Findings & intelligence
Explore threat intelligence and CVE context
Navigate ATT&CK, threat actors, malware, CAPEC, indicators, and CVE relationships in Secorvia Threat Intelligence.
Reviewed
Before you start
Your plan must include the feature and the deployment must have synchronized threat intelligence data.
Choose the intelligence view
Open Threat Intelligence and select ATT&CK Techniques, Threat Actors, Malware, CAPEC, IOCs, or CVE Context. Choose the view that matches the investigation instead of treating every record as a detected incident.
Inspect an intelligence record
Review identifiers, descriptions, aliases, tactics, platforms, related techniques, and Last synced where provided. References describe the intelligence source; they do not establish that the actor or technique was observed in your environment.
Trace a CVE through its context
In CVE Context, enter a CVE identifier. The view relates weaknesses and CAPEC patterns to ATT&CK techniques, threat actors, and malware when those mappings exist. No context may mean the CVE or mappings are absent.
Distinguish searchable indicators from correlations
In IOCs, use indicator type filters. The current interface states that file hashes are searchable reference data, not matched against host activity. URL and IP indicators are correlated with runtime-agent telemetry. Use Runtime Security to investigate telemetry-linked findings.
Where you are now
You can use intelligence as investigation context without confusing catalog entries with observed activity.
WHEN SOMETHING LOOKS OFF
A few things to check
The catalog is empty
Ask a platform administrator to check the threat intelligence feed and worker status.
No threat context for a CVE
Confirm the identifier and check whether the catalog includes weakness mappings for it.
PUT IT INTO PRACTICE
Make your next move in Secorvia.
Open the app and follow along with your own organization.