Findings & intelligence

Explore threat intelligence and CVE context

Navigate ATT&CK, threat actors, malware, CAPEC, indicators, and CVE relationships in Secorvia Threat Intelligence.

Reviewed

Before you start

Your plan must include the feature and the deployment must have synchronized threat intelligence data.

Choose the intelligence view

Open Threat Intelligence and select ATT&CK Techniques, Threat Actors, Malware, CAPEC, IOCs, or CVE Context. Choose the view that matches the investigation instead of treating every record as a detected incident.

Inspect an intelligence record

Review identifiers, descriptions, aliases, tactics, platforms, related techniques, and Last synced where provided. References describe the intelligence source; they do not establish that the actor or technique was observed in your environment.

Trace a CVE through its context

In CVE Context, enter a CVE identifier. The view relates weaknesses and CAPEC patterns to ATT&CK techniques, threat actors, and malware when those mappings exist. No context may mean the CVE or mappings are absent.

Distinguish searchable indicators from correlations

In IOCs, use indicator type filters. The current interface states that file hashes are searchable reference data, not matched against host activity. URL and IP indicators are correlated with runtime-agent telemetry. Use Runtime Security to investigate telemetry-linked findings.

Where you are now

You can use intelligence as investigation context without confusing catalog entries with observed activity.

WHEN SOMETHING LOOKS OFF

A few things to check

The catalog is empty

Ask a platform administrator to check the threat intelligence feed and worker status.

No threat context for a CVE

Confirm the identifier and check whether the catalog includes weakness mappings for it.

PUT IT INTO PRACTICE

Make your next move in Secorvia.

Open the app and follow along with your own organization.

Open Secorvia