⚡ Event / Incident
A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
Analysis
Sources
0
0 no-auth
Disciplines
0
that use it
Mission domains
0
reach
Workbench
—
native tool
🔗 Analyst pivots
🔍 Lookup
📜 Playbook — Event / Incident exploitation
- Direction — frame the requirement for Event / Incident: what decision does this support, by when?
- Collection — pull the 0 mapped sources (0 free) and the native workbench; capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
✨ Enrichment pathways
🎫 Event / Incident
An event / incident is a discrete, timestamped occurrence (breach, intrusion, outage, protest, kinetic or geopolitical event) associated with actors, locations, and indicators. It matters as the central correlation anchor that binds IOCs, TTPs, victims, and actors into a coherent timeline for attribution and response.
Format: Structured record: unique id, ISO 8601 timestamp/range, geo (lat/lon or ISO 3166), and a typed taxonomy code (STIX 2.1 object, MITRE ATT&CK technique, VERIS or ACLED event category)
📡 How it is collected
- SIEM / EDR alert ingestion
- CERT / CISA advisories
- OSINT and news feed monitoring
- Incident ticketing systems
- Threat-intel report parsing
- ACLED / GDELT event feeds
📚 Enrichment & validation sources
🔗 Pivot to
🧩 Analysis & hunting techniques
- Timeline reconstruction
- MITRE ATT&CK TTP mapping
- Cross-IOC correlation
- Actor attribution (Diamond Model)
- Kill-chain / cyber kill chain analysis
- Geospatial event clustering
- Confidence scoring and de-confliction
- Related-event graph linking
🔧 Tools
- MISP
- TheHive
- Timesketch
- MITRE ATT&CK Navigator
- OpenCTI
- Maltego
- Elastic SIEM
⚡ Workbench actions
- Build timeline
- Map ATT&CK TTPs
- Correlate IOCs
- Attribute actor
- Geo-plot event
- Link related events
- Export STIX bundle
- Generate incident report
📊 Dashboard KPIs
Linked IOC countAttribution confidenceDwell timeAffected asset countRelated-event count
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron