Skip to content
crafted signal

02 · Threat

Threat Intelligence

Convert threat briefs, IOCs, Sigma rules, CVEs and ethical hack findings into risk-scored Backlog work, hunts and detections.

CraftedSignal dashboard showing risk and coverage context
  1. 01 Curated briefs include rules, tests, IOCs, runbooks, playbooks, ATT&CK mappings and affected products.
  2. 02 Relevance is calculated against your business surface, technology stack, telemetry and rules.
  3. 03 Briefs can be marked affected, marked not affected, adopted, hunted, watchlisted, dismissed, or mirrored for air-gapped use.

Outcomes

What this changes for the team.

Triage

Less feed noise

Threat intel is filtered by what you run, what you can observe and what your business model says is exposed.

Action

Briefs become work

A relevant brief can create Backlog work, start a hunt, suggest a rule, connect to a risk, or enter a watchlist.

Reuse

Community content stays portable

Open Sigma, SPL and KQL content can be deduplicated, tested and adapted to local telemetry.

The problem

Threat intelligence is easy to collect and hard to operationalize. Feeds deliver a constant stream of campaigns, indicators, techniques, vendor advisories and ready-made detections. Most teams still have to answer the same questions manually: does this affect us, can our telemetry see it, are we already covered, and should we hunt before we deploy a rule?

Ethical hack and red-team findings create the same problem in another form. The finding is valuable, but it often stays trapped in a report. The SOC needs a bridge from “this path worked” to “we hunted for it, wrote a rule, tested it, deployed it and measured it.”

How CraftedSignal handles intelligence

CraftedSignal treats a threat brief as a package of usable detection work. A brief can include narrative, affected vendors and products, CVEs, IOCs, MITRE ATT&CK techniques, suggested Sigma rules, suggested hunts, tests, runbooks, playbooks and actor metadata.

The platform scores every brief against your business surface, telemetry and current rules. Modeled services, data assets, attack paths, operating systems, vendors, products, known log sources and existing detections all influence whether the item is urgent, useful, or noise.

From brief to detection work

Analysts can mark whether the threat affects them, adopt suggested rules, start a hunt, link the brief to an existing risk, watchlist it, or dismiss it with a recorded reason. When a brief includes runbooks or playbooks, those response steps move with the adopted rule or hunt instead of being left behind in the feed. A threat that is relevant but not ready for a permanent rule can become a hunt first. A threat that maps to a critical path can raise priority on an existing risk.

This keeps the feed connected to the rest of the platform. Intelligence is not a separate work queue; it becomes Backlog, hunts, rules and coverage evidence when there is work to do.

Public and private sources

CraftedSignal supports curated platform briefs and a public derivative feed at feed.craftedsignal.io. The community library can bring open detection content into the workflow, where it is deduplicated and tested before it becomes production coverage.

For regulated or isolated environments, signed bundles can be mirrored into an internal deployment. The same relevance and adoption workflow still applies, but outbound internet access is not required.

Related docs

Go deeper in the technical docs.

Next feature sets

Follow the loop.

View all solutions