Skip to main content

Key concepts glossary—Cyber Threat Intel (CTI)

The following table defines the core terms used across the Cyber Threat Intel platform.

Term

Definition

CTI

Cyber Threat Intelligence — the platform capability that monitors the threat landscape, filters signals based on your context, and surfaces actionable intelligence for security teams.

Bulletin

The central CTI document. It consolidates everything known about a specific threat: summary, timeline, recommended actions, TTPs, CVEs, IoCs, and supporting sources.

Threat Landscape

The daily command center in CTI. It shows what is affecting your environment, what is trending globally, and what requires immediate attention, based on your monitored technologies and assets.

Monitoring Rules

Rules that automate threat tracking based on specific criteria such as technologies, malware, threat actors, geographic locations, sectors, and risk levels.

IoC

Indicator of Compromise — a technical artifact (hash, IP address, domain) associated with malicious activity. Used to identify threats, validate suspicions, and enrich investigations.

CVE

Common Vulnerabilities and Exposures — a standardized identifier for a specific publicly known software vulnerability.

CVSS

Common Vulnerability Scoring System — a scale from 0.0 to 10.0 that measures the technical severity of a vulnerability. It does not indicate whether the vulnerability is actively exploited.

EPSS

Exploit Prediction Scoring System — a 0–1 score estimating the probability that a vulnerability will be exploited in the next 30 days, based on machine learning and real-world data.

TTP

Tactics, Techniques, and Procedures — the behaviors and methods used by threat actors to carry out attacks, classified according to the MITRE ATT&CK framework.

Threat Actor

A group or individual responsible for a threat or attack. In CTI, each actor profile includes motivation, TTPs, targeted sectors, and links to related IoCs and CVEs.

Confidence Level

A metric (Low, Medium, or High) indicating how trustworthy the classification of an IoC as malicious is, based on multi-source vendor analysis.

Smart Search

A natural language search mode in the Bulletins area that generates AI-powered summaries based on real bulletins in the database, allowing exploration without predefined filters.

STIX/TAXII

Standardized formats and protocols for sharing cyber threat intelligence between platforms. Used in the OpenCTI integration.

MISP

Malware Information Sharing Platform — an open-source threat intelligence platform that can ingest Axur IoCs via Pull Feed integration.

MSSP

Managed Security Service Provider — an organization that provides outsourced cybersecurity monitoring and management services.


If you have any questions, feel free to reach out at [email protected] 😊

Did this answer your question?