Threat Foundry platform

A governed threat operations platform built around evidence continuity.

Understand the environment, model the threat, hunt and investigate, engineer and validate detections, then turn current evidence into governed risk and resilience decisions.

The evidence loop

See how threat context becomes governed action.

Each stage keeps the source, evidence, and analyst decision attached. Outcomes feed the next intelligence review and hunt instead of ending in a disconnected queue.

Guided Operations

One explained decision at a time. Expert depth when needed.

Start with an outcome, see the prerequisites, and resume at the next accountable decision. Guided workflows keep the authoritative expert workspace available without pretending navigation performed an action.

  • Investigate alerts, create detections, validate, tune, migrate, and connect platforms
  • My Work queue for owned, blocked, waiting, stale, and ready work
  • Visible completion criteria, blockers, repair paths, and expert handoffs
  • Generate → Review → Run before AI contact, query execution, validation, or export

Intelligence + Exposure

Qualify the source, the environment, and the reason to act.

The Intelligence Library preserves normalized MISP, OpenCTI, and STIX-derived context. Threat Library adds the analyst decision: relevance, hypothesis, telemetry, expected evidence, and whether the current item can move forward.

  • Markings, provenance, relationships, confidence, lifecycle, and currentness
  • Optional AI-assisted triage with deterministic policy and analyst review
  • Priority products, business assets, normalized fields, and telemetry readiness
  • Source policy rechecked before hunt, detection, or query execution
Threat Intelligence Dashboard
Threat Intelligence DashboardSource activity, relationships, ATT&CK context, currentness, and review progression.

Exposure Scanner + EASM

Connect what is internet-facing to ownership and verified follow-through.

Exposure Scanner strengthens discovery and finding context within explicitly approved scope. EASM connects observed services, KEVs, identity exposure, DNS and email posture, scanner evidence, business assets, owners, due dates, and retest outcomes.

  • Discovery only against explicitly approved customer-owned scope
  • Evidence-backed confidence, asset identity, affected service, and observation history
  • KEV, EPSS, business criticality, ownership, recurrence, remediation, and retest
  • Triage, risk register, case, ticket, report, and customer-publication handoffs

Hunting + Investigation

Generate the plan. Review the handoff. Run with intent.

Hunt Builder and Attack Path Builder ground ATT&CK behavior in configured telemetry, field mappings, assets, time bounds, and query policy. The review checkpoint shows the selected AI provider and customer-authorized evidence before any provider contact or query execution.

  • Enterprise, Cloud, Mobile, and ICS ATT&CK scope
  • Provider and model binding retained across Generate → Review → Run
  • Saved hunts, scheduling, run history, baselines, and triage handoff
  • Provenance carried from CTI, exposure, alerts, and Threat Modeling findings

Alert investigation + cases

Turn returned rows and normalized alerts into an evidence story.

Review the alert context, hypothesis, read-only query plan, observed and missing evidence, entity relationships, and analyst conclusion before routing the outcome to triage or a case.

  • Entity-aware timelines, graphs, commands, DNS, processes, and movement paths
  • Explicit provider-contact review with bounded time and result limits
  • Accountable triage ownership and durable case event history
  • Tasks, blockers, signoff, overrides, external handoff, and reports
Entity Analyzer
Entity AnalyzerAccounts, assets, processes, relationships, and investigation pivots.

FORGE by Threat Foundry

Reason from authorized evidence. Keep deterministic truth and human authority intact.

Forge brings evidence-grounded analysis into investigation, triage, cases, detection design, validation, and tuning. Closed tools retrieve bounded current context; the interface separates observed facts, deterministic findings, model inferences, missing evidence, recommendations, and draft proposals.

  • Tenant, user, permission, source, policy, evidence, and currentness rechecked throughout the run
  • Finite read tools with strict schemas, deadlines, result bounds, cancellation, citations, and audit history
  • Prepared case tasks, detection content, and tuning work remain bounded drafts requiring authorized review
  • No arbitrary execution, provider mutation, approval, deployment, response, or silent fallback
Explore Forge

Detection Lifecycle

Plan, build, validate, improve, and deliver from one evidence chain.

Begin with a governed request, CTI item, coverage gap, incident lesson, case, audit need, or analyst hypothesis. Carry that source through environment strategy, platform versions, testing, approval, and customer-controlled delivery.

  • Detection requests, coverage gaps, registry, and environment strategies
  • Sigma source, controlled detection intent, and reviewed platform versions
  • Telemetry and field compatibility recorded per target
  • Promotion readiness and package history without provider deployment
Detection Lifecycle Command Center
Detection Lifecycle Command CenterRequests, coverage, platform versions, readiness, drift, and delivery state.

Validation + Tuning

Test exact versions. Improve only from current evidence.

Detection Assurance binds positive and negative controls to frozen candidate, telemetry, mapping, connector, inventory, and test revisions. Results stay distinct and explainable instead of collapsing into a pass/fail promise.

  • Passed, failed, blocked, expired, and inconclusive outcomes
  • Read-only connected validation where the target and tenant support it
  • Health, drift, usefulness, regression, evidence age, and due work
  • Structured tuning comparisons with coverage-loss warnings and independent review
Detection Assurance Center
Detection Assurance CenterCurrent tests, dependency readiness, validation evidence, drift, and recommended next actions.

Threat Modeling

Make threats, assumptions, paths, and evidence operational.

Threat Blueprints model components, trust boundaries, typed flows, business context, and threat hypotheses; apply the reproducible STRIDE baseline; and carry scoped attack-path findings into hunts, detections, cases, and governed risk work.

  • Offline AWS, Azure, Google Cloud, and supported inventory imports
  • Explicit assets, actors, assumptions, preconditions, trust transitions, and control context
  • Architecture-change checks prevent stale findings from moving forward
  • Owners, remediations, evidence, review gates, and point-in-time publication

Risk & Resilience

Turn operational evidence into governed risk decisions.

Move advisory findings through human review, treatment, shared remediation, implementation evidence, validation, and residual-risk decision. Customer-defined appetite thresholds keep portfolio status tied to approved policy rather than a product default.

  • Evidence-backed risk register and accountable ownership
  • CREF candidate mitigation lineage through NIST SP 800-53 Rev. 5
  • Associated framework controls shown on demand for a selected NIST control
  • D3FEND coverage and defensive-technique heatmap grounded in current evidence
Explore Risk & Resilience

BYOAI routing

Choose the provider without surrendering the decision.

Tenants can retain multiple provider configurations and activate exactly one. Supported AI-assisted workflows bind the selected provider and model at review time and stop if that route changes before execution.

  • Exactly one active provider; inactive configurations are retained, never used as fallback
  • Complete customer-authorized workflow evidence with no hidden row or field reduction
  • Reusable credential values are visibly protected; provider and connector credentials are never prompt content
  • No silent provider failover or partial AI verdict when the selected route or complete handoff is unavailable
  • Saving and using a route confirms the customer’s provider/model choice and acceptance of the provider’s applicable terms

Governance + Scale

Make the action boundary and evidence chain visible.

Threat Foundry keeps source, versions, permissions, tenant scope, review, provider contact, approvals, and customer delivery attached to the work.

EV

Evidence traceability

Trace source, candidates, tests, provider evidence, tuning decisions, approvals, packages, and operational handoffs.

RB

Review before action

Inspect the exact tenant, connector, content version, limits, provider-contact state, change boundary, warning, and action before confirmation.

SC

Control Center

Coordinate tenant lifecycle, work, SLAs, health, licensing, delivery, reporting, access, and evidence-free Forge guidance across an authorized service portfolio.

Explore MSSP/MSP operations
AP

API & Automation

Use the tenant-scoped public API for bounded, paginated access to supported local evidence with explicit completeness state and review-preserving workflow actions.

Explore the public API boundary

Cases + Reporting

Carry reviewed outcomes into ownership and proof.

Case Workspace
Case WorkspaceEvidence history, ownership, tasks, signoff, blockers, and external handoff.
Coverage Heatmap
Coverage HeatmapATT&CK evidence across hunts, detections, telemetry, and validation without overstating coverage.

Managed outcomes

Use the same operating model as software or service.

TH

THaaS

Recurring reviewed hunts, investigation, publication, and follow-through.

Explore service
EX

EASM

Approved-scope discovery, prioritization, remediation tracking, retest, and reporting.

Explore service
TB

Threat Blueprints service

Reviewed architecture assessment, resilience findings, remediation, and publication.

Explore service
DE

DEaaS

Governed intake, multi-platform engineering, assurance, tuning, and package delivery.

Explore service

Start with the workflow

See your threat operations workflow as one system.

Bring your current intelligence, exposure, telemetry, architecture, detection content, and analyst or service process. We will map the fastest path to a useful outcome.