Indicators
One referential for every indicator you assert, with an approval lifecycle and delivery to the tools that act on them.
Features
- One indicator per value, citing every record it came from: phishing reports, incidents, alerts or manual entry.
- A lifecycle of held, approved, published, rejected and withdrawn.
- Withdrawing an indicator never rewrites the records that cited it.
- Published indicators can be pushed to MISP through a connector.
Other modules
- Vulnerability alertsPublish vulnerability alerts to your entities, collect their exposure answers and track patching deadlines.
- Cyber incidentsAn incident registry with impact matrix, taxonomies, response times and a reconstructed story of each incident.
- Cyber weatherOne weather icon per organization that sums up current security tension, computed from incidents and alerts with rules you set.
- AssetsA referential of domains, IP ranges, brands and technologies, linked to the organizations that own or operate them.
- Phishing reportsReceive reported emails, inspect them safely, extract observables and group near-identical mails into clusters.
- Phishing campaignsJoin clusters into campaigns by shared infrastructure and spot unusual spikes and recurring waves.
- ReportsReports built from your metrics, rendered to PDF and delivered on a schedule, each reader seeing only what they may read.
- CatalogPublish tools, services, policies and training to your organizations, organized by a taxonomy you define.
- RequestsUsers ask for access or for a change they cannot make themselves, reviewers approve, and the change applies on approval.
- DocumentsMarkdown documents kept per organization, with archive and permissions.
- DashboardsDrag-and-drop dashboards with charts over your security data, shared per user, per organization or globally.
- ConnectorsConnect MISP, Slack, DNS checks and outbound webhooks, with stored credentials encrypted and health checked.