The intelligence cycle · 3 of 6

Analysis

Your analysts work the intelligence — triaging it, questioning it, and mapping it against the frameworks they already use.


What you can do

  • Triage, per item or in bulk — Investigate, escalate, bookmark or dismiss, individually or across a selection, with escalations and investigations visible to the whole team.
  • Ask your intelligence questions — Chat scoped to your own reports and feeds. Every answer cites the sources behind it, and when your corpus cannot answer, it says so instead of inventing something.
  • Threats mapped to MITRE ATT&CK® — See which techniques are actually appearing in your intelligence, and which tactics your reporting is not touching.
  • Actors and connections — Threat actor profiles cross-referenced against MITRE ATT&CK® and MISP Galaxy, with relationships explorable on a link-analysis canvas.
  • Vulnerabilities, prioritised for you — CISA SSVC decisions over the KEV catalogue and EPSS scores, personalised through your requirements — a globally routine CVE can be an Act decision for you.
  • Reconstruct and rehearse — Record kill chains as intrusions actually unfolded, and build intelligence-grounded tabletop scenario documents from real reporting.

22/22

Answer-quality set

grounded, complete and correctly refused

0

Fabrications

across questions the corpus cannot answer

36/36

SSVC decisions

matching the published CISA truth table

A word about coverage

The ATT&CK view measures what has been observed in your intelligence. It is not a measure of defensive control coverage or detection readiness, and we will not present it as one — those are different claims, and conflating them is how a dashboard misleads the person relying on it.

The rest of the cycle

See it against your own requirements

The fastest way to judge an intelligence platform is to point it at what you actually need to know.

Contact Sales