💻 Cyber Intelligence (CYBINT)
Adversary Activity in Networks and Systems
Cyber & Threat
Sources
0
0 no-auth
Mission domains
0
reach
Data points
0
covered
Related INT
0
disciplines
🔍 Lookup
📊 Pre-built Queries · Cyber Intelligence
📜 Playbook — Cyber Intelligence collection
- Direction — frame the requirement for Cyber Intelligence: what decision does this support, by when?
- Collection — collect from the 0 mapped sources (0 free) — filter the catalog by CYBINT; capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
✨ Enrichment pathways
🎯 Mission
Cyber Intelligence tracks threat actors, campaigns, tooling, and indicators of compromise, mapping adversary behavior to a common framework of tactics and techniques. It answers who is targeting the organization, what TTPs and tooling they use, and which indicators and known-exploited vulnerabilities demand immediate defensive action.
📡 Collection methods
- Aggregating and deduplicating IOC feeds from open and community threat-sharing platforms
- Mapping observed adversary behavior to MITRE ATT&CK techniques and building actor TTP profiles
- Tracking threat-actor campaigns and infrastructure across reporting and telemetry
- Correlating CISA KEV and exploited-CVE data against the organization's asset inventory
- Sandbox and OSINT enrichment of indicators to add context and confidence scoring
- Sharing and consuming structured intel via STIX/TAXII and MISP communities
📚 Key sources & datasets
🎫 Data points produced
🔧 Tools & frameworks
- MISP
- OpenCTI
- ATT&CK Navigator
- YARA
- TheHive
- Yeti
- STIX/TAXII
- Sigma
📜 Cyber Intelligence Tradecraft
- Collect IOCs and campaign reporting from feeds, sharing communities, and OSINT filtered to relevant sectors and geographies
- Normalize indicators, enrich with WHOIS/passive-DNS/sandbox context, and score confidence and false-positive risk
- Analyze clustered indicators and behaviors against ATT&CK to characterize the campaign's objectives and kill-chain stage
- Attribute activity to a named actor or cluster using TTP overlap, infrastructure reuse, and diamond-model pivots
- Disseminate finished intelligence, detection rules (YARA/Sigma), and priority-intelligence-requirement answers to defenders
- Push high-confidence indicators to blocking and detection controls and measure hits to validate and retire them
📊 Dashboard KPIs
Active campaigns trackedIOCs ingestedKEV exposureActor coverageDetection rules deployed
🔍 Pre-built queries
🔗 Cross-discipline pivots
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron