Skip to content
crafted signal

01 · Risk

Risk Modeling

Turn business services, crown-jewel data, attack paths, threats and findings into risk-scored detection priorities your SOC can defend.

CraftedSignal coverage view showing exposure and detection depth
  1. 01 Start with manual input, regular imports, or a plain-text asset description.
  2. 02 ATT&CK techniques, telemetry and findings are weighted by exposure, not counted equally.
  3. 03 Risks flow into Backlog items, hunts, detections, reports, and audit trails.

Outcomes

What this changes for the team.

Decision

Which gap matters next

Prioritize detections by business exposure, threat relevance and telemetry coverage instead of rule count, vendor heatmaps, or the loudest alert queue.

Context

One operating model

Services, data, attack paths, findings, residual risk, and mitigation state live in the same platform analysts use.

Proof

Reports write themselves

Coverage, accepted gaps, Backlog decisions, hunts, and rule changes are tied back to the risks they reduce.

The problem

Most SOC planning starts too far downstream. Teams know how many rules they have, which ATT&CK cells are colored, and which SIEM alerts are noisy. They often do not know which business service those rules protect, which data asset is still exposed, whether a new threat actually affects them, or why one missing detection should outrank the next.

That creates a familiar operating gap: risk teams talk about crown jewels and attack paths, while detection engineers talk about queries, fields, and false positives. Audits then become spreadsheet exercises because the system of record for detection work is not connected to the system of record for business exposure.

How CraftedSignal models risk

CraftedSignal starts with the business surface the SOC is defending. You declare services, data assets, and attack paths manually, from regular imports, or from a plain-language asset description when no CMDB exists. Each path maps to attacker techniques and the platform weights those techniques by exposure. A technique on a crown-jewel path is treated differently from the same technique on a low-value path.

Coverage is tracked across the layers where detection actually happens: endpoint, network, identity, cloud, email and application telemetry. That prevents a generic “covered” answer when only one telemetry layer has a rule and the real attack path still has gaps.

From model to work queue

Accepted attack paths become operational risks. Each risk has a state, owner, priority score, coverage, and timeline. Analysts can hunt it, accept residual risk, escalate it, schedule re-hunts, or link it to rules that reduce the exposure.

The important shift is that risk is not a PDF attached to a ticket. It is a live object that can create Backlog work, create hunts, explain why a rule exists, and show whether the detection program is closing the right gaps.

Threat Intake sits just before this risk lifecycle. SOC reviewers can accept candidate threats that need detection, hunting, simulation, or validation work and dismiss candidates that do not apply. The default is no threat, no work, except urgent verification for actively exploited critical exposure the platform cannot rule out.

What the SOC gets

Detection engineers get a ranked Backlog that explains why a rule matters. SOC leaders get coverage reporting that separates real risk reduction from activity metrics. CISOs get an answer to “are we protected against this path?” that points to active detections, known blind spots, missing telemetry, residual decisions, and work in progress.

The model also gives threat intelligence and findings a place to land. When a new brief, critical CVE, pentest finding, or future CTEM input arrives, CraftedSignal scores it against the services, technologies, telemetry, rules and paths already known instead of treating every advisory as equal.

Related docs

Go deeper in the technical docs.

Next feature sets

Follow the loop.

View all solutions