Skip to main content

Threat Intelligence

THREAT LANDSCAPE

Where adversaries operate, and what that means for you

A globe drawn from the intelligence, not from a stock map.

One globe, two views. The world as the intelligence describes it, then your own estate on the same sphere, with your findings ranked by the threat behind them.

Two views, one globe

The world, then your estate.

The switch sits above the globe. Nothing else about the page changes shape, so you never lose your place.

01

World view

Every country the intelligence names as an origin, every country being targeted, and the arcs between them.

02

Organization view

The same globe over your own sites and systems, with your open findings ordered by the threat behind them.

What one country tells you

Click a marker and the callout pins to it.

Ask Alloy answers from this same payload, so a question about an origin or an actor costs nothing extra.

Arcs are rate limited on purpose. Every arc drawn at once is a picture of nothing.

Volume

CVE count, how many are known exploited, and the worst CVSS in the set.

Who

The actors attributed to that origin, and the MITRE group where one is matched.

How

A kill chain strip showing which ATT&CK stages the activity covers, from a vendored ATT&CK index.

How likely

An exploitable share meter and an average EPSS meter, so a large count and a dangerous one are not confused.

Your side of it

Turn the globe on your own estate.

01

A ranked worklist

Your open findings ordered by the threat behind them rather than by how many there are.

02

Where your machines are

Sites resolved from your own inventory. Click one and the globe flies to it.

03

Fixes, not findings

Findings grouped by the single fix that closes them, ranked by threat, and handed to the sprint board.

04

How current it is

Every count says how old the data behind it is, read from the source's own last seen date.

A minute with it

The whole thing, end to end.

Recorded on the synthetic showcase dataset. No customer data appears.

Where the boundaries are

Two halves, two different sources.

  • The world view is intelligence
  • It is not a live attack feed. There is no telemetry of attacks in progress behind it.
  • Country attribution covers the subset of CVEs the intelligence attributes, not every CVE.
  • Nothing in this half is drawn from your scan data.
  • The organization view is yours
  • This half is your data: your sites, your systems, your open findings.
  • The two are joined by the same ATIP corpus that feeds exploitation weighted ranking.
  • So the globe says what is in play, and then what it means for you.

What it costs

One cached payload every five minutes, and the rest runs in the browser.

  • Land

    A dot matrix of 10,921 points, rotated with plain arithmetic. The projection is tested against d3 over thousands of random points.

  • Drawing

    Two canvases, cached layers, and a frame monitor that drops effects on its own when drawing gets expensive.

  • Server

    One cached, gzipped payload every five minutes. Everything else is client side.

See it turning, on your own intelligence.

The globe reads whichever intelligence source you point it at, and the organization view reads whichever scanner you already run.