MISP
Bounded, read-only event synchronization through a configured integration. Review normalized entities before downstream use.
Read-only syncConnected, deliberately
Threat Foundry states whether each target supports bounded read-only search, rule verification, inventory, validation, or portable export. Provider contact is explicit; provider mutation remains outside the workflow.
Threat intelligence
Bounded, read-only event synchronization through a configured integration. Review normalized entities before downstream use.
Read-only syncBounded, read-only GraphQL intake from a configured server and token. Entity and relationship content stays tenant-owned.
Read-only syncUpload a bounded STIX bundle for review when a live platform connection is not appropriate for the environment.
File intakeConnected platform families
Configuration, licensed products, tenant policy, permissions, telemetry, mappings, and the selected workflow determine which controls are available.
Use configured search and detection workflows with bounded queries, reviewed limits, normalized fields, and current connector readiness.
Read-only operationsInvestigate normalized alerts and run explicitly reviewed, time-bounded searches where the tenant connection is ready.
Read-only operationsUse the bounded, read-only telemetry query path when the tenant connector is configured. Detection-rule deployment is not implied.
Read-only queryUse the bounded, read-only telemetry query path when the tenant connector is configured. Detection-rule deployment is not implied.
Read-only queryKeep UDM Search as the read-only telemetry path and YARA-L as the separate rule-verification target.
Search + verificationUse allowlisted read operations with the provider's broad-RBAC warning visible during setup and review.
Read-only boundaryA connected target may support only some combination of translation, linting, query validation, bounded search, rule verification, or inventory. Threat Foundry does not create, update, enable, disable, delete, or deploy provider content.
Portable detection targets
Customer-controlled portable export; no provider contact.
Review-package output for the customer's deployment process.
Portable artifacts with the supported context and limitations attached.
Export-only handoff rather than simulated validation.
Review package for customer-controlled implementation.
Source, generated artifacts, tests, evidence index, approvals, checksums, guidance, and rollback planning.
Exposure + Asset Context
Bring configured vulnerability and scanner context into KEV and exposure prioritization.
Configured enrichmentUse tenant-approved exposure evidence to enrich affected-asset and remediation decisions.
Configured enrichmentUpload bounded CSV or JSON findings and business metadata when an API connection is not appropriate.
File intakeThreat Modeling inventory
Export inventory from the customer cloud, inspect the file, and import it without granting Threat Foundry standing cloud credentials.
Import a supported bounded inventory export to propose components, relationships, and security zones for analyst review.
Offline exportTranslate supported Azure inventory exports into Blueprint proposals without a live control-plane connection.
Offline exportUse supported Cloud Asset inventory exports to seed a reviewable architecture model.
Offline exportBring your own AI
Configure supported providers for the tenant, retain alternatives for later use, and activate exactly one. AI-assisted workflows bind the selected provider and model through Generate → Review → Run so a route change cannot silently redirect an approved handoff.
The customer selects the provider, models, account, and reviewed workflow evidence. Saving and using that route confirms acceptance of the provider’s applicable terms, privacy, retention, pricing, and data-handling conditions. Provider-account and model-choice governance remain the customer’s responsibility; Threat Foundry enforces the configured route without silently substituting or approving a provider.
Operations ecosystem
Use supported normalized alerts and bounded host context for review-first investigation without endpoint response.
Hand reviewed work to configured ticket providers while retaining the internal evidence and decision record.
Use the customer-selected route for supported summarization, scoping, drafting, and analysis with visible evidence handoff and review.
Manage supported non-secret settings and purpose-bound credential references through tenant-aware configuration.
Map customer aliases into a consistent investigation and detection entity model; draft mappings with Field Builder.
Constrain indexes, sources, fields, time ranges, result limits, overrides, and telemetry expectations before execution.
Availability depends on licensed third-party products, current configuration, supported formats, permissions, customer policy, and the exact workflow. Vendor names describe possible interoperability and do not imply partnership, endorsement, certification, or uniform feature parity.
Start with the workflow
We will identify what can work on day one, what requires a connection, and where offline import or portable export is the safer first step.