Forge
Research & insights
Practical thinking for teams turning threat context into action.
Explore threat intelligence, hunting, cloud security, detection engineering, incident response, AI governance, and security operating models.
Exposure Management
Exposure management beyond the scan: an operating model for risk reduction
A practical exposure-management loop that connects approved scope, trustworthy observations, exploit and business context, ownership, remediation, retesting, and risk decisions.Read articleThreat Intelligence
How to use the Intelligence Library effectively
A field guide to finding relevant intelligence, checking provenance and markings, exploring bounded relationships, and creating reviewable hunt candidates without losing source context.Read articleRisk & Resilience
Risk & Resilience: the operating layer that ties Threat Foundry together
How Threat Foundry connects durable security evidence to governed risk decisions, shared remediation, validation, and residual-risk review.Read articleDetection Engineering
Reduce detection risk with an evidence-backed coverage loop
Use ATT&CK Coverage, D3FEND relationships, Detection Studio, validation, and assurance to prioritize and reduce detection risk without making unsupported coverage claims.Read articleExposure Management
Reduce exposure risk by connecting external findings to owned remediation
A practical workflow for turning approved-scope EASM evidence, asset context, KEV intelligence, ownership, and retesting into accountable risk reduction.Read articleAI and Hunting
AI-assisted threat hunting should be review-first, not autopilot.
How AI can accelerate hunt generation, CTI summarization, Sigma drafting, and YARA drafting while keeping analysts in control.Read articleDetection Engineering
Community Sigma and YARA Detection Exchange
How Threat Foundry approaches opt-in community sharing for Sigma and YARA detections while keeping customer rules private by default.Read articleThreat Intelligence
Tune CTI prioritization with CTI Modeling and Metric Weights
How to use Threat Foundry CTI Modeling, reporting, Auto Triage, and Metric Weights to tune CTI prioritization without creating noisy queues.Read articleThreat Hunting
Detecting lateral movement with Threat Foundry.
How Threat Foundry helps teams hunt and detect lateral movement across identity, endpoint, network, cloud, and asset context.Read articleIncident Response
The DFIR feedback loop: turn incidents into better detections.
Why incident response should produce reusable intelligence, Sigma/YARA candidates, playbooks, and telemetry improvements.Read articleEnterprise Security
Enterprise detection engineering needs governance as much as content.
Why large security programs need repeatable detection lifecycle management, field normalization, evidence review, and reporting around Sigma, YARA, and hunt workflows.Read articleVulnerability Intelligence
KEV is vulnerability intelligence, not just a patch list
How CISA KEV can help security teams prioritize exploited vulnerabilities, scope exposure, trigger hunts, and drive detection work.Read articleMidsize Business
A practical detection program for midsize businesses.
How midsize organizations can build useful threat hunting and detection workflows without needing enterprise-scale tooling or staff.Read articleMSP Strategy
How MSPs can offer threat hunting without adding a full hunt team.
A practical model for MSPs and MSSPs to package CTI-led hunting, detection review, and customer reporting with repeatable workflows.Read articleYARA and DFIR
Practical YARA for incident response teams.
How IR teams can use YARA to turn malware traits, strings, and file artifacts into reviewable detection content.Read articleSOC Operations
From CTI to triage: making SOC analyst workflows less noisy.
How SOC teams can move from raw intelligence to reviewed hunts, detections, triage, and cases without turning every feed item into work.Read articleThreat Hunting
Hunting living off the land attacks with Threat Foundry.
How to use Threat Foundry to hunt living off the land attacks by turning legitimate-tool abuse into reviewed ATT&CK-driven hunts, Sigma candidates, and evidence.Read articleCloud Hunting
Threat Hunting in the Cloud, Part 1: From Logs to Behavior
A provider-neutral model for cloud threat hunting built around identity, control-plane activity, data movement, workload runtime, and the MITRE ATT&CK Cloud matrix.Read articleCloud Hunting
Threat Hunting in the Cloud, Part 2: AWS
How to build AWS threat hunts around CloudTrail, GuardDuty, Security Lake, IAM, S3, EKS, runtime telemetry, and the MITRE ATT&CK Cloud matrix.Read articleCloud Hunting
Threat Hunting in the Cloud, Part 3: Microsoft Azure
How to build Azure cloud hunts around Entra ID, Activity Logs, Defender XDR advanced hunting, Microsoft Sentinel, hybrid identity, and the ATT&CK Cloud matrix.Read articleCloud Hunting
Threat Hunting in the Cloud, Part 4: Google Cloud
How to build Google Cloud hunts around Security Command Center, Google Security Operations, IAM, service accounts, BigQuery, GKE, Cloud Run, and the ATT&CK Cloud matrix.Read articleThreat Hunting Program
Start with a threat hunting charter before buying more tools.
How mature hunt programs define mission, scope, PIRs, authority, cadence, and handoffs before scaling technology.Read articleThreat Intelligence
The power of information sharing in threat intelligence
Why threat intelligence sharing is a force multiplier when it is timely, trusted, contextual, and tied to hunt and detection workflows.Read articleThreat Hunting
Why TTP-driven hunting beats IOC chasing.
Why durable threat hunting starts with adversary behavior, not just disposable indicators.Read articleThreat Blueprints
Getting the most from Threat Blueprints
A practical guide to turning architecture context, data flows, attack paths, findings, and remediations into an operating security workflow.Read articleThreat Intelligence
How to leverage CTI across the Threat Foundry platform
Move selected intelligence through normalization, review, prioritization, hunting, detection, investigation, and reporting without losing provenance.Read articleNo articles match this topic.