02 · Threat
Threat Intelligence
Convert threat briefs, IOCs, Sigma rules, CVEs and ethical hack findings into risk-scored Backlog work, hunts and detections.

- 01 Curated briefs include rules, tests, IOCs, runbooks, playbooks, ATT&CK mappings and affected products.
- 02 Relevance is calculated against your business surface, technology stack, telemetry and rules.
- 03 Briefs can be marked affected, marked not affected, adopted, hunted, watchlisted, dismissed, or mirrored for air-gapped use.
Outcomes
What this changes for the team.
Triage
Less feed noise
Threat intel is filtered by what you run, what you can observe and what your business model says is exposed.
Action
Briefs become work
A relevant brief can create Backlog work, start a hunt, suggest a rule, connect to a risk, or enter a watchlist.
Reuse
Community content stays portable
Open Sigma, SPL and KQL content can be deduplicated, tested and adapted to local telemetry.
The problem
Threat intelligence is easy to collect and hard to operationalize. Feeds deliver a constant stream of campaigns, indicators, techniques, vendor advisories and ready-made detections. Most teams still have to answer the same questions manually: does this affect us, can our telemetry see it, are we already covered, and should we hunt before we deploy a rule?
Ethical hack and red-team findings create the same problem in another form. The finding is valuable, but it often stays trapped in a report. The SOC needs a bridge from “this path worked” to “we hunted for it, wrote a rule, tested it, deployed it and measured it.”
How CraftedSignal handles intelligence
CraftedSignal treats a threat brief as a package of usable detection work. A brief can include narrative, affected vendors and products, CVEs, IOCs, MITRE ATT&CK techniques, suggested Sigma rules, suggested hunts, tests, runbooks, playbooks and actor metadata.
The platform scores every brief against your business surface, telemetry and current rules. Modeled services, data assets, attack paths, operating systems, vendors, products, known log sources and existing detections all influence whether the item is urgent, useful, or noise.
From brief to detection work
Analysts can mark whether the threat affects them, adopt suggested rules, start a hunt, link the brief to an existing risk, watchlist it, or dismiss it with a recorded reason. When a brief includes runbooks or playbooks, those response steps move with the adopted rule or hunt instead of being left behind in the feed. A threat that is relevant but not ready for a permanent rule can become a hunt first. A threat that maps to a critical path can raise priority on an existing risk.
This keeps the feed connected to the rest of the platform. Intelligence is not a separate work queue; it becomes Backlog, hunts, rules and coverage evidence when there is work to do.
Public and private sources
CraftedSignal supports curated platform briefs and a public derivative feed at feed.craftedsignal.io. The community library can bring open detection content into the workflow, where it is deduplicated and tested before it becomes production coverage.
For regulated or isolated environments, signed bundles can be mirrored into an internal deployment. The same relevance and adoption workflow still applies, but outbound internet access is not required.
Related docs
Go deeper in the technical docs.
Threat Feed
Brief structure, scoring, rule adoption, IOCs and air-gapped bundles.
Threat Intake
SOC triage queue for candidate threats from CTI and risk requests.
Library
Reusable detection and hunt templates with tests and response steps.
Runbooks & Playbooks
How response steps move from briefs and libraries into rules and hunts.
Threat Actors
Normalized actor catalog and pivoting across briefs, hunts, risks and rules.
Air-gapped Mode
How isolated deployments handle signed bundles and outbound restrictions.
Next feature sets