Skip to main content

Cyber Threat Intel (CTI)

What CTI is and how to get started

Cyber Threat Intelligence (CTI) is the platform's cyber threat intelligence capability. In practice, it works like a radar that monitors the threat landscape, identifies attacks, vulnerabilities, and relevant signals, and cross-references all of that with your context to highlight what matters most to your monitored environment.

The main difference between CTI and a generic security news feed is that CTI does not simply show what is happening in the world. It filters threats based on the technologies your organization uses, the assets you monitor, your industry, and other contextual criteria, turning information volume into actionable intelligence.

CTI is designed for cybersecurity teams and MSSPs that need to operate in a constantly changing threat landscape. Its value lies in aggregating, synthesizing, and filtering information from hundreds of trusted sources so that the output is relevant and usable for response and prioritization.


The first step: add technologies and assets

Before any analysis begins, CTI needs to understand what makes up your environment. That is why the first step is to add the technologies you want to monitor. Without this initial setup, Threat Landscape has no basis to determine relevance and may appear empty or indicate that no technologies are being monitored.

To add technologies, go to Monitored Assets, click Add Asset, select Technologies, and enter the relevant technology names separated by commas. Existing lists can also be copied from files such as CSV, as long as the entries remain comma-separated.

In addition to technologies, the platform also lets you add hosts, such as domains and subdomains. In that case, CTI analyzes the exposed surface and retrieves information such as the associated IP address, open ports, running services, known vulnerabilities, and certificates in use.

Once technologies and assets are configured, Threat Landscape stops being generic and starts reflecting your actual context, showing relevant mentions, threats associated with your monitored stack, highlighted vulnerabilities, and active threat actors connected to the analyzed environment.


How Threat Landscape works

After the initial setup, Threat Landscape becomes the daily command center for CTI. It organizes the view of the threat landscape and helps answer, at a glance, what is affecting your environment, what is trending globally, and what requires immediate attention.

Its main blocks include a time-saved summary, which quantifies effort saved by avoiding scattered news reading; the monitored assets impacted indicator, which shows the percentage of your assets already mentioned in bulletins; Trending CVEs, which highlight vulnerabilities that are trending and actively exploited; and lists of the most active threat actors, malwares, and TTPs.

The Threat Landscape is controlled by three main filters:

  • Trending in — defines the analysis period, such as 7, 15, or 30 days.

  • Related to — lets you switch between my technologies, to focus on what affects your environment, and the whole world, to view the global threat landscape.

  • Within — narrows the view by sector or industry, such as finance, education, retail, or healthcare.

These filters make CTI more flexible. They let you investigate what affects your assets directly, understand broader security trends, or monitor threats affecting companies in your sector even before they directly impact your environment.


AI-generated period summaries

The Generate summary button creates an automated summary of bulletins for a specific period. Available options include today, yesterday, two days ago, last week, and last month, always combined with the same scope selection between my technologies and the whole world.

This feature is useful when the goal is not to investigate item by item, but to quickly obtain a daily, weekly, or period-based summary. In practice, it answers the question: what do I need to know today?


Monitoring rules

Checking Threat Landscape every day may work in smaller environments, but CTI offers a more scalable mechanism through Monitoring Rules. These rules automate threat tracking based on specific criteria.

Rules can combine multiple criteria such as monitored technologies and assets, specific malware, threat actors, geographic locations, industry sectors, threat types, and risk levels.

CTI already includes default rules to illustrate common use cases:

  • Threats to my technologies — focused on threats related to your monitored stack.

  • Threats targeted at specific industries and locations — focused on sectors and geography.

  • Specific threat actor activity — focused on following particular threat actors.

The existence of a rule alone does not mean notifications are active. To start receiving alerts, you must actively follow the rule. You can also edit or remove default rules that do not fit your context or create new ones from scratch.

Rules can be broad or highly specific. For example, you can create recurring rules for strategic topics and, at the same time, targeted rules for CVEs, countries, campaigns, or combinations such as a country, a threat type, and a specific severity level.


Notification channels

Following a rule defines what you want to monitor, but it does not determine how the alert is delivered. For that, you need to configure channels in notification preferences.

You can choose channels such as WhatsApp and email. If you choose WhatsApp, you also need to register a phone number.

Without at least one configured channel in the Monitoring Rules section, following a rule does not generate actual notifications.


How to follow bulletins

The Bulletins you follow area gathers the bulletins you are tracking. A bulletin can appear there automatically when it matches a followed monitoring rule or manually when you star it during an investigation.

Once you follow a bulletin, you begin receiving alerts when new IoCs or CVEs related to that bulletin are identified.

Following or unfollowing a bulletin affects only your own account and is not applied company-wide.


How to explore threats

In many cases, you may want to explore the dataset freely to understand what is happening. That is what the Bulletins area is for: it serves as the central repository of all bulletins on the platform.

This exploration can happen in two ways:

  • With Smart Search enabled — you can ask questions in natural language, and CTI generates a summary based on real bulletins in the database.

  • With Smart Search disabled — the interface returns to a traditional table view, with filters for severity, threat actor, malware, CVE, and other fields.

Both modes coexist and support different investigation moments. Smart Search is useful when you start from a question; filtered exploration is better when the goal is to browse the database and progressively narrow the focus.


How to investigate technical evidence

When a bulletin points to something relevant, CTI offers dedicated investigation areas for IoCs, CVEs, and Threat Actors.

  • IoCs — gathers indicators of compromise such as hashes, IPs, and domains. You can use confidence score, tags, type, and detection date to narrow the volume of evidence.

  • CVEs — gathers vulnerabilities and allows filtering by CVSS, EPSS, exploitation status, affected systems, threat type, and overall status. The Exploitation: Active filter isolates issues that are actively being exploited.

  • Threat Actors — shows the groups behind the threats, including motivation, TTPs, and a history of targeted sectors and organizations. Tabs inside each actor profile connect directly to related IoCs, TTPs, and CVEs.


What a bulletin contains and how the intelligence behind it is built

A bulletin is the central CTI document. It brings together, in one place, everything known about a specific threat, including a summary, timeline, recommended actions, techniques used, associated vulnerabilities, technical evidence, and supporting sources.

What a bulletin contains

At the top of the bulletin, there is a set of elements that helps quickly establish the relevance and context of the threat. These include the severity badge, category tags, title, creation and last-updated dates, the Follow button, and the Copy link option.

Severity can appear as Critical, High, Medium, or Low, signaling the priority of the threat. Category tags identify the type of attack involved, with examples such as CyberAttack, DataBreach, ExploitAttacks, InjectionAttacks, SocialEngineering, and RansomwareAttack.

Creation and update dates help interpret how the case evolved. A bulletin created on one date and updated months later indicates that the threat is still being tracked and that the document remains live over time.

The Copy link option generates a public link for sharing the bulletin. Anyone opening the link without authentication can view the bulletin but cannot access the technical CVE and IoC data. Unlike a screenshot or exported PDF, this link points to the live bulletin — if the timeline is updated after the link is shared, the recipient sees the latest version.


Bulletin tabs

The tabs shown in a bulletin vary depending on what was identified for that threat:

  • Overview — answers the question: what is happening and how has it evolved?

  • What to do — answers: what should be done about it?

  • TTPs — details the attack techniques involved.

  • CVEs — shows which vulnerabilities are being exploited.

  • IoCs — gathers technical evidence such as hashes, IPs, and domains.

  • Sources — shows where the underlying information came from.

Bulletins with many updates, many TTPs, and many sources usually indicate active and evolving threats, making them strong candidates for continuous follow-up.


How the intelligence behind a bulletin is built

The process starts with continuous collection. The platform monitors thousands of sources, such as news, security reports, investigations, vulnerability databases, forums, and specialized channels, looking for threat signals around the clock.

Then comes correlation. Signals from different sources that point to the same event are automatically cross-referenced. IoCs, TTPs, actors, CVEs, and targeted sectors are connected to determine whether what is being observed is an isolated event or part of a broader campaign.

Next comes AI enrichment. At this stage, the raw information is organized into a structured and actionable format, with a summary, techniques used, associated vulnerabilities, affected sectors and regions, and response recommendations.

Speed is also a key aspect: new bulletins can be published just minutes after the initial signal is identified, and they continue to be updated over time as new information about the same threat emerges.

In practice, a bulletin is the result of an intelligence pipeline that combines multiple sources, automated correlation, AI enrichment, and human curation.


Examples of technologies you can add for monitoring

The following are examples of technologies that can be added for monitoring, grouped by category. This list is illustrative — any technology name can be entered as long as it matches how it is commonly referenced in security reports and threat databases.

Operating systems

  • Windows

  • Windows 11

  • Windows Server 2022

  • macOS

  • macOS Big Sur

  • Linux

  • Ubuntu

  • Red Hat Enterprise

  • FreeBSD

  • Android

Browsers

  • Edge

  • Chrome

  • Firefox

  • Safari

Business applications

  • Microsoft Office

  • Microsoft 365

  • Google Workspace

  • Adobe Acrobat

  • SAP

  • Oracle

  • Teams

  • Slack

  • Zoom

  • PowerBI

Key partners

  • Google

  • Microsoft

  • Meta

  • Apple

  • IBM

  • Salesforce

  • Deloitte

  • Cloudflare

Network infrastructure

  • Cisco

  • Juniper

  • Fortinet

  • F5

  • Palo Alto

Databases

  • Oracle Database

  • Microsoft SQL

  • MySQL

  • PostgreSQL

  • MongoDB

  • Elasticsearch

Cloud

  • AWS

  • Azure

  • GCP

Containers

  • Docker

  • Kubernetes

Other

  • iPad

  • iPhone

  • Apache

  • ChatGPT

  • GitHub


If you have any questions, feel free to reach out at [email protected] 😊

Did this answer your question?