control. We agree intelligence requirements first and report against those in STIX, so the output is machine-readable rather than a PDF somebody has to retype.

How confident is attribution, really?

Attribution is a judgement with a confidence level attached, not a fact. We state the confidence and the evidence behind it, and where the evidence supports only a cluster rather than a named group, we say cluster.

Can you tell us we are about to be attacked?

Sometimes — staging infrastructure, a domain registered against your brand or credentials appearing for sale are all pre-attack signals. Often not: plenty of intrusions begin with an exposed service and no warning at all.

Next step

See what an attacker sees

We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.