How it works

From signal to residual-risk proof in nine governed steps.

Threat Foundry preserves source, analyst decisions, generated work, validation evidence, risk approvals, and handoffs so context does not disappear between tools.

  1. 01

    Understand bounded context

    Bring in selected CTI, exposure, alert, architecture, asset, telemetry, or analyst context with tenant and source boundaries attached.

  2. 02

    Qualify the reason to act

    Preserve provenance, markings, lifecycle, confidence, ATT&CK scope, environment relevance, currentness, and the analyst decision.

  3. 03

    Model threats and likely paths

    Connect trust boundaries, components, typed flows, threat hypotheses, controls, assumptions, and scoped attack paths to operational context.

  4. 04

    Choose the governed outcome

    Start or resume a guided workflow for investigation, hunting, detection creation, risk review, validation, tuning, connection, or reporting.

  5. 05

    Generate, review, then run

    Inspect the selected provider, model, customer-authorized evidence, query plan, limits, and action boundary before provider contact or execution.

  6. 06

    Hunt, investigate, and engineer

    Interpret returned and missing evidence, then carry reviewed intent into target-specific detection candidates with version lineage.

  7. 07

    Govern risk and remediation

    Review advisory risk, select treatment work, assign accountable owners, and retain the evidence behind the decision.

  8. 08

    Validate and decide residual risk

    Run approved controls, retain distinct outcomes, validate implementation, and make the next risk decision against customer-approved appetite.

  9. 09

    Measure and learn

    Use dispositions, drift, noise, validation age, ownership, closures, residual risk, and evidence-backed reports to improve the next cycle.

Visible operating boundary

Opening or advancing a workflow does not silently run AI, contact a provider, approve risk, execute a query, export a package, or change provider data. Provider-facing work requires current configuration, permission, visible customer-authorized evidence, explicit review, and confirmation.

The governed path

Guidance, evidence, and customer control stay connected.

Validation Campaign
Validation CampaignExact versions, positive and negative controls, distinct outcomes, and provider-contact state.

Start with the workflow

Walk through your own signal-to-proof path.

Bring your current intelligence, exposure, telemetry, architecture, detection content, and analyst or service process. We will map the fastest path to a useful outcome.