The following table defines the core terms used across the Cyber Threat Intel platform.
Term | Definition |
CTI | Cyber Threat Intelligence — the platform capability that monitors the threat landscape, filters signals based on your context, and surfaces actionable intelligence for security teams. |
Bulletin | The central CTI document. It consolidates everything known about a specific threat: summary, timeline, recommended actions, TTPs, CVEs, IoCs, and supporting sources. |
Threat Landscape | The daily command center in CTI. It shows what is affecting your environment, what is trending globally, and what requires immediate attention, based on your monitored technologies and assets. |
Monitoring Rules | Rules that automate threat tracking based on specific criteria such as technologies, malware, threat actors, geographic locations, sectors, and risk levels. |
IoC | Indicator of Compromise — a technical artifact (hash, IP address, domain) associated with malicious activity. Used to identify threats, validate suspicions, and enrich investigations. |
CVE | Common Vulnerabilities and Exposures — a standardized identifier for a specific publicly known software vulnerability. |
CVSS | Common Vulnerability Scoring System — a scale from 0.0 to 10.0 that measures the technical severity of a vulnerability. It does not indicate whether the vulnerability is actively exploited. |
EPSS | Exploit Prediction Scoring System — a 0–1 score estimating the probability that a vulnerability will be exploited in the next 30 days, based on machine learning and real-world data. |
TTP | Tactics, Techniques, and Procedures — the behaviors and methods used by threat actors to carry out attacks, classified according to the MITRE ATT&CK framework. |
Threat Actor | A group or individual responsible for a threat or attack. In CTI, each actor profile includes motivation, TTPs, targeted sectors, and links to related IoCs and CVEs. |
Confidence Level | A metric (Low, Medium, or High) indicating how trustworthy the classification of an IoC as malicious is, based on multi-source vendor analysis. |
Smart Search | A natural language search mode in the Bulletins area that generates AI-powered summaries based on real bulletins in the database, allowing exploration without predefined filters. |
STIX/TAXII | Standardized formats and protocols for sharing cyber threat intelligence between platforms. Used in the OpenCTI integration. |
MISP | Malware Information Sharing Platform — an open-source threat intelligence platform that can ingest Axur IoCs via Pull Feed integration. |
MSSP | Managed Security Service Provider — an organization that provides outsourced cybersecurity monitoring and management services. |
If you have any questions, feel free to reach out at [email protected] 😊
