Threat Intelligence
THREAT LANDSCAPEWhere adversaries operate, and what that means for you
A globe drawn from the intelligence, not from a stock map.
One globe, two views. The world as the intelligence describes it, then your own estate on the same sphere, with your findings ranked by the threat behind them.
Two views, one globe
The world, then your estate.
The switch sits above the globe. Nothing else about the page changes shape, so you never lose your place.
01
World view
Every country the intelligence names as an origin, every country being targeted, and the arcs between them.
02
Organization view
The same globe over your own sites and systems, with your open findings ordered by the threat behind them.
What one country tells you
Click a marker and the callout pins to it.
Ask Alloy answers from this same payload, so a question about an origin or an actor costs nothing extra.
Arcs are rate limited on purpose. Every arc drawn at once is a picture of nothing.
Volume
CVE count, how many are known exploited, and the worst CVSS in the set.
Who
The actors attributed to that origin, and the MITRE group where one is matched.
How
A kill chain strip showing which ATT&CK stages the activity covers, from a vendored ATT&CK index.
How likely
An exploitable share meter and an average EPSS meter, so a large count and a dangerous one are not confused.
Your side of it
Turn the globe on your own estate.
01
A ranked worklist
Your open findings ordered by the threat behind them rather than by how many there are.
02
Where your machines are
Sites resolved from your own inventory. Click one and the globe flies to it.
03
Fixes, not findings
Findings grouped by the single fix that closes them, ranked by threat, and handed to the sprint board.
04
How current it is
Every count says how old the data behind it is, read from the source's own last seen date.
A minute with it
The whole thing, end to end.
Recorded on the synthetic showcase dataset. No customer data appears.
Where the boundaries are
Two halves, two different sources.
- The world view is intelligence
- It is not a live attack feed. There is no telemetry of attacks in progress behind it.
- Country attribution covers the subset of CVEs the intelligence attributes, not every CVE.
- Nothing in this half is drawn from your scan data.
- The organization view is yours
- This half is your data: your sites, your systems, your open findings.
- The two are joined by the same ATIP corpus that feeds exploitation weighted ranking.
- So the globe says what is in play, and then what it means for you.
What it costs
One cached payload every five minutes, and the rest runs in the browser.
-
Land
A dot matrix of 10,921 points, rotated with plain arithmetic. The projection is tested against d3 over thousands of random points.
-
Drawing
Two canvases, cached layers, and a frame monitor that drops effects on its own when drawing gets expensive.
-
Server
One cached, gzipped payload every five minutes. Everything else is client side.
Threat Intelligence
Also in this area
Understand active threats and adversary behavior
How it all fits togetherAvint Threat Intelligence Platform
ATIPA daily refreshed corpus of 370,000 CVEs enriched with actors, malware, exploits and ATT&CK.
Agile Risk Enumeration Algorithm
AREAExploitation weighted scoring, tiering and sprint planning. Deterministic core, AI explains.
CVE to MITRE ATT&CK Mapping
CVE to ATT&CKEvery vulnerability read as adversary tactics and techniques, not just a severity number.
See it turning, on your own intelligence.
The globe reads whichever intelligence source you point it at, and the organization view reads whichever scanner you already run.