How it works
From signal to residual-risk proof in nine governed steps.
Threat Foundry preserves source, analyst decisions, generated work, validation evidence, risk approvals, and handoffs so context does not disappear between tools.
- 01
Understand bounded context
Bring in selected CTI, exposure, alert, architecture, asset, telemetry, or analyst context with tenant and source boundaries attached.
- 02
Qualify the reason to act
Preserve provenance, markings, lifecycle, confidence, ATT&CK scope, environment relevance, currentness, and the analyst decision.
- 03
Model threats and likely paths
Connect trust boundaries, components, typed flows, threat hypotheses, controls, assumptions, and scoped attack paths to operational context.
- 04
Choose the governed outcome
Start or resume a guided workflow for investigation, hunting, detection creation, risk review, validation, tuning, connection, or reporting.
- 05
Generate, review, then run
Inspect the selected provider, model, customer-authorized evidence, query plan, limits, and action boundary before provider contact or execution.
- 06
Hunt, investigate, and engineer
Interpret returned and missing evidence, then carry reviewed intent into target-specific detection candidates with version lineage.
- 07
Govern risk and remediation
Review advisory risk, select treatment work, assign accountable owners, and retain the evidence behind the decision.
- 08
Validate and decide residual risk
Run approved controls, retain distinct outcomes, validate implementation, and make the next risk decision against customer-approved appetite.
- 09
Measure and learn
Use dispositions, drift, noise, validation age, ownership, closures, residual risk, and evidence-backed reports to improve the next cycle.
Opening or advancing a workflow does not silently run AI, contact a provider, approve risk, execute a query, export a package, or change provider data. Provider-facing work requires current configuration, permission, visible customer-authorized evidence, explicit review, and confirmation.
The governed path
Guidance, evidence, and customer control stay connected.
Start with the workflow
Walk through your own signal-to-proof path.
Bring your current intelligence, exposure, telemetry, architecture, detection content, and analyst or service process. We will map the fastest path to a useful outcome.